Former Uber Chief Security Officer to Face Wire Fraud Charges
justice.gov
justice.gov
https://gimletmedia.com/shows/reply-all/z3hler/91-the-russia...
https://gimletmedia.com/shows/reply-all/xjheve/93-beware-all
https://gimletmedia.com/shows/reply-all/5whmed/111-return-of...
Are there any hints about the other “large tech company” hit by the same hackers? To be transparent to the authorities is not always easy, but in this case, it could have prevented another attack :/
> The separate guilty pleas entered by the hackers demonstrate that after Sullivan assisted in covering up the nature of the hack of Uber, the hackers were able to commit an additional intrusion at another corporate entity—Lynda.com—and attempt to ransom that data as well.
Couldn't have happened to a nicer company! (for those unaware, it was bought by LinkedIn shortly before the hack)
Why not just reveal the breach? Why risk going to jail just to avoid looking bad in your job? I don't think they would have even let him go because of this.
My money is on heavy peer pressure on this one.
This is so weird. Did the "old management" aka TK and Thuan Pham know about this and instruct that guy to pay $$$ and keep quiet? Sounds like it? Or did he pay the ransom secretly out of his own pocket?
So maybe it's someone else that should be held accountable and the "new management" is just throwing the CSO under the bus?
https://gdpr-info.eu/art-33-gdpr/
"Personal data" is the threshold.
Which is why I'm arguing for reporting any breach, not with a threshold of type or quantity of data stolen. If you had a breach and you believe that no data was taken you should still be required to report it and if it turns out that you have made evidence of a breach disappear that should automatically trigger the worst penalties under the law.
Oh, and EU PII is drastically less useful. Most countries in the EU have national ID systems, which are used and required for anything important ( like a new bank account or loan). A bad actor could still use PII for social engineering though.
In cases of breaches there will often be commercial pressure in a company not to disclose (to avoid financial impact)
With personal criminal liability being a possibility for the CISO they are then placed in the position of disclose regardless of internal pressure (risking their job) or don't disclose (and risk criminal prosecution)
NOTE: So, if you are black-mailed by hackers and pay you now go to federal prison. The only way to play with the hackers is not work with the FBI (obviously). I understand the 'anti-uber hn hate' here, but wow, being attacked by hackers, then getting scared, playing along, paying out blackmailers, then going to federal prison? Wirefraud could be 20 years in federal prison. This guy is worse than a rapist? Not following.
Also. If the FBI wants to talk to you - get a lawyer, they have no interest in "assisting" you. They do enjoy posting your name on "www.justice.gov" to permanently destroy your career though. Never, ever, ever talk to the FBI
Wire fraud that destroys someone's life savings (i.e. on the Madoff scale) can be arguably put in the same ball park as a sexual assault, in terms of net damage inflicted. Plus wire fraud has the potential to inflict damage on large numbers of people. So that's probably what the maximum penalty is motivated by. (Whether the maximum applies in this case is a separate matter).
Being attacked by hackers, then getting scared, playing along, paying out blackmailers, then going to federal prison?
What you're allegedly paid for as a CSO, or chief-anything of a large publicly traded company (and at a level astronomically higher than that of your rank-and-file muscle workers who you won't even dignify as "employees") is your awareness of the law (or at least the minimal sense to ask a lawyer), and your ability to not shit your pants in these situations -- but to act rationally.
"Can't do the time, don't do the C-level".
Might was well get the full sack of horse shit from the original source, than half a sack from a secondary.
Some journalists will try stuff like that, but that’s arguably worse than a press release.
If you're interested, the congress hearing is here. That hearing is still the primary source for this story. It's worth some time - some journalists have tried to cover this but mostly just cherrypicked quotes. The entire hearing is better than any of the coverage.
https://www.commerce.senate.gov/2018/2/data-security-and-bug...
You can watch the hearing on that page (it's more interesting to watch than to read) or find links to the various witnesses and their testimony. For example, if you want to read John Flynn's testimony, it is available here (.pdf):
John Flynn - CISO @ Uber - https://www.commerce.senate.gov/services/files/7D70E53E-73E9...
At this point, the only real lesson for CISO's seems to be 'report'.