Chief Security Officer at Facebook (2010-2015) and Uber (2015-2017)
Joe Sullivan (born in 1968) is an American Internet security expert. Having served as a federal prosecutor with the United States Department of Justice, he worked as a CSO at Facebook, Uber and Cloudflare. For his role in covering up the 2016 data breaches at Uber, he was convicted in October 2022 on federal felony charges of obstruction and misprision.
[1] In January 2023, he took on the role of CEO of Ukraine Friends, a nonprofit focused on humanitarian aid to Ukraine.[2]
From 2000 to 2002, Sullivan worked as Assistant US Attorney at the Northern District of California.[7] He was a founding member of the Computer Hacking and Intellectual Property unit at the Northern District of California.[8] In 2001 and 2002, together with Scott Frewing he represented the U.S. government in United States v. Elcom Ltd. case, the first prosecution in the U.S. under the Digital Millennium Copyright Act.[9][10] Sullivan also worked on multiple cybercrime cases including digital evidence aspects of the 9/11 investigation, economic espionage and child predator cases.[11]
eBay
In April 2002, Sullivan joined eBay in as Senior Director of Trust and Safety.[12][13] In a September 2006 United States congressional hearing, he described his duties as "overseeing company relations with law enforcement and regulatory agencies in the United States and Canada, directing the company's Fraud Investigations team and determining policies related to listing of items on eBay".[14] In 2003, he was criticized by Yuval Dror at the Haaretz newspaper for being willing to share eBay user's personal data with law-enforcement agencies potentially without proper legal framework.[15][16] From 2006 to 2008 he was an Associate General Counsel at PayPal.[12] One of his top priorities was preventing phishing scams.[17]
Facebook
In 2008, he started at Facebook first as an attorney, and next as its Chief Security Officer (2010-2015).[5] Sullivan assembled a security team to handle requests from law enforcement agencies globally and fight various types of cybercrime within the social network.[5][8] He introduced a practice of security hackathons and bug bounty programs both internally and externally, encouraging coders to find vulnerabilities.[18][19] His team was handling complicated and large-scale security issues such as an attempt to hack the accounts of Tunisian Facebook users in the 2011 "Arab Spring" during the Tunisian Revolution.[20][21]
Sullivan also gained a reputation as an expert at fighting online bullying. He testified on this subject before Congress in 2010,[22] and was invited to the first White House Conference on Bullying Prevention in 2011.[23]
Uber
In Spring 2015, Sullivan joined Uber as its first CSO, at the time when the company was experiencing multiple safety and security issues.[24][25] His primary focus was on safety of riders and drivers, both in the digital space and in the physical world.[26] As an example, he was involved in investigating the 2016 Kalamazoo shootings.[27]
In November 2017, Sullivan and Craig Clark, a senior lawyer at the company, were fired for allegedly covering up a major data breach in 2016 and paying hackers $100,000.[28][29] Later in 2018, Reuters reported that the decision not to disclose the breach was made by the company's legal department.[30]
Cloudflare
In May 2018, Sullivan joined Cloudflare as the company's first chief security officer.[31] In December 2021, he was among the top Internet security experts who were exploring the Log4Shell vulnerability.[32]
Volunteer government roles
Over the years, Sullivan has held several positions at government agencies and national organizations. From 2011 to 2016, he served as a commissioner at National Cyber Security Alliance, a non-profit organization that promotes cybersecurity and privacy education,[33][34] where he ran a number of cyber security awareness initiatives.[35][36] In 2012, he became a board member for the National Action Alliance for Suicide Prevention and co-authored the "2012 National Strategy for Suicide Prevention".[37]
In April 2016, President Obama appointed him as a commissioner on the Commission on Enhancing National Cybersecurity, a government body that was dissolved in December 2016 after releasing recommendations to the White House on how to address the nation's cybersecurity issues.[38]
2016 Uber Data Breach, Trial and Conviction
In August 2020, the US Department of Justice announced criminal charges against Sullivan for obstruction of justice for his handling of the 2016 data breaches at Uber. The criminal complaint said Sullivan arranged, with CEO Travis Kalanick's knowledge, to pay a ransom for the breach as a "bug bounty" to conceal its true nature, and to falsify non-disclosure agreements with the hackers to say they had not obtained any data.[39] In December 2021, he faced additional charges of wire fraud.[40]
On October 6, 2022, Sullivan was convicted of one count of obstruction of justice, and one count of misprision of felony.[41][42] He was sentenced to three years probation on May 4, 2023.[43] The trial of Sullivan represented the first United States federal prosecution of a corporate executive for the handling of a data breach.[44]