HOME

TheInfoList



OR:

Joe Sullivan (born in 1968) is an American Internet security expert. Having served as a federal prosecutor with the
United States Department of Justice The United States Department of Justice (DOJ), also known as the Justice Department, is a United States federal executive departments, federal executive department of the United States government tasked with the enforcement of federal law and a ...
, he worked as a CSO at
Facebook Facebook is an online social media and social networking service owned by American company Meta Platforms. Founded in 2004 by Mark Zuckerberg with fellow Harvard College students and roommates Eduardo Saverin, Andrew McCollum, Dustin ...
,
Uber Uber Technologies, Inc. (Uber), based in San Francisco, provides mobility as a service, ride-hailing (allowing users to book a car and driver to transport them in a way similar to a taxi), food delivery ( Uber Eats and Postmates), pack ...
and
Cloudflare Cloudflare, Inc. is an American content delivery network and DDoS mitigation company, founded in 2009. It primarily acts as a reverse proxy between a website's visitor and the Cloudflare customer's hosting provider. Its headquarters are in San ...
. For his role in covering up the 2016 data breaches at Uber, he was convicted in October 2022 on federal felony charges of obstruction and
misprision Misprision (from fro, mesprendre, modern french: se méprendre, "to misunderstand") in English law describes certain kinds of offence. Writers on criminal law usually divide misprision into two kinds: negative and positive. It survives in the la ...
. In January 2023, he took on the role o
CEO of Ukraine Friends
a nonprofit focused on humanitarian aid to Ukraine.


Early life and education

Joe Sullivan was born in 1968 in
Rutland Rutland () is a ceremonial county and unitary authority in the East Midlands, England. The county is bounded to the west and north by Leicestershire, to the northeast by Lincolnshire and the southeast by Northamptonshire. Its greatest l ...
,
Vermont Vermont () is a state in the northeast New England region of the United States. Vermont is bordered by the states of Massachusetts to the south, New Hampshire to the east, and New York to the west, and the Canadian province of Quebec to the ...
. He grew up in
Cambridge, Massachusetts Cambridge ( ) is a city in Middlesex County, Massachusetts, United States. As part of the Greater Boston, Boston metropolitan area, the cities population of the 2020 United States Census, 2020 U.S. census was 118,403, making it the fourth most ...
. Sullivan graduated from Matignon High School in 1986, earned his
Bachelor of Arts Bachelor of arts (BA or AB; from the Latin ', ', or ') is a bachelor's degree awarded for an undergraduate program in the arts, or, in some cases, other disciplines. A Bachelor of Arts degree course is generally completed in three or four yea ...
degree at
Providence College Providence College is a private Catholic university in Providence, Rhode Island. Founded in 1917 by the Dominican Order and the local diocese, it offers 47 undergraduate majors and 17 graduate programs. It requires all of its undergradua ...
in 1990, and graduated from the
University of Miami School of Law The University of Miami School of Law (Miami Law or UM Law) is the law school of the University of Miami, a private research university in Coral Gables, Florida. Founded in 1926, the University of Miami School of Law is the oldest law school in ...
in 1993.


Career


US Department of Justice

After law school, Sullivan spent the first eight years of his career in the
Department of Justice A justice ministry, ministry of justice, or department of justice is a ministry or other government agency in charge of the administration of justice. The ministry or department is often headed by a minister of justice (minister for justice in a ...
, having started as an intern at the DOJ Miami office in 1992 and then ultimately working at the San-Francisco office with
Robert Mueller Robert Swan Mueller III (; born August 7, 1944) is an American lawyer and government official who served as the sixth director of the Federal Bureau of Investigation (FBI) from 2001 to 2013. A graduate of Princeton University and New York ...
. From 1997 to 1999, he served as
Assistant United States Attorney An assistant United States attorney (AUSA) is an official career civil service position in the U.S. Department of Justice composed of lawyers working under the U.S. Attorney of each U.S. federal judicial district. They represent the federal go ...
at the
District of Nevada A district is a type of administrative division that, in some countries, is managed by the local government. Across the world, areas known as "districts" vary greatly in size, spanning regions or counties, several municipalities, subdivisi ...
in
Las Vegas Las Vegas (; Spanish language, Spanish for "The Meadows"), often known simply as Vegas, is the List of United States cities by population, 25th-most populous city in the United States, the most populous city in the U.S. state, state of Neva ...
. From 2000 to 2002, Sullivan worked as Assistant US Attorney at the
Northern District of California The United States District Court for the Northern District of California (in case citations, N.D. Cal.) is the federal United States district court whose jurisdiction comprises the following counties of California: Alameda, Contra Costa, ...
. He was a founding member of the Computer Hacking and Intellectual Property unit at the Northern District of California. In 2001 and 2002, together with Scott Frewing he represented the U.S. government in ''
United States v. Elcom Ltd. ''United States v. ElcomSoft and Dmitry Sklyarov'' was a 2001–2002 criminal case in which Dmitry Sklyarov and his employer ElcomSoft were charged with alleged violation of the DMCA. The case raised some concerns of civil rights and legal process ...
'' case, the first prosecution in the U.S. under the
Digital Millennium Copyright Act The Digital Millennium Copyright Act (DMCA) is a 1998 United States copyright law that implements two 1996 treaties of the World Intellectual Property Organization (WIPO). It criminalizes production and dissemination of technology, devices, or ...
. Sullivan also worked on multiple cybercrime cases including digital evidence aspects of the 9/11 investigation, economic espionage and child predator cases.


eBay

In April 2002, Sullivan joined
eBay eBay Inc. ( ) is an American multinational e-commerce company based in San Jose, California, that facilitates consumer-to-consumer and business-to-consumer sales through its website. eBay was founded by Pierre Omidyar in 1995 and became ...
in as Senior Director of Trust and Safety. In a September 2006
United States congressional hearing A United States congressional hearing is the principal formal method by which United States congressional committees collect and analyze information in the early stages of legislative policymaking. Whether confirmation hearings (a procedure unique ...
, he described his duties as "overseeing company relations with law enforcement and regulatory agencies in the United States and Canada, directing the company's Fraud Investigations team and determining policies related to listing of items on eBay". In 2003, he was criticized by Yuval Dror at the ''
Haaretz ''Haaretz'' ( , originally ''Ḥadshot Haaretz'' – , ) is an Israeli newspaper. It was founded in 1918, making it the longest running newspaper currently in print in Israel, and is now published in both Hebrew and English in the Berliner ...
'' newspaper for being willing to share eBay user's personal data with law-enforcement agencies potentially without proper legal framework. From 2006 to 2008 he was an Associate General Counsel at
PayPal PayPal Holdings, Inc. is an American multinational financial technology company operating an online payments system in the majority of countries that support online money transfers, and serves as an electronic alternative to traditional paper ...
. One of his top priorities was preventing
phishing Phishing is a type of social engineering where an attacker sends a fraudulent (e.g., spoofed, fake, or otherwise deceptive) message designed to trick a person into revealing sensitive information to the attacker or to deploy malicious softwar ...
scams.


Facebook

In 2008, he started at
Facebook Facebook is an online social media and social networking service owned by American company Meta Platforms. Founded in 2004 by Mark Zuckerberg with fellow Harvard College students and roommates Eduardo Saverin, Andrew McCollum, Dustin ...
first as an attorney, and next as its Chief Security Officer (2010-2015). Sullivan assembled a security team to handle requests from law enforcement agencies globally and fight various types of cybercrime within the social network. He introduced a practice of security
hackathon A hackathon (also known as a hack day, hackfest, datathon or codefest; a portmanteau of hacking and marathon) is an event where people engage in rapid and collaborative engineering over a relatively short period of time such as 24 or 48 hours. Th ...
s and bug bounty programs both internally and externally, encouraging coders to find vulnerabilities. His team was handling complicated and large-scale security issues such as an attempt to hack the accounts of Tunisian Facebook users in the 2011 "Arab Spring" during the
Tunisian Revolution The Tunisian Revolution, also called the Jasmine Revolution, was an intensive 28-day campaign of civil resistance. It included a series of street demonstrations which took place in Tunisia, and led to the ousting of longtime president Zine ...
. Sullivan also gained a reputation as an expert at fighting online bullying. He testified on this subject before Congress in 2010, and was invited to the first White House Conference on Bullying Prevention in 2011.


Uber

In Spring 2015, Sullivan joined
Uber Uber Technologies, Inc. (Uber), based in San Francisco, provides mobility as a service, ride-hailing (allowing users to book a car and driver to transport them in a way similar to a taxi), food delivery ( Uber Eats and Postmates), pack ...
as its first CSO, at the time when the company was experiencing multiple safety and security issues. His primary focus was on safety of riders and drivers, both in the digital space and in the physical world. As an example, he was involved in investigating the 2016 Kalamazoo shootings. In November 2017, Sullivan and Craig Clark, a senior lawyer at the company, were fired for allegedly covering up a major data breach in 2016 and paying hackers $100,000. Later in 2018, ''
Reuters Reuters ( ) is a news agency owned by Thomson Reuters Corporation. It employs around 2,500 journalists and 600 photojournalists in about 200 locations worldwide. Reuters is one of the largest news agencies in the world. The agency was est ...
'' reported that the decision not to disclose the breach was made by the company's legal department.


Cloudflare

In May 2018, Sullivan joined
Cloudflare Cloudflare, Inc. is an American content delivery network and DDoS mitigation company, founded in 2009. It primarily acts as a reverse proxy between a website's visitor and the Cloudflare customer's hosting provider. Its headquarters are in San ...
as the company's first Chief Security Officer. In December 2021, he was among the top Internet security experts who were exploring the
Log4Shell Log4Shell (CVE-2021-44228) was a zero-day vulnerability in Log4j, a popular Java logging framework, involving arbitrary code execution. The vulnerability had existed unnoticed since 2013 and was privately disclosed to the Apache Software Foun ...
vulnerability.


Volunteer government roles

Over the years, Sullivan has held several positions at government agencies and national organizations. From 2011 to 2016, he served as a commissioner at National Cyber Security Alliance, a non-profit organization that promotes cybersecurity and privacy education, where he ran a number of cyber security awareness initiatives. In 2012, he became a board member for the National Action Alliance for Suicide Prevention and co-authored the "2012 National Strategy for Suicide Prevention". In April 2016, President
Obama Barack Hussein Obama II ( ; born August 4, 1961) is an American politician who served as the 44th president of the United States from 2009 to 2017. A member of the Democratic Party, Obama was the first African-American president of the U ...
appointed him as a commissioner on the Commission on Enhancing National Cybersecurity, a government body that was dissolved in December 2016 after releasing recommendations to the White House on how to address the nation's cybersecurity issues.


2016 Uber Data Breach, Trial and Conviction

In August 2020, the
US Department of Justice The United States Department of Justice (DOJ), also known as the Justice Department, is a federal executive department of the United States government tasked with the enforcement of federal law and administration of justice in the United Stat ...
announced criminal charges against Sullivan for
obstruction of justice Obstruction of justice, in United States jurisdictions, is an act that involves unduly influencing, impeding, or otherwise interfering with the justice system, especially the legal and procedural tasks of prosecutors, investigators, or other gov ...
for his handling of the 2016 data breaches at Uber. The criminal complaint said Sullivan arranged, with CEO Travis Kalanick's knowledge, to pay a ransom for the breach as a "bug bounty" to conceal its true nature, and to falsify non-disclosure agreements with the hackers to say they had not obtained any data. In December 2021, he faced additional charges of wire fraud. On October 6th 2022, Sullivan was convicted of one count of obstruction of justice, and one count of
misprision of felony Misprision of felony is a form of misprision, and an offence under the common law of England that is no longer active in many common law countries. Where it was or is active, it is classified as a misdemeanor. It consists of failing to report k ...
. He is currently awaiting sentencing. The trial of Sullivan represents the first United States federal prosecution of a corporate executive for the handling of a
data breach A data breach is a security violation, in which sensitive, protected or confidential data is copied, transmitted, viewed, stolen or used by an individual unauthorized to do so. Other terms are unintentional information disclosure, data leak, info ...
.


Bibliography

*


References

{{DEFAULTSORT:Sullivan, Joe Assistant United States Attorneys People from Rutland (city), Vermont American people of Irish descent Providence College alumni University of Miami School of Law alumni EBay employees PayPal people Cloudflare people Facebook employees Chief security officers 1968 births Living people