In 2016, hackers obtained Uber rider and driver data — publicly reported to cover roughly 57 million accounts — while the company was already under Federal Trade Commission investigation for an earlier breach. Prosecutors alleged that Uber's chief security officer, Joseph Sullivan, routed the hackers' demand through the company's bug bounty program, paid them $100,000, and had them sign a nondisclosure agreement, concealing the breach from regulators and from Uber's own general counsel.
The United States charged Sullivan in September 2020 in the Northern District of California — United States v. Sullivan, Case No. 3:20-cr-00337, before Judge William H. Orrick. The case went to a jury in the fall of 2022.
Why it was difficult
The trial asked twelve laypeople to draw a line through technical conduct. A bug bounty payment is a legitimate, everyday security practice; a payment used to paper over a breach is, on the government's theory, a cover-up. Which one happened turned on facts that live in security operations — how the program worked, what the security team knew and recorded, what the nondisclosure agreement was made to say — and on whether those facts could be explained to a jury without either oversimplifying them or losing the room.
Criminal matters are the hardest environment for that translation. The stakes are liberty, the standard is beyond a reasonable doubt, and both sides field experts.
The firm's role
A Law & Forensics principal, Daniel B. Garrie, served as a cybersecurity expert in the matter. The firm's published record cites the engagement as: United States v. Joseph Sullivan, N.D. Cal., Case No. 3:20-cr-00337-WHO (2022) — one of the named criminal and civil matters in the firm's record of court and arbitral engagements. The firm does not publish matter details beyond that record.
Evidence and method
Cybersecurity expert work in a criminal case is reconstruction under oath: what the systems recorded, what the security organization's own artifacts — tickets, chat logs, program rules, agreements — show about who knew what and when, and how ordinary security practice actually operates, explained in terms a jury can test against the evidence. Digital evidence in federal criminal proceedings also carries its own doctrinal weight in the Ninth Circuit — the firm has written on the governing framework in its analysis of United States v. Comprehensive Drug Testing.
The firm's standard for this work is the one every testifying engagement is built to: opinions grounded in artifacts, stated with their limits, and written to be checked.
Impact
On October 5, 2022, the jury found Sullivan guilty of obstructing the FTC's investigation and of misprision of a felony; he was later sentenced, as publicly reported, to probation and a fine. The verdict was widely described as the first criminal conviction of a corporate security executive over the handling of a data breach, and it changed the conversation in every boardroom and security organization in the country: incident response is now personal-liability territory, and the record an executive builds during a breach is the record a jury may one day read.
The firm's named presence in the matter of record for that shift is part of why its principals are retained where security conduct itself is on trial.
The expert dimension
Expert work in a federal criminal trial is examined from both directions at once — by federal prosecutors and by defense counsel — under Rule 702, in front of a judge acting as gatekeeper and a jury instructed to doubt. There is no forum where an unsupported assertion is punished faster. Work built for that environment starts from artifacts the other side also possesses, so that every statement can be verified by the people most motivated to disprove it.
Related capabilities
Expert Witness Services · Court & Arbitral Appointments · Daniel B. Garrie







