Sullivan’s sole focus—in this incident and throughout his distinguished career—has been ensuring the safety of people’s personal data on the Internet.”When Sullivan first learned of the second data breach, he disguised the illegal activity by paying the hackers through Uber’s bug bounty program.Uber had just announced the program in March 2016 in coordination with HackerOne, a widely used security firm whose company values urge executives like Sullivan to “default to disclosure” and ask “why keep this private?” instead of “why make this public?” It took less than a year for Sullivan to use HackerOne’s bug bounty program as a way to avoid disclosing a hack.Those efforts included consulting with an external cybersecurity expert on how to restructure Uber’s security team and how to implement processes to prevent leadership from making the same mistake again.We are changing the way we do business, putting integrity at the core of every decision we make and working hard to earn the trust of our customers.”The Times included a statement in its report from Stephanie M. Hinds, the US attorney for the Northern District of California, where Sullivan’s case was heard, suggesting that Sullivan should serve as an example of how not to handle a hack.“We will not tolerate concealment of important information from the public by corporate executives more interested in protecting their reputation and that of their employers than in protecting users,” Hinds said."