AWSCIO BriefingsRetrospectives

CIO Brief: Breach Concealment, Disclosure Laws and the Uber Lesson

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from November 2017, written in 2026 with the benefit of hindsight.

The short version: Uber's 2016 breach began with cloud passwords left in a code repository. What made it infamous was the cover-up: the company paid the attackers, hid the breach for a year, and its security chief was later convicted of a federal crime.

Why disclosure decisions belong to leadership

Breach notification laws, regulators and courts now expect timely, honest disclosure. Treating a breach as a private matter between the security team and the attackers is no longer defensible — for the company or for the individuals involved.

The business impact

  • Regulatory penalties for late or missing notification, often larger than the breach itself.
  • Personal legal risk for executives who conceal incidents.
  • Trust damage when the concealment comes out, as it usually does.

Questions to ask your team

  • Do we have a documented incident response plan that includes legal counsel and disclosure decisions?
  • Who decides whether an incident must be reported, and within what timeframe?
  • Do we know our obligations — state laws, SEC rules if public, sector regulators, contracts?
  • Are cloud passwords and keys ever stored in our code?

What good looks like

An incident response plan with clear escalation to legal and leadership, pre-identified outside counsel and forensics firms, documented disclosure decisions, and technical controls that keep secrets out of code.

The decision

Run a tabletop exercise that ends with a disclosure decision. The point is not the technical response; it is making sure leadership knows its obligations before the clock starts.

uber data breach 2016 impactUber AWS keys in GitHub2017

More on this story