CIO Brief: Breach Concealment, Disclosure Laws and the Uber Lesson
Retrospective: this article looks back at events from November 2017, written in 2026 with the benefit of hindsight.
The short version: Uber's 2016 breach began with cloud passwords left in a code repository. What made it infamous was the cover-up: the company paid the attackers, hid the breach for a year, and its security chief was later convicted of a federal crime.
Why disclosure decisions belong to leadership
Breach notification laws, regulators and courts now expect timely, honest disclosure. Treating a breach as a private matter between the security team and the attackers is no longer defensible — for the company or for the individuals involved.
The business impact
- Regulatory penalties for late or missing notification, often larger than the breach itself.
- Personal legal risk for executives who conceal incidents.
- Trust damage when the concealment comes out, as it usually does.
Questions to ask your team
- Do we have a documented incident response plan that includes legal counsel and disclosure decisions?
- Who decides whether an incident must be reported, and within what timeframe?
- Do we know our obligations — state laws, SEC rules if public, sector regulators, contracts?
- Are cloud passwords and keys ever stored in our code?
What good looks like
An incident response plan with clear escalation to legal and leadership, pre-identified outside counsel and forensics firms, documented disclosure decisions, and technical controls that keep secrets out of code.
The decision
Run a tabletop exercise that ends with a disclosure decision. The point is not the technical response; it is making sure leadership knows its obligations before the clock starts.
- Uber's Hidden Breach (Disclosed Nov 2017): AWS Keys in a Private GitHub Repo Incident Teardowns
- How to Prevent Hardcoded AWS Keys With Secret Scanning and IAM Roles How-To & Hardening
- Detecting Leaked AWS Access Keys: CloudTrail, GuardDuty and Athena Queries Detection & Response