{"id":12648,"date":"2016-07-21T11:04:54","date_gmt":"2016-07-21T15:04:54","guid":{"rendered":"https:\/\/www.kaspersky.com\/blog\/?p=12648"},"modified":"2019-11-15T06:55:18","modified_gmt":"2019-11-15T11:55:18","slug":"mlb-hacker-sentenced","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com\/blog\/mlb-hacker-sentenced\/12648\/","title":{"rendered":"Cardinals hacker gets 4 years in prison"},"content":{"rendered":"<p>In sports, teams are always looking for ways to get ahead. Players and teams continually, frantically search for new ways to squash their competition en route to claiming another title. After all, the more they win, the more they get paid.<\/p>\n<p>Sometimes that involves the use of performance-enhancing drugs, substances that could help with eluding opponents, improving a grip, or theatrical flopping \u2014 an edge is an edge right? Last year, we saw Major League Baseball\u2019s St. Louis Cardinals take the competitive edge to a new level \u2014 hacking.<\/p>\n<p>Yes, you read that correctly. Back in June of last year, <a href=\"https:\/\/twitter.com\/dennisf\" target=\"_blank\" rel=\"noopener nofollow\">Dennis Fisher<\/a> penned a <a href=\"https:\/\/threatpost.com\/fbi-investigating-alleged-attack-on-houston-astros\/113342\/\" target=\"_blank\" rel=\"noopener nofollow\">story on Threatpost<\/a> with this lede: <em>\u201cIn one of the more bizarre alleged hacking stories to emerge recently, federal authorities are investigating whether employees\u00a0of the St. Louis Cardinals hacked into systems belonging to the Houston Astros and got access to internal team conversations about players, trades, scouting reports, and other sensitive information.\u201d<\/em><\/p>\n<p>As anyone knows who reads Kaspersky Daily or Threatpost regularly, hacking is nothing new, and it actually happens quite regularly. What made this hack noteworthy was not that it happened, but rather <em>how<\/em> it happened.<\/p>\n<p>Houston Astros General Manager Jeff Luhnow was a polarizing executive during his time with the Cardinals. And according to initial reports on this story, it appeared that executives from the Cardinals tried to access the Astros\u2019 systems by using Luhnow\u2019s old passwords.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">Ex-<a href=\"https:\/\/twitter.com\/hashtag\/Cardinals?src=hash&amp;ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">#Cardinals<\/a> Exec Sentenced Four Years for <a href=\"https:\/\/twitter.com\/hashtag\/Astros?src=hash&amp;ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">#Astros<\/a> Hack: <a href=\"https:\/\/t.co\/EzrMyQMrCE\" target=\"_blank\" rel=\"noopener nofollow\">https:\/\/t.co\/EzrMyQMrCE<\/a> <a href=\"https:\/\/twitter.com\/hashtag\/MLB?src=hash&amp;ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">#MLB<\/a> via <a href=\"https:\/\/twitter.com\/threatpost?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">@threatpost<\/a> <a href=\"https:\/\/t.co\/n2ztP1OVJM\" target=\"_blank\" rel=\"noopener nofollow\">pic.twitter.com\/n2ztP1OVJM<\/a><\/p>\n<p>\u2014 Kaspersky (@kaspersky) <a href=\"https:\/\/twitter.com\/kaspersky\/status\/755477965350301697?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">July 19, 2016<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>Now fast forward a little over a year from the initial reports. Chris Correa, a former scouting director for the Cardinals, has been sentenced to 46 months in prison after admitting that he had hacked the databases.<\/p>\n<p>According to the <a href=\"http:\/\/www.stltoday.com\/news\/local\/metro\/former-cardinals-scouting-director-sentenced-to-months-for-hacking-astros\/article_442f4c83-0de3-5b45-9fe9-8cd3736b6827.html\" target=\"_blank\" rel=\"noopener nofollow\">St. Louis Post-Dispatch<\/a>: \u201cDuring his guilty plea six months ago, Correa contended he hacked into the Astros accounts to see if former Cardinals employees had taken proprietary data or statistical models to use in their new positions with the Astros. Correa told prosecutors he found evidence that it did occur.\u201d<\/p>\n<p>Looking at the above statement, you can see there may have been some forces for good at play, but even if so, the execution was just wrong. It also goes to show that when you access data without permission, there can be real-world repercussions. So \u2014 don\u2019t hack, kids. Even if you think your motives are good or fair. Even if you are not using any special hacking software and are just logging into someone else\u2019s account with their password, which you happen to know.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">Cybercrimes \u2013 Real Sentences. Check out the latest list of cybercriminals now facing arrest and prosecution. <a href=\"http:\/\/t.co\/gW5wHsL4Ma\" target=\"_blank\" rel=\"noopener nofollow\">http:\/\/t.co\/gW5wHsL4Ma<\/a><\/p>\n<p>\u2014 Kaspersky (@kaspersky) <a href=\"https:\/\/twitter.com\/kaspersky\/status\/326806543695757313?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">April 23, 2013<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>The incident also shows that it is not a good idea to share passwords, or to reuse them. If former coworkers knew of a common password(s) and\/or user name(s) used by Luhnow, they could have gotten to much more sensitive information than baseball prospect notes and personnel information \u2014 they could potentially have obtained personal financial information.<\/p>\n<p>This particular case happened in MLB, but that is not to say any other sort of team looking to gain an edge would not to do this \u2014 say, in the Premier League, FIFA, or the Olympics. And it probably does happen; we simply don\u2019t know about it yet.<\/p>\n<p>So, a short takeaway:<\/p>\n<ol>\n<li>Once again, don\u2019t hack. Just don\u2019t.<\/li>\n<li>Use passwords appropriately and well. You can read about password reuse and freshness <a href=\"https:\/\/www.kaspersky.com\/blog\/passwords-are-like-underwear\/10645\/\" target=\"_blank\" rel=\"noopener nofollow\">here<\/a>, and check if your passwords are good enough <a href=\"https:\/\/password.kaspersky.com\/\" target=\"_blank\" rel=\"noopener\">here<\/a>.<\/li>\n<\/ol>\n","protected":false},"excerpt":{"rendered":"<p>A story of dumb password usage, good intentions, and bad actions \u2014 and how all these led to the imprisonment of a former St. Louis Cardinals scouting director.<\/p>\n","protected":false},"author":636,"featured_media":12649,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5],"tags":[1721,82,1724,1722,1720,1723],"class_list":{"0":"post-12648","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-news","8":"tag-chris-correa","9":"tag-hacking","10":"tag-hacking-sentence","11":"tag-houston-astros","12":"tag-mlb","13":"tag-st-louis-cardinals"},"hreflang":[{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/mlb-hacker-sentenced\/12648\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/mlb-hacker-sentenced\/7432\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/mlb-hacker-sentenced\/7414\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/mlb-hacker-sentenced\/8756\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/mlb-hacker-sentenced\/8658\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/mlb-hacker-sentenced\/5890\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/mlb-hacker-sentenced\/8263\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/mlb-hacker-sentenced\/12059\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/mlb-hacker-sentenced\/12648\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/mlb-hacker-sentenced\/12648\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com\/blog\/tag\/chris-correa\/","name":"Chris Correa"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/12648","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/users\/636"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/comments?post=12648"}],"version-history":[{"count":1,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/12648\/revisions"}],"predecessor-version":[{"id":30211,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/12648\/revisions\/30211"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media\/12649"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media?parent=12648"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/categories?post=12648"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/tags?post=12648"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}