Attacks/Breaches

5/30/2018
04:50 PM
50%
50%

Hacker Sentenced to 5 Years in Yahoo Credential Theft Case

Karim Baratov given prison time and seven-figure fine after guilty plea in the massive Yahoo data breach

One of the most prominent computer hacking cases in recent years reached a new chapter as Karim Baratov was sentenced to five years in prison and fined an amount equivalent to his remaining assets. Baratov, a Kazakhstan-born Canadian citizen, was sentenced for his role in the massive Yahoo credentials breach that exposed more than 1 billion records to criminals.

Karim Baratov, aka Kay, aka Karim Taloverov, aka Karim Akehmet Tokbergenov, pleaded guilty to nine charges stemming from the breaches. In addition, he admitted to attempting to hack at least 80 Web mail accounts on behalf of co-conspirators, and to hacking more than 11,000 webmail accounts in total from 2010 through March of 2017.

Baratov was one of four individuals charged in the case, the other three being Russian citizens including two officers of the Russian Federal Security Service (FSB). The other three indicted co-conspirators are Dmitry Aleksandrovich Dokuchaev, Igor Anatolyevich Sushchin, and Alexsey Alexseyevich Belan, (aka Magg, one the FBI's most-wanted cybercriminals), all of whom are currently living in Russia.

Officials from the Department of Justice said in statements that the sentence reflects the serious nature of both the crimes and the way that the DoJ views nation-state sponsored criminal hacking. Baratov was a "hacker for hire" who became a resource of the FSB when it came to gathering credentials that could be used for further breaches.

In pre-sentencing motions, Baratov's lawyers had argued that his mercenary nature made him less culpable for his crime, because he didn't know that he was being hired by the FSB — he would hack an account for anyone. Baratov had claimed that most of his customers were individuals looking for information about the online habits of spouses or lovers, though Department of Justice prosecutors argued that the FSB's request for 80 sets of credentials made the claim less credible in this case.

Ultimately, Baratov was given a sentence that, while lengthy for a cybercrime, was less than the maximum possible under the law. The government had argued for a longer sentence on the grounds that nation-state hacking must be considered more serious than "average" criminal activity.

Related Content:

Curtis Franklin Jr. is Senior Editor at Dark Reading. In this role he focuses on product and technology coverage for the publication. In addition he works on audio and video programming for Dark Reading and contributes to activities at Interop ITX, Black Hat, INsecurity, and ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
REISEN1955
50%
50%
REISEN1955,
User Rank: Ninja
6/4/2018 | 12:37:59 PM
Re: Nation State Hacking
Agree in nature of Yahoo - a fading search engine and right up there with anyone who has --- yes, they still do - an AOL email account.   
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
5/31/2018 | 3:20:30 PM
Nation State Hacking
While I agree that nation state hacking needs to be handled more stringently than private campaigns, I still think proposing a less than maximum sentence fits the crime. I think we need to keep in perspective what was stolen. Yahoo accounts really don't provide individuals with up front sensitive data. This would need to be gleaned through a deep dive of each individual account. 
Microsoft President: Governments Must Cooperate on Cybersecurity
Kelly Sheridan, Staff Editor, Dark Reading,  11/8/2018
To Click or Not to Click: The Answer Is Easy
Kowsik Guruswamy, Chief Technology Officer at Menlo Security,  11/14/2018
Veterans Find New Roles in Enterprise Cybersecurity
Kelly Sheridan, Staff Editor, Dark Reading,  11/12/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Flash Poll
Online Malware and Threats: A Profile of Today's Security Posture
Online Malware and Threats: A Profile of Today's Security Posture
This report offers insight on how security professionals plan to invest in cybersecurity, and how they are prioritizing their resources. Find out what your peers have planned today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-19279
PUBLISHED: 2018-11-14
PRIMX ZoneCentral before 6.1.2236 on Windows sometimes leaks the plaintext of NTFS files. On non-SSD devices, this is limited to a 5-second window and file sizes less than 600 bytes. The effect on SSD devices may be greater.
CVE-2018-19280
PUBLISHED: 2018-11-14
Centreon 3.4.x has XSS via the resource name or macro expression of a poller macro.
CVE-2018-19281
PUBLISHED: 2018-11-14
Centreon 3.4.x allows SNMP trap SQL Injection.
CVE-2018-17960
PUBLISHED: 2018-11-14
CKEditor 4.x before 4.11.0 allows user-assisted XSS involving a source-mode paste.
CVE-2018-19278
PUBLISHED: 2018-11-14
Buffer overflow in DNS SRV and NAPTR lookups in Digium Asterisk 15.x before 15.6.2 and 16.x before 16.0.1 allows remote attackers to crash Asterisk via a specially crafted DNS SRV or NAPTR response, because a buffer size is supposed to match an expanded length but actually matches a compressed lengt...