Attacks/Breaches

5/30/2018
04:50 PM
50%
50%

Hacker Sentenced to 5 Years in Yahoo Credential Theft Case

Karim Baratov given prison time and seven-figure fine after guilty plea in the massive Yahoo data breach

One of the most prominent computer hacking cases in recent years reached a new chapter as Karim Baratov was sentenced to five years in prison and fined an amount equivalent to his remaining assets. Baratov, a Kazakhstan-born Canadian citizen, was sentenced for his role in the massive Yahoo credentials breach that exposed more than 1 billion records to criminals.

Karim Baratov, aka Kay, aka Karim Taloverov, aka Karim Akehmet Tokbergenov, pleaded guilty to nine charges stemming from the breaches. In addition, he admitted to attempting to hack at least 80 Web mail accounts on behalf of co-conspirators, and to hacking more than 11,000 webmail accounts in total from 2010 through March of 2017.

Baratov was one of four individuals charged in the case, the other three being Russian citizens including two officers of the Russian Federal Security Service (FSB). The other three indicted co-conspirators are Dmitry Aleksandrovich Dokuchaev, Igor Anatolyevich Sushchin, and Alexsey Alexseyevich Belan, (aka Magg, one the FBI's most-wanted cybercriminals), all of whom are currently living in Russia.

Officials from the Department of Justice said in statements that the sentence reflects the serious nature of both the crimes and the way that the DoJ views nation-state sponsored criminal hacking. Baratov was a "hacker for hire" who became a resource of the FSB when it came to gathering credentials that could be used for further breaches.

In pre-sentencing motions, Baratov's lawyers had argued that his mercenary nature made him less culpable for his crime, because he didn't know that he was being hired by the FSB — he would hack an account for anyone. Baratov had claimed that most of his customers were individuals looking for information about the online habits of spouses or lovers, though Department of Justice prosecutors argued that the FSB's request for 80 sets of credentials made the claim less credible in this case.

Ultimately, Baratov was given a sentence that, while lengthy for a cybercrime, was less than the maximum possible under the law. The government had argued for a longer sentence on the grounds that nation-state hacking must be considered more serious than "average" criminal activity.

Related Content:

Curtis Franklin Jr. is Senior Editor at Dark Reading. In this role he focuses on product and technology coverage for the publication. In addition he works on audio and video programming for Dark Reading and contributes to activities at Interop ITX, Black Hat, INsecurity, and ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
REISEN1955
50%
50%
REISEN1955,
User Rank: Ninja
6/4/2018 | 12:37:59 PM
Re: Nation State Hacking
Agree in nature of Yahoo - a fading search engine and right up there with anyone who has --- yes, they still do - an AOL email account.   
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
5/31/2018 | 3:20:30 PM
Nation State Hacking
While I agree that nation state hacking needs to be handled more stringently than private campaigns, I still think proposing a less than maximum sentence fits the crime. I think we need to keep in perspective what was stolen. Yahoo accounts really don't provide individuals with up front sensitive data. This would need to be gleaned through a deep dive of each individual account. 
What We Talk About When We Talk About Risk
Jack Jones, Chairman, FAIR Institute,  7/11/2018
Major International Airport System Access Sold for $10 on Dark Web
Kelly Sheridan, Staff Editor, Dark Reading,  7/11/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-14373
PUBLISHED: 2018-07-17
An issue was discovered in LibTIFF 4.0.9. In TIFFFindField in tif_dirinfo.c, the structure tif is being dereferenced without first checking that the structure is not empty and has the requested fields (tif_foundfield). In the call sequences following from the affected library functions (TIFFVGetFiel...
CVE-2018-14374
PUBLISHED: 2018-07-17
An issue was discovered in LibTIFF 4.0.9. A buffer overflow can occur via an empty fmt argument to unixErrorHandler in tif_unix.c, and it can be exploited (at a minimum) via the following high-level library API functions: TIFFClientOpen, TIFFFdOpen, TIFFRawStripSize, TIFFCheckTile, TIFFComputeStrip,...
CVE-2018-14375
PUBLISHED: 2018-07-17
An issue was discovered in LibTIFF 4.0.9. A buffer overflow vulnerability can occur via an invalid or empty tif argument to TIFFRGBAImageOK in tif_getimage.c, and it can be exploited (at a minimum) via the following high-level library API functions: TIFFReadRGBAImage, TIFFRGBAImageOK, and TIFFRGBAIm...
CVE-2018-14378
PUBLISHED: 2018-07-17
An issue was discovered in LibTIFF 4.0.9. A buffer overflow can occur via an invalid or empty tif argument to TIFFWriteBufferSetup in tif_write.c, and it can be exploited (at a minimum) via the following high-level library API function: TIFFWriteTile.
CVE-2018-14363
PUBLISHED: 2018-07-17
An issue was discovered in NeoMutt before 2018-07-16. newsrc.c does not properly restrict '/' characters that may have unsafe interaction with cache pathnames.