Attacks/Breaches

Hacker Sentenced to 5 Years in Yahoo Credential Theft Case

Karim Baratov given prison time and seven-figure fine after guilty plea in the massive Yahoo data breach

One of the most prominent computer hacking cases in recent years reached a new chapter as Karim Baratov was sentenced to five years in prison and fined an amount equivalent to his remaining assets. Baratov, a Kazakhstan-born Canadian citizen, was sentenced for his role in the massive Yahoo credentials breach that exposed more than 1 billion records to criminals.

Karim Baratov, aka Kay, aka Karim Taloverov, aka Karim Akehmet Tokbergenov, pleaded guilty to nine charges stemming from the breaches. In addition, he admitted to attempting to hack at least 80 Web mail accounts on behalf of co-conspirators, and to hacking more than 11,000 webmail accounts in total from 2010 through March of 2017.

Baratov was one of four individuals charged in the case, the other three being Russian citizens including two officers of the Russian Federal Security Service (FSB). The other three indicted co-conspirators are Dmitry Aleksandrovich Dokuchaev, Igor Anatolyevich Sushchin, and Alexsey Alexseyevich Belan, (aka Magg, one the FBI's most-wanted cybercriminals), all of whom are currently living in Russia.

Officials from the Department of Justice said in statements that the sentence reflects the serious nature of both the crimes and the way that the DoJ views nation-state sponsored criminal hacking. Baratov was a "hacker for hire" who became a resource of the FSB when it came to gathering credentials that could be used for further breaches.

In pre-sentencing motions, Baratov's lawyers had argued that his mercenary nature made him less culpable for his crime, because he didn't know that he was being hired by the FSB — he would hack an account for anyone. Baratov had claimed that most of his customers were individuals looking for information about the online habits of spouses or lovers, though Department of Justice prosecutors argued that the FSB's request for 80 sets of credentials made the claim less credible in this case.

Ultimately, Baratov was given a sentence that, while lengthy for a cybercrime, was less than the maximum possible under the law. The government had argued for a longer sentence on the grounds that nation-state hacking must be considered more serious than "average" criminal activity.

Related Content:

Curtis Franklin Jr. is Senior Editor at Dark Reading. In this role he focuses on product and technology coverage for the publication. In addition he works on audio and video programming for Dark Reading and contributes to activities at Interop ITX, Black Hat, INsecurity, and ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
REISEN1955
50%
50%
REISEN1955,
User Rank: Ninja
6/4/2018 | 12:37:59 PM
Re: Nation State Hacking
Agree in nature of Yahoo - a fading search engine and right up there with anyone who has --- yes, they still do - an AOL email account.   
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
5/31/2018 | 3:20:30 PM
Nation State Hacking
While I agree that nation state hacking needs to be handled more stringently than private campaigns, I still think proposing a less than maximum sentence fits the crime. I think we need to keep in perspective what was stolen. Yahoo accounts really don't provide individuals with up front sensitive data. This would need to be gleaned through a deep dive of each individual account. 
New Free Tool Scans for Chrome Extension Safety
Dark Reading Staff 2/21/2019
Making the Case for a Cybersecurity Moon Shot
Adam Shostack, Consultant, Entrepreneur, Technologist, Game Designer,  2/19/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
5 Emerging Cyber Threats to Watch for in 2019
Online attackers are constantly developing new, innovative ways to break into the enterprise. This Dark Reading Tech Digest gives an in-depth look at five emerging attack trends and exploits your security team should look out for, along with helpful recommendations on how you can prevent your organization from falling victim.
Flash Poll
How Enterprises Are Attacking the Cybersecurity Problem
How Enterprises Are Attacking the Cybersecurity Problem
Data breach fears and the need to comply with regulations such as GDPR are two major drivers increased spending on security products and technologies. But other factors are contributing to the trend as well. Find out more about how enterprises are attacking the cybersecurity problem by reading our report today.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-9037
PUBLISHED: 2019-02-23
An issue was discovered in libmatio.a in matio (aka MAT File I/O Library) 1.5.13. There is a buffer over-read in the function Mat_VarPrint() in mat.c.
CVE-2019-9038
PUBLISHED: 2019-02-23
An issue was discovered in libmatio.a in matio (aka MAT File I/O Library) 1.5.13. There is an out-of-bounds read problem with a SEGV in the function ReadNextCell() in mat5.c.
CVE-2019-9026
PUBLISHED: 2019-02-23
An issue was discovered in libmatio.a in matio (aka MAT File I/O Library) 1.5.13. There is a heap-based buffer overflow in the function InflateVarName() in inflate.c when called from ReadNextCell in mat5.c.
CVE-2019-9027
PUBLISHED: 2019-02-23
An issue was discovered in libmatio.a in matio (aka MAT File I/O Library) 1.5.13. There is a heap-based buffer overflow problem in the function ReadNextCell() in mat5.c.
CVE-2019-9028
PUBLISHED: 2019-02-23
An issue was discovered in libmatio.a in matio (aka MAT File I/O Library) 1.5.13. There is a stack-based buffer over-read in the function InflateDimensions() in inflate.c when called from ReadNextCell in mat5.c.