Attacks/Breaches

5/30/2018
04:50 PM
50%
50%

Hacker Sentenced to 5 Years in Yahoo Credential Theft Case

Karim Baratov given prison time and seven-figure fine after guilty plea in the massive Yahoo data breach

One of the most prominent computer hacking cases in recent years reached a new chapter as Karim Baratov was sentenced to five years in prison and fined an amount equivalent to his remaining assets. Baratov, a Kazakhstan-born Canadian citizen, was sentenced for his role in the massive Yahoo credentials breach that exposed more than 1 billion records to criminals.

Karim Baratov, aka Kay, aka Karim Taloverov, aka Karim Akehmet Tokbergenov, pleaded guilty to nine charges stemming from the breaches. In addition, he admitted to attempting to hack at least 80 Web mail accounts on behalf of co-conspirators, and to hacking more than 11,000 webmail accounts in total from 2010 through March of 2017.

Baratov was one of four individuals charged in the case, the other three being Russian citizens including two officers of the Russian Federal Security Service (FSB). The other three indicted co-conspirators are Dmitry Aleksandrovich Dokuchaev, Igor Anatolyevich Sushchin, and Alexsey Alexseyevich Belan, (aka Magg, one the FBI's most-wanted cybercriminals), all of whom are currently living in Russia.

Officials from the Department of Justice said in statements that the sentence reflects the serious nature of both the crimes and the way that the DoJ views nation-state sponsored criminal hacking. Baratov was a "hacker for hire" who became a resource of the FSB when it came to gathering credentials that could be used for further breaches.

In pre-sentencing motions, Baratov's lawyers had argued that his mercenary nature made him less culpable for his crime, because he didn't know that he was being hired by the FSB — he would hack an account for anyone. Baratov had claimed that most of his customers were individuals looking for information about the online habits of spouses or lovers, though Department of Justice prosecutors argued that the FSB's request for 80 sets of credentials made the claim less credible in this case.

Ultimately, Baratov was given a sentence that, while lengthy for a cybercrime, was less than the maximum possible under the law. The government had argued for a longer sentence on the grounds that nation-state hacking must be considered more serious than "average" criminal activity.

Related Content:

Curtis Franklin Jr. is Senior Editor at Dark Reading. In this role he focuses on product and technology coverage for the publication. In addition he works on audio and video programming for Dark Reading and contributes to activities at Interop ITX, Black Hat, INsecurity, and ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
REISEN1955
50%
50%
REISEN1955,
User Rank: Ninja
6/4/2018 | 12:37:59 PM
Re: Nation State Hacking
Agree in nature of Yahoo - a fading search engine and right up there with anyone who has --- yes, they still do - an AOL email account.   
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
5/31/2018 | 3:20:30 PM
Nation State Hacking
While I agree that nation state hacking needs to be handled more stringently than private campaigns, I still think proposing a less than maximum sentence fits the crime. I think we need to keep in perspective what was stolen. Yahoo accounts really don't provide individuals with up front sensitive data. This would need to be gleaned through a deep dive of each individual account. 
New Cold Boot Attack Gives Hackers the Keys to PCs, Macs
Kelly Sheridan, Staff Editor, Dark Reading,  9/13/2018
Yahoo Class-Action Suits Set for Settlement
Dark Reading Staff 9/17/2018
RDP Ports Prove Hot Commodities on the Dark Web
Kelly Sheridan, Staff Editor, Dark Reading,  9/17/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Flash Poll
How Data Breaches Affect the Enterprise
How Data Breaches Affect the Enterprise
This report, offers new data on the frequency of data breaches, the losses they cause, and the steps that organizations are taking to prevent them in the future. Read the report today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-3912
PUBLISHED: 2018-09-18
Bypassing password security vulnerability in McAfee Application and Change Control (MACC) 7.0.1 and 6.2.0 allows authenticated users to perform arbitrary command execution via a command-line utility.
CVE-2018-6690
PUBLISHED: 2018-09-18
Accessing, modifying, or executing executable files vulnerability in Microsoft Windows client in McAfee Application and Change Control (MACC) 8.0.0 Hotfix 4 and earlier allows authenticated users to execute arbitrary code via file transfer from external system.
CVE-2018-6693
PUBLISHED: 2018-09-18
An unprivileged user can delete arbitrary files on a Linux system running ENSLTP 10.5.1, 10.5.0, and 10.2.3 Hotfix 1246778 and earlier. By exploiting a time of check to time of use (TOCTOU) race condition during a specific scanning sequence, the unprivileged user is able to perform a privilege escal...
CVE-2018-16515
PUBLISHED: 2018-09-18
Matrix Synapse before 0.33.3.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper transaction and event signature validation.
CVE-2018-16794
PUBLISHED: 2018-09-18
Microsoft ADFS 4.0 Windows Server 2016 and previous (Active Directory Federation Services) has an SSRF vulnerability via the txtBoxEmail parameter in /adfs/ls.