Case file · ASTROS HACK 2013

How a Cardinals executive hacked the Astros with an old reused password

Published 2026-09-29 · 5 min read · Missing control: Force new unique passwords plus MFA

The St. Louis Cardinals executive who broke into the Houston Astros' private scouting database did not need any hacking skills. He used a variation of a password a former colleague had used on his old Cardinals laptop.[1] This case file covers how a reused password opened a rival's crown jewels, why a password reset did not lock him out, what it cost the man and the team, and the one control that was missing.

What happened

Christopher Correa worked for the Cardinals from 2009 to 2015 and became their director of baseball development in 2013, providing analytics support to the front office.[1] Late in 2011 a Cardinals colleague left for a job with the Astros. When he departed, he turned in his Cardinals laptop and its password to Correa.[1][3]

In Houston, the Astros had built a private web database called Ground Control holding scouting reports, player evaluations and trade talks.[3] Starting in March 2013, Correa used a variation of the former colleague's old password to get into that employee's Astros email and Ground Control accounts.[1][2] He went in at the moments that mattered most, including around the June 2013 amateur draft and on July 31, 2013, the trade deadline, reading scout rankings of draft-eligible players and notes on trade discussions with other clubs.[1][3]

In March 2014, a newspaper story revealed the database's web address, and the Astros saw attempts to get in. They moved the site to a new address, reset every password to a complex default, and emailed the new logins to staff that evening.[2][3] The next day Correa read that email in the former colleague's inbox, took the new password and address, and logged in as a different Astros employee. He viewed 118 pages, including the team's unfinished 2014 draft board.[1][3]

How they got in

Two ordinary habits did the work. First, the former colleague had apparently carried a close variation of an old password into his new job, and the person who had been handed that old password could guess the new one.[1][2] Nobody forced a truly fresh password when he joined a new organization, and a password alone was enough to get in.

Second, the Astros' fix depended on email. The emergency reset sent new passwords to inboxes, and one of those inboxes was already open to the intruder. Changing the lock and mailing the new key to the same address the burglar was reading did not keep him out.[3] Prosecutors said Correa also hid his identity, location and the type of device he used while logging in.[2]

How it was caught

The Astros spotted attempts to get into the database in March 2014, and the case became a federal investigation.[3][4] Correa's employment with the Cardinals ended in July 2015, and on January 8, 2016, he pleaded guilty in federal court in Houston to 5 counts of unauthorized access of a protected computer.[1][2] Major League Baseball said its own inquiry, along with those by the FBI, the Justice Department and the Cardinals, found he acted alone.[4]

What it cost

On July 18, 2016, a federal judge sentenced Correa to 46 months in prison, 2 years of supervised release and $279,038.65 in restitution. Prosecutors estimated the Astros' loss at about $1.7 million.[1] The judge told him he had made life harder for the people whose work he took.[1]

On January 30, 2017, baseball's commissioner ordered the Cardinals to pay the Astros $2 million and hand over their first 2 picks in that year's draft, numbers 56 and 75. Correa was placed on the league's permanently ineligible list.[4][5] The commissioner held the club responsible for its employee's conduct even though the team had not authorized it.[6]

The missing control

The missing control: a forced new, unique password plus multi-factor login. A new hire should never be able to reuse a close version of an old employer's password, and a password alone should never be enough to open email or a crown-jewel database.

With multi-factor login, knowing or guessing the password would have gotten Correa nowhere without the employee's phone or security key. The same safeguard would have protected the March 2014 reset, because a new password pulled from an email would still have needed that second step. And if new staff had to set fresh passwords that were checked against their old ones, the variation he guessed would not have existed in the first place.

What to do in your business

Watch the case
How a Cardinals exec got into the Astros' secret databaseDrops 2026-11-20
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More identity and access cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. U.S. Department of Justice: Former Cardinals official sentenced to prison for Astros computer intrusions
  2. U.S. Attorney's Office, S.D. Tex.: Former St. Louis Cardinals official pleads guilty to Houston Astros computer intrusions
  3. Houston Chronicle: How Chris Correa hacked the Astros' system and emails at crucial times
  4. MLB.com: Astros awarded Cardinals' first two Draft picks
  5. Sports Illustrated: Cardinals given stiff fine, docked draft picks for hacking scandal
  6. CNN: Cardinals fined $2 million, lose draft picks over Astros hacking