How a Cardinals executive hacked the Astros with an old reused password
The St. Louis Cardinals executive who broke into the Houston Astros' private scouting database did not need any hacking skills. He used a variation of a password a former colleague had used on his old Cardinals laptop.[1] This case file covers how a reused password opened a rival's crown jewels, why a password reset did not lock him out, what it cost the man and the team, and the one control that was missing.
What happened
Christopher Correa worked for the Cardinals from 2009 to 2015 and became their director of baseball development in 2013, providing analytics support to the front office.[1] Late in 2011 a Cardinals colleague left for a job with the Astros. When he departed, he turned in his Cardinals laptop and its password to Correa.[1][3]
In Houston, the Astros had built a private web database called Ground Control holding scouting reports, player evaluations and trade talks.[3] Starting in March 2013, Correa used a variation of the former colleague's old password to get into that employee's Astros email and Ground Control accounts.[1][2] He went in at the moments that mattered most, including around the June 2013 amateur draft and on July 31, 2013, the trade deadline, reading scout rankings of draft-eligible players and notes on trade discussions with other clubs.[1][3]
In March 2014, a newspaper story revealed the database's web address, and the Astros saw attempts to get in. They moved the site to a new address, reset every password to a complex default, and emailed the new logins to staff that evening.[2][3] The next day Correa read that email in the former colleague's inbox, took the new password and address, and logged in as a different Astros employee. He viewed 118 pages, including the team's unfinished 2014 draft board.[1][3]
How they got in
Two ordinary habits did the work. First, the former colleague had apparently carried a close variation of an old password into his new job, and the person who had been handed that old password could guess the new one.[1][2] Nobody forced a truly fresh password when he joined a new organization, and a password alone was enough to get in.
Second, the Astros' fix depended on email. The emergency reset sent new passwords to inboxes, and one of those inboxes was already open to the intruder. Changing the lock and mailing the new key to the same address the burglar was reading did not keep him out.[3] Prosecutors said Correa also hid his identity, location and the type of device he used while logging in.[2]
How it was caught
The Astros spotted attempts to get into the database in March 2014, and the case became a federal investigation.[3][4] Correa's employment with the Cardinals ended in July 2015, and on January 8, 2016, he pleaded guilty in federal court in Houston to 5 counts of unauthorized access of a protected computer.[1][2] Major League Baseball said its own inquiry, along with those by the FBI, the Justice Department and the Cardinals, found he acted alone.[4]
What it cost
On July 18, 2016, a federal judge sentenced Correa to 46 months in prison, 2 years of supervised release and $279,038.65 in restitution. Prosecutors estimated the Astros' loss at about $1.7 million.[1] The judge told him he had made life harder for the people whose work he took.[1]
On January 30, 2017, baseball's commissioner ordered the Cardinals to pay the Astros $2 million and hand over their first 2 picks in that year's draft, numbers 56 and 75. Correa was placed on the league's permanently ineligible list.[4][5] The commissioner held the club responsible for its employee's conduct even though the team had not authorized it.[6]
The missing control
The missing control: a forced new, unique password plus multi-factor login. A new hire should never be able to reuse a close version of an old employer's password, and a password alone should never be enough to open email or a crown-jewel database.
With multi-factor login, knowing or guessing the password would have gotten Correa nowhere without the employee's phone or security key. The same safeguard would have protected the March 2014 reset, because a new password pulled from an email would still have needed that second step. And if new staff had to set fresh passwords that were checked against their old ones, the variation he guessed would not have existed in the first place.
What to do in your business
- Turn on multi-factor login for email first. Email is the key to every other reset, so protect it with an app prompt or security key for every user.
- Make new hires start clean. During onboarding, have new staff create brand-new passwords, ideally with a password manager, and tell them not to reuse anything from a previous job.
- Do not send new passwords by email. After a suspected breach, hand out temporary logins by phone or in person, force a change at first login, and require multi-factor at the same time.
- Collect and retire old credentials properly. When someone leaves, disable their accounts and never keep their passwords on file. No one should hold a departed employee's login.
- Watch for logins from odd places. Turn on alerts in your email and key systems for sign-ins from new devices, locations or anonymizing services.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: Employee offboarding checklist: how to cut off a former employee's access the same day
- Guide: How to verify callers before password resets, and protect your phone number from SIM swaps
- Guide: Which two-step login actually stops phishing, and how a small office rolls it out
- How the SEC's X account was hacked: a fake ID, a SIM swap and no MFA
- How the Colonial Pipeline hack happened: one unused VPN account and no MFA
- How the 2020 Twitter hack happened: a fake help desk call and an admin tool
- How the Mirai botnet knocked Twitter and Netflix offline with factory passwords
- How the Ronin bridge was hacked: a fake job offer and $600 million
- How Uber got hacked in 2022: a stolen password and one tired tap
- Every identity and access control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- U.S. Department of Justice: Former Cardinals official sentenced to prison for Astros computer intrusions
- U.S. Attorney's Office, S.D. Tex.: Former St. Louis Cardinals official pleads guilty to Houston Astros computer intrusions
- Houston Chronicle: How Chris Correa hacked the Astros' system and emails at crucial times
- MLB.com: Astros awarded Cardinals' first two Draft picks
- Sports Illustrated: Cardinals given stiff fine, docked draft picks for hacking scandal
- CNN: Cardinals fined $2 million, lose draft picks over Astros hacking