• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechCybersecurity

Everything you need to know about the bizarre Astros baseball hack

Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
June 17, 2015, 10:05 AM ET
St Louis Cardinals v Houston Astros
KISSIMMEE, FL - MARCH 10: Thomas Pham #60 of the St. Louis Cardinals swings at a pitch during a spring training game against the Houston Astros at Osceola County Stadium on March 10, 2015 in Kissimmee, Florida. (Photo by Stacy Revere/Getty Images)!Stacy Revere — Getty Images

The Federal Bureau of Investigation is investigating St. Louis Cardinals front office employees for allegedly hacking into the computer systems of the Houston Astros, the New York Times reported Tuesday.

That word “hacking” has a funny ring to it once you dig into the details—this was by no means a high-tech affair on the level of foreign intrusions into American government networks. Yet this is exactly what a lot of “hacking” involves: Lapses, blunders, and bungles. It doesn’t take a crack squad of NSA whizzes to shuck open protected databases like a washed ashore shellfish. A target who fails to use proper password protections is all any adversary needs.

The primary victim in the Astros case, Jeff Luhnow, once worked for the Cardinals as a statistics expert. There he built a luminary database tool to give the team an edge, codenamed “Red Bird Dog.” But he never quite fit in there, as a profile in Businessweek details. Luhnow eventually flew the Cardinals coop, bringing his know-how in developing a signature data analytics platform with him to Houston. This one was called “Ground Control.” Its aim? To rejuvenate the struggling baseball team via big data and predictive analytics.

For all its Moneyball-esque hype, Luhnow’s secret weapon seems to have been felled by nothing short of bad password hygiene. As the law enforcement officers cited by the Times suggest, Luhnow failed to refresh the password protections on his system when developing the new tool at—or porting it over to—his new gig:*

Investigators believe Cardinals officials, concerned that Mr. Luhnow had taken their idea and proprietary baseball information to the Astros, examined a master list of passwords used by Mr. Luhnow and the other officials who had joined the Astros when they worked for the Cardinals. The Cardinals officials are believed to have used those passwords to gain access to the Astros’ network, law enforcement officials said.

The investigators presume Luhnow’s former colleagues gained access to the Astros’ precious database simply by peaking at Luhnow’s old passwords list. But Luhnow isn’t the only person to be sloppy; the so-called hackers were no better.

As if Luhnow’s possible password reuse wasn’t enough, the thieves—believed to be Luhnow’s old colleagues in the Cardinals’ front office—apparently launched the intrusion right from their own home. “Agents soon found that the Astros’ network had been entered from a computer at a home that some Cardinals officials had lived in,” the Times says. That’s a rookie mistake. As Deadspin writer Tom Ley advises, “Go find, like, an Internet cafe or something.”

But one detail from the story seems out of place. Why would Cardinals officials bother to post nearly a year’s worth of hacked Astros’ data to Anonbin, an online repository for leaked information? Was it done simply as a covert smear tactic to embarrass the Astros? Wouldn’t it be wiser to keep that information private and use it solely to gain a competitive advantage?

Of course, the investigation is ongoing, there is no way to know for sure who did what just yet. Perhaps the Cardinals and Major League Baseball officials’ subpoenaed communications will reveal more information. But if the reports are to be believed, then Moneyball-style stats may have revolutionized the game, but MLB officials are still dopes when it comes to cybersecurity.

Subscribe to Data Sheet, Fortune’s daily newsletter on the business of technology.

***

* Update June 18, 2015: In an exclusive interview with Sports Illustrated, a sibling publication to Fortune, Astros’ general manager Jeff Luhnow disputed a number of the claims in the original New York Times story. He says he did not recycle passwords between the databases (to wit: “that’s absolutely false”), did not take any proprietary information from his time at the Cardinals with him to the Astros (“I didn’t take anything, any proprietary information. Nor have we ever received any inquiries from anybody that even suggested that we had”), and did not have a strained relationship with his former colleagues (“This wasn’t a bad breakup. It was a happy promotion of a person to a higher position in another organization”). Read the full report on SI.com.

About the Author
Robert Hackett
By Robert Hackett
Instagram iconLinkedIn iconTwitter icon
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

A SpaceX Falcon 9 rocket is displayed outside a Space Exploration Technologies Corp. facility in Hawthorne, California.
Startups & VentureElon Musk
SpaceX has filed confidentially for IPO ahead of AI rivals
By Bailey Lipschultz, Edward Ludlow and BloombergApril 1, 2026
2 hours ago
AI ‘slop’ is flooding YouTube Kids—and more than 200 groups and experts are calling for a ban
CybersecurityYouTube
AI ‘slop’ is flooding YouTube Kids—and more than 200 groups and experts are calling for a ban
By Catherina GioinoApril 1, 2026
2 hours ago
Deutsche Bank asked AI if it’s true that AI will solve the economy’s inflation problems. The robots answered
Economydisruption
Deutsche Bank asked AI if it’s true that AI will solve the economy’s inflation problems. The robots answered
By Nick LichtenbergApril 1, 2026
2 hours ago
ntsb
LawAutos
Why hands-free systems in self-driving cars aren’t actually safer, according to the NTSB
By Josh Funk and The Associated PressApril 1, 2026
2 hours ago
Mike Wirth, chief executive officer of Chevron.
EnergyData centers
Microsoft and Chevron enter exclusivity deal on powering West Texas AI data center complex
By Jordan BlumApril 1, 2026
3 hours ago
A chip research center site operations manager stands next to a window overlooking the facility.
EnvironmentData centers
Data centers are so hot their ‘heat island’ effect is raising temperatures up to 6 miles away and impacting 343 million people worldwide, study finds
By Sasha RogelbergApril 1, 2026
5 hours ago

Most Popular

Jerome Powell says the $39 trillion national debt is ‘not unsustainable,’ but warns the trajectory ‘will not end well’
Economy
Jerome Powell says the $39 trillion national debt is ‘not unsustainable,’ but warns the trajectory ‘will not end well’
By Fortune EditorsMarch 30, 2026
2 days ago
Two-thirds of parents say their adult Gen Z kids still rely on them financially  for support—even though it's putting them under strain
Success
Two-thirds of parents say their adult Gen Z kids still rely on them financially  for support—even though it's putting them under strain
By Fortune EditorsMarch 31, 2026
1 day ago
Kevin O'Leary says if you earn $68,000 a year and follow this rule, you'll retire a millionaire
Personal Finance
Kevin O'Leary says if you earn $68,000 a year and follow this rule, you'll retire a millionaire
By Fortune EditorsMarch 31, 2026
1 day ago
A man used AI to call 3,000 Irish bartenders to track the cost of Guinness. Now pubs are lowering their prices to compete
AI
A man used AI to call 3,000 Irish bartenders to track the cost of Guinness. Now pubs are lowering their prices to compete
By Fortune EditorsMarch 30, 2026
2 days ago
Hiring just hit a level not seen since the economy was ‘closed down literally’ during COVID, top economist says
Economy
Hiring just hit a level not seen since the economy was ‘closed down literally’ during COVID, top economist says
By Fortune EditorsMarch 31, 2026
1 day ago
Markets cheer as Trump threatens to abandon Iran war, but Jamie Dimon sides with allies: ‘Win this thing and clean up the straits’
Energy
Markets cheer as Trump threatens to abandon Iran war, but Jamie Dimon sides with allies: ‘Win this thing and clean up the straits’
By Fortune EditorsMarch 31, 2026
1 day ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.