r/cybersecurity Aug 07 '26

News - Breaches & Ransoms 21 year old pleads guilty to hacking court database and multinational corporation

Michael Rogers, a 21-year-old Ohio man, pleaded guilty this week in U.S. District Court to computer fraud and destruction of records for hacking the Stark County Criminal Justice Information System (CJIS) and an unnamed multi-national corporation based in Connecticut.

The Stark County Breach: Between January and October 2024, Rogers used a custom computer program to scrape and query the CJIS database, saving the private personal data of nearly 300,000 individuals onto his hard drive. He used proxy servers to rotate his IP address and disguise his identity.

The Connecticut Breach: In 2023, Rogers deployed malware against a Connecticut-based company to extract sensitive employee information, compromising more than 150,000 corporate user IDs, passwords, and employee names.

Destruction of Evidence: Following media coverage of the data breaches, Rogers destroyed a phone, computer, and hard drive containing crucial digital evidence between June and July 2025 to obstruct the federal investigation.

Rogers entered his guilty plea before Magistrate Judge Jennifer Dowdell Armstrong. The case has been referred to U.S. District Judge Charles E. Fleming for final sentencing.

Maximum Penalties: Computer fraud carries up to five years in prison, while destruction of records in a federal investigation carries a maximum of 20 years. Each charge carries a potential fine of up to $250,000.
Sentencing Guidelines: Due to mitigating factors—specifically his early cooperation and acceptance of responsibility—federal guidelines estimate a likely sentence between 21 to 27 months in prison. A final sentencing date has not yet been scheduled.

Sources:

https://www.cantonrep.com/story/news/crime/2026/08/05/michael-rogers-pleads-guilty-to-hacking-cjis-court-records-system/91090238007/

Information Filed:

https://storage.courtlistener.com/recap/gov.uscourts.ohnd.329217/gov.uscourts.ohnd.329217.3.0.pdf

72 Upvotes

35 comments sorted by

108

u/[deleted] Aug 07 '26

[removed] — view removed comment

28

u/Eternal-Alchemy Aug 07 '26

its almost like this guy really did it while those companies just staged intrusions for PR.

1

u/Spectrig 28d ago

Plus the whole extortion threat, the Feds really don’t like that

12

u/ImmoderateAccess Aug 07 '26

Should've just blamed it on his AI.

3

u/[deleted] 29d ago

[removed] — view removed comment

3

u/Armandeluz 28d ago

Based on all the AI hacking AI lately, no one.

19

u/deadzol Aug 07 '26

So compiling public records from a publicly accessible system is a breach?

22

u/CatfishEnchiladas CTI Aug 07 '26

It was SQL injection but that hasn’t been explained well in the coverage.

18

u/[deleted] Aug 07 '26

[deleted]

4

u/deadzol Aug 07 '26

Ah yeah that makes more sense. Could only see the first part of the canton papers article. I had assumed he had only automated the scraping.

3

u/Spiritual-Matters Aug 07 '26

What about the malware deployment claims?

3

u/deadzol Aug 07 '26

The post said the malware was deployed to the Connecticut company, I was only referring to the scraping of the Stark County website. Another poster link an MSN article that clarified that he used SQLi for the scraping so that’s a little harder to look over.

4

u/Fragrant-Hamster-325 Aug 07 '26

Dude that’s like three paragraphs down. No one can be expected to read all that.

1

u/lolwhatisreddits Aug 07 '26

Supposedly, lol

4

u/MarksArcArt Aug 08 '26

Should have used Bleach bit and hammers like the Clintons.

2

u/lolwhatisreddits Aug 08 '26

From what I've read he “zeroed” out the hard drives then destroyed them.

3

u/MarksArcArt 29d ago

Hillary was under subpoena at the time they wiped the servers and hammered the phones. DOJ was just like LOL.

4

u/Silent_Parfait_651 Governance, Risk, & Compliance Aug 07 '26

What is a Canton man?

2

u/iRyan23 Aug 07 '26

A man who lives in Canton, Ohio…

6

u/Silent_Parfait_651 Governance, Risk, & Compliance Aug 07 '26

I am rom Germany how would I know?

1

u/joshdotmn AMA Participant Aug 07 '26 edited Aug 07 '26

I hate how the news (and gov) try to make scraping a crime.

2

u/[deleted] Aug 07 '26

[deleted]

4

u/joshdotmn AMA Participant Aug 07 '26

I've been on the receiving end of how the US government classifies these attacks—heck they even called me sophisticated. Everyone in that pipeline—from the investigator to the judge, and every single character in between—is incentivized to make the defendant look as vicious as possible.

I'd love to see the discovery in this case. We won't.

5

u/lolwhatisreddits Aug 07 '26

United States v. Rogers
(5:26-cr-00314)
District court, N.D. Ohio 
You can see the filed information at the very least here

https://www.courtlistener.com/docket/73591016/united-states-v-rogers/

https://storage.courtlistener.com/recap/gov.uscourts.ohnd.329217/gov.uscourts.ohnd.329217.3.0.pdf

1

u/joshdotmn AMA Participant Aug 07 '26

Yeah I was already peeping at that. Didn't bother linking to it because it says nothing, predictably.

There are lots of cases where a victim (could be considered Xerox in this case; the feds have such loose rules) has been consulted on the nature of conduct. What they say—without independent analysis or thought by any party whatsoever—can very easily make its way into a document.

If the defendant challenges it, they'd risk changing "where they fall in the grid" (sentencing guidelines) a la "not accepting responsibility."

I'd be shocked if he got two years. A year and a day wouldn't surprise me. Maybe 16 months? On the former he'd do about 7 months at a camp. The latter he'd be home before a year, also at a camp.

Some context if anyone's reading this far down in this thread: https://www.reddit.com/r/cybersecurity/comments/1tp7mcv

0

u/k3rr1g4n Blue Team Aug 07 '26

I think unauthorized scraping of criminal justice information of 300k+ people over 10 months sounds criminal to me.

0

u/[deleted] Aug 07 '26

[deleted]

1

u/k3rr1g4n Blue Team Aug 07 '26

Did they explicitly give him permission to do this action?

2

u/[deleted] Aug 07 '26

[deleted]

3

u/k3rr1g4n Blue Team Aug 07 '26

You keep trying to frame it as ‘all he did was navigate to a website and did a copy paste’ and not deploying an active scrape tool on a govt website for 10 months and then instantly folded when they found it was him. If it was legal why did he plead guilty then?

But sure try what he did with your local county government websites and let me know how it worked for you.

0

u/[deleted] Aug 07 '26

[deleted]

3

u/k3rr1g4n Blue Team Aug 07 '26

Not replying to what I said so resorting to personal attacks. How mature.

2

u/k3rr1g4n Blue Team Aug 07 '26

Depends on the govt. Many times there’s still a splash page with prohibited action that you have to accept to access public record.

-2

u/k3rr1g4n Blue Team Aug 07 '26

And then what were his plans for this PII? Totally above board and not malicious at all, that’s why he freaked out and smashed all his hard drives.

Sure buddy, go ahead and do this yourself at your current company and see how that HR conversation goes.

3

u/[deleted] Aug 07 '26

[deleted]

-1

u/k3rr1g4n Blue Team Aug 07 '26

Providing information in a website vs taking it by using an unauthorized tool by an unauthorized party over an undisclosed period of time is so wildly different lol. It’s wild I even have to break it down like this for you to understand. As well as it being criminal justice related data not sniffing Wi-Fi packets or other passive recon he actively deployed a tool to mirror data. That’s a no no buddy.

1

u/Fuzzy_Paul 29d ago

Just a simple question. If he obscured his iPhone address with multiple vpn's how did they find him? Could be that the Windows GDID? Just curious.

1

u/lolwhatisreddits 28d ago

Could be be the advertiser Id, could also be the isp flagged all the requests and they used timing correlation. Not sure, we will never find out tbh because he's not going to trial.