David Aragona is a respected voice in the world of horse racing, and he has no connection to Marshall Gramm. He wrote on X on Thursday, “Marshall Gramm’s actions were despicable, especially given his position of repute, power, and advantage in this industry. Serious punishments are appropriate.”
Then he kept going, and landed on a sentence that cuts to the core of this matter: “The only appropriate response here is to be absolutely incensed about both the moral failings of the individual and the incompetence of the organization who each gave us false hope of changing this sport for the better.”
I wrote about this case on Tuesday and disclosed at the top that Gramm is a friend, an ITM contributor, and that Ten Strike Racing was our first commercial sponsor. A fair number of readers concluded I was asking for leniency on behalf of a friend. So let me be plain about what I am not saying. I am not arguing Gramm should get a break because he is a known quantity and a hitherto well-liked figure in this game. That doesn’t earn a free pass or even a discount on punishment. What I did argue is that a lifetime ban is the nuclear option, and that the element of HISA’s case that would justify reaching for it — that Gramm deliberately evaded their security — is not just unproven. It is weaker now than it was on Monday.
The second reversal
In Tuesday’s piece I went through what HISA told the industry in June: that the leaked past performances could not have come from the HISA Portal, that other organizations might want to review their own systems, and then, ten days later, that a review of every API call over the previous six months had turned up no unusual Portal activity. That review covered precisely the window in which HISA now says Gramm was pulling records at vast scale. It took two months to arrive at the opposite conclusion.
The second reversal took two days.
At Monday’s press conference, unprompted, in her opening remarks, Lisa Lazarus addressed what she called a rumor going around: that all Gramm had done was change a number in a URL. “That is patently false,” she said, “and not at all what happened.”
On Wednesday, HISA sent me a written statement. “Dr. Gramm initially discovered the ability to view confidential horse health information by changing numbers in the HISA Portal URL he was using to view veterinary information for one of his horses until, through trial and error, he got to veterinary information for a random horse to which he had no legitimate connection.”
There was no correction and no retraction. The account just changed.
HISA’s position now is that the URL change is beside the point. As a spokesperson put it to me this week: “If all he did was change the URL for a few horses, we would have had a conversation with Marshall, not enforcement actions.” Understood and sensible. But that is not what Lazarus said on Monday. She did not say the URL change was a minor first step in a larger problem. She forcefully volunteered that the idea was “patently false” and “not at all what happened.” Two days later her own organization confirmed it as fact — the credibility issues here are mounting.
To HISA’s credit, that same Wednesday statement contains something it didn’t need to include. “I take full responsibility,” Lazarus wrote, “for the fact that our systems were vulnerable to this attack in the first place.” That is a real concession. Tuesday’s piece argued the vulnerability was HISA’s failure, and Lazarus now says the same.
What an outsider sees
I wanted the opinion of someone with real technical knowledge and no stake in any of this, so I called Justin Cappos, a computer science professor at NYU and a cybersecurity expert who had never heard of any of the people involved. Everything he told me was on the record.
He disagreed with one of my assertions in the first piece. I wrote that downloading in batches of 500 was unremarkable — that anyone working with a large data set pulls it in chunks so the process doesn’t fall over. Cappos does not buy that on its own as a defense. “Five hundred at a time feels like the person’s trying to scrape,” he said. “They’re trying to basically make a copy of as much data on there as possible. And that’s pretty hard to justify.”
His point was that once you have seen you can reach someone else’s records by changing an ID, you try one or two more to confirm the pattern, and you have seen enough to know you have something to report. “I don’t have to go and download every person’s data,” he said. “I don’t have to violate everyone’s privacy.”
This vulnerability could have been reported right away. It seems curiosity got the better of Gramm. “People tend to have revisionist history when they think about why they made decisions,” Cappos said. “It’s very tempting to want to look around and see all the interesting things and explore. There’s a rush that comes with this.”
Now the other half.
On how the records were reachable in the first place, Cappos was unequivocal. “The system’s poorly designed,” he said. “If you’re just able to go and make a very minor change — like, for instance, it gives you a record number, and it’s a sequential number, and I can go and move the number up and down and see other people’s records — they’ve clearly designed their system very, very poorly.”
And on whose fault that is: “It’s not the user who goes into the URL bar and types in a different number. It’s not their fault. Anyone who so poorly protects their systems is just leaving the front door open.”
HISA has described what Gramm did as going behind their security systems and deploying methods and programs to avoid security detection. Cappos was uncomfortable with that framing, and with the word the industry has been using around it. “It makes me uncomfortable to call this a hack,” he said. He noted a legal case that treated this kind of conduct as hacking and was “widely panned by researchers and security experts.” He called the characterization “a very dubious claim,” and said this was the sort of vulnerability that “was everywhere” ten or twenty years ago. The HISA Portal is about four years old.
Then he offered an analogy that really resonates, and it cuts both ways. Imagine a house in the middle of downtown with all the doors and windows open, a band playing, no fence, food and drinks lying around, no security of any kind. Some neighbors show up and wander in. “That is probably what you should expect to happen,” he said. “And that’s pretty close to what the site did.”
He is careful to finish the thought. “He didn’t take a drink or two. He went in and he tried to take the whole keg away. And that’s not a very nice way to act at a party.” What Gramm should have done, Cappos said, was tell the neighbors the doors were open.
But about the organization that threw the party, he was blunt. “There’s ineptitude on the side of the organization trying to protect the data.” He went further, and I want to quote him exactly: the setup “almost served as a honey pot for someone,” and “without intentionally being entrapment,” it is “about as close as you would come to something like entrapment.”
The warnings
There is one sentence in HISA’s Wednesday statement that carries an enormous amount of weight. “The technology he was using would have informed him — several times — that he was not authorized to view or obtain this information. He made the active choice to bypass those warnings.”
Read that as an ordinary person would, and it describes a man clicking past a series of stop signs.
Cappos could not definitively tell what it meant. He said it reads two ways. Either the AI tool Gramm used to help write his code flagged something to him, or it is describing error codes the Portal returned to the script — which is a different thing entirely, because a script handles those and a person may never see them at all. If a system is refusing requests, he explained, what comes back is not data but a return code. A well-written script sleeps and retries without ever notifying the person running it. A badly written one skips records, or asks over and over and keeps getting told no.
So I asked HISA to clarify.
The answer, attributable to a HISA spokesperson: “It was Claude that would have warned him that he was not entitled to access the information he was seeking to download unless he was a HISA employee.”
Not the Portal. The chatbot.
Then I asked whether HISA actually has that conversation, or whether this is based on how such tools generally behave. The answer is worth reading twice.
“HISA has the prompts that Gramm supplied to Claude but he refused to provide Claude’s responses to the prompts. We are inferring the responses by typing word-for-word the prompts provided by Gramm into Claude and seeing what it tells us.”
HISA is asserting that the technology informed him several times that he was not authorized and that he made the active choice to bypass those warnings. That claim is not based on anything HISA has seen. It rests on HISA typing his prompts into Claude themselves, months later, and observing what the chatbot says to them.
Start with the most basic problem, and it is a big one.
Claude writes code. In this case, it did not run it. These tools can be set up to execute things, but that is not what HISA describes: by their own account, Gramm supplied prompts, the model produced a script, and the script did the collecting. I have used them this way myself for data projects in baseball, where the data is free and public — you describe what you need, the model writes it, and then you go away and run it. The model is not in the loop after that. It never sees a request go out. It never sees what comes back. It has no idea whether the records arriving on your screen belong to you or to somebody else, because it is not there.
So whatever Claude may have said to Gramm, it was said before a single record was requested, in response to a question about writing code. It could not have warned him that he was not authorized to view a specific horse’s veterinary history, because it had no way of knowing what he was going to point the script at, or what the Portal would hand over when he did.
Then there is the reconstruction itself. These systems are not deterministic. Ask the same question twice and you get two different answers — that is how they are built. AI agents also respond to context, not to prompts in isolation. What a model says to the seventh instruction in a conversation depends on the six before it and on its own replies along the way. HISA has the prompts. It does not have the replies. Feeding those prompts back in without the answers that shaped them does not re-run the conversation. It runs a different one.
And the model HISA typed into this month is not the model Gramm was using in May. These systems are updated continuously.
There is one more thing. Asking an AI assistant to write a script that collects data from a website is entirely ordinary work. Developers do it every day. It is not a request that announces itself as wrongdoing.
“Would have informed him” is doing an Atlas amount of work in that sentence, and it is simply not credible. It is also the fourth confident claim from HISA this summer that did not survive even a basic inquiry.
Which leaves the other half of the same paragraph. Lazarus wrote that Gramm obtained the records “by going behind our security systems and deploying methods and programs to avoid security detection.” I asked what security systems those were and what was deployed to get past them.
The answer: “The investigations confirmed that the AI tool used a program like puppeteer/playmaker to mimic authorized behavior.”
I take it they mean Playwright. Along with Puppeteer, it is an open-source browser automation framework. Developers use them every day to test their own websites, and mimicking a user in a browser is the entire point of them — it is what they are for, not a disguise adopted for this occasion. Nothing in that answer identifies a security system, or explains what was gone behind.
The only candidate left is the batching. And there the evidence is thin. Cappos read the batching as a sign Gramm was scraping rather than confirming — an ethical problem, sure, not evidence he was dodging an alarm. Gramm has never accepted that he was evading anything, and Lazarus said as much on Monday: HISA assumed it from the instructions in his script. An assumption is not a finding. The document that could potentially turn it into one is in the report they will not release.
There is a smaller irony worth noting. HISA’s terms of use do prohibit copying data from the site, and they specify the remedy: they can throw you off the platform. The thing Cappos flagged as the real ethical problem — the automated collection at scale — isn’t mentioned in them at all. No bots, no scrapers, no rate limits, nothing. The document was last updated in June 2022.
What the scale actually was
HISA did answer one question nobody had asked, and the number deserves to be stated plainly. Those records covered approximately 57,000 Covered horses, dating back to October 2025. The total is now put at 4.5 million records.
That is the case against Marshall Gramm, and it is a serious one. It requires no argument about hacking, no reconstruction of a chatbot conversation, and no theory about batch sizes. He pulled the veterinary histories of 57,000 horses that were none of his business. He should accept punishment for that offense and has already established his willingness to do so.
The question underneath the question
The speculation that Gramm was not the only one accessing this data is everywhere right now, and it is not coming only from cranks online, though rest assured, there are plenty of those.
Here is Aragona again, in the same thread quoted above: “With everything we know, is there any doubt that the most active CAW teams were exploiting the same flaw in HISA’s system that Marshall did? It seems implausible to suggest otherwise.” And: “The fact that HISA — our bastion of integrity — set up a database that essentially gave those entities even more wagering power, while sparking even further deterioration of confidence among the stakeholders we most need (retail gamblers), is both ludicrous and infuriating.”
I want to be careful here, because nobody has produced a shred of actual evidence that anyone else did this, and I am not going to accuse identifiable firms of something just because it’s plausible.
HISA’s answer is that it looked. Lazarus said Monday that the investigation is over, that Arete found no evidence anyone else had used the same method, and that she is confident it was only Gramm. She invited anyone who knows otherwise to come forward.
But there is a King Kong-sized problem with that answer. By HISA’s own account, they began tracking Gramm’s activity only after the past performances surfaced in June. If the monitoring that would have caught this was not catching it in real time, and the logging was not there before the leak, then the records that would prove or disprove the question may not exist. I’ll put it mildly: an organization that did not see this happening while it happened is not well placed to certify that nothing else ever did.
This is what makes the whole case problematic. HISA is asking the industry to accept a set of conclusions on trust, from a position where its public conclusions this summer keep not surviving contact with the facts.
They could fix some of that nearly immediately. Release the report, redacted. Show the log entries. If the evidence of deliberate evasion is what they say it is, showing it restores something. Refusing to show it, from an organization whose account of this has now changed twice, asks the industry for a kind of trust it has not earned this summer.
Disclosure: Marshall Gramm is a good friend, a regular contributor to In The Money Media, and his Ten Strike Racing was the first commercial sponsor this company ever had. I was not among the small group he shared those past performances with before they became public. I have tried to report this the way I would report it about a stranger, including the parts that make him look bad.




I wish I had read all this before I decided to play today… I would have saved $50-but it was assiniboia- so no harm, no foul