Marshall Gramm, HISA and a Sport Wearing Blinkers

August 18, 2026

Okay, the “reporting” is on hold for today, let’s go unfiltered.

For many years I have closed my articles with a movie scene or quote. Sometimes it is a song, sometimes an image. It is probably the part of writing I enjoy the most. Occasionally the scene comes at the beginning. Sometimes it lands somewhere in the middle. Rarely, I use three. They always mean something. Sometimes the meaning is obvious, sometimes subliminal, sometimes an inside joke between friends, and sometimes there is more than one meaning buried in there. They are never random.

This time I need three. Hopefully at least some of you will get them all.

Welcome to horse racing in 2026.

The Marshall Gramm story is no longer merely about Marshall Gramm. It is about HISA, data security, wagering integrity, claiming, handicapping tournaments, friendships, enemies, agendas, technology, accountability and a sport where seemingly everyone owns a pair of blinkers and most don’t even know they are wearing them. Depending upon which corner of racing you occupy, the same set of facts apparently tells an entirely different story.

That is a problem. Let’s start with what we actually know.

HISA has charged Marshall Gramm with multiple rule violations, including fraud, arising from what it says was unauthorized access to confidential horse-health information. HISA says its investigation, which included its own personnel and an independent forensic cybersecurity analysis by Arete, concluded that Gramm deliberately and methodically obtained confidential information over approximately six weeks beginning in early May and ending in mid-June. According to HISA, Gramm developed an automated method to obtain information at scale while mimicking authorized activity in an effort to avoid detection. HISA says Gramm participated during that period in pari-mutuel wagering, handicapping contests and claiming activity. Gramm has admitted being the source of the enhanced past performances for Deterministic and Griffin’s Wharf that ultimately appeared on social media, while disputing significant portions of HISA’s characterization of how and why he obtained the information.

Those aren’t rumors. Those aren’t somebody on X connecting dots. Those are the allegations HISA has put its name behind and the portion Gramm himself has acknowledged.

We now know more. At the press conference following the announcement, Lisa Lazarus said Gramm claimed nine horses during the relevant period and HISA determined he had accessed confidential information on each of those nine horses before the claims were made. HISA intends to reimburse previous owners for approximately $80,000 to $90,000 in post-claim purse earnings and then seek recovery from Gramm. Publicly reviewed claiming records put the total claiming prices at $210,500 and subsequent purse earnings at $80,455.

The Elephant in the Pari-Mutuel Room

I am a bettor. I look at virtually everything in racing through that lens because it is the world I know. Every wager I make is an investment in an outcome. I have spent decades looking for information that gives me an edge. I make my own observations. I keep notes. I use independent speed figures. I make proprietary calculations. I watch races differently than other people watch them. If I can legally obtain information available within the rules that helps me make a better decision, I want it. That is called handicapping. Confidential veterinary information unavailable to the rest of the wagering public is something else.

We know what the nine claimed horses earned after they changed hands. We can count those dollars. What nobody outside the investigation has publicly quantified is what happened at the windows.

How much did Marshall Gramm wager during those six weeks? On what? Through which accounts? What did he win? What did he lose? Did anyone wager for him? Were there offshore wagers? Were there partnerships? Was any confidential information incorporated into handicapping decisions? Did it affect contest play? We don’t know. And anyone pretending the claiming results answer those questions is looking at the wrong tote board.

The two past performances that exposed this whole thing were for Deterministic and Griffin’s Wharf. HISA says they contained confidential horse-health information and that Gramm created them. Those horses weren’t being examined on leaked sheets because somebody was deciding whether to drop a claim slip on them. That alone proves nothing about whether Gramm bet them, and I am not saying it does. It does, however, destroy the idea that the only conceivable utility of this information was claiming horses. There was handicapping value. There was potentially wagering value. There was potentially tournament value. And there was unquestionably claiming value.

That is why Mike Rennie’s reaction deserves more attention than some of the noise surrounding this story. Rennie says Gramm beat him in the final race of a Santa Anita contest for an NHC seat approximately three months ago and he wants the seat. I don’t know whether confidential information had anything whatsoever to do with that result. Neither does Rennie. But if that contest occurred during the period HISA says Gramm was improperly accessing confidential information, Rennie has every right in the world to ask the question. So does everyone else who competed against him. And so does every bettor who put a nickel into a pari-mutuel pool Gramm played during that period.

This is the part some people in racing still don’t understand. When you bet into a pari-mutuel pool, you aren’t betting against NYRA, Churchill Downs, Santa Anita or HISA. You’re betting against me. I’m betting against you. We divide the money after the takeout. If somebody sitting across that invisible table possesses meaningful confidential information that the rest of us aren’t permitted to possess, every other dollar in that pool potentially sits at a disadvantage. If you are a horseplayer and that doesn’t bother you, please bet more. Bet big. Thank you.

The Bank Wasn’t Secure. So Take the Money?

Now we arrive at the narrative that has consumed much of racing social media. HISA had a vulnerability. Correct. HISA was responsible for safeguarding confidential information entrusted to it. Correct. The vulnerability should not have existed. Correct. HISA should determine how it happened, how long it existed, whether anyone else exploited it and make damn sure it cannot happen again. Correct.

Therefore Marshall Gramm bears little or no responsibility for exploiting it.

GTFOH.

I don’t know how else to put it. If I walk into a bank and discover that its security is terrible, that does not make the money mine. If I discover that a lock can be picked, picking it does not become an innocent act because the locksmith should have built a better lock. If I have the key to my safe-deposit box and discover a method that lets me use my legitimate credentials to get into somebody else’s box, the bank has a serious security problem. It may even have been negligent. Fix it. Investigate it.

I still don’t get to take what’s inside.

Imagine the defense in court.

Your Honor, I discovered their security was terrible. I was able to get the money. Therefore this is actually the bank president’s fault. Acquit me and blame him.

Good luck with that.

The factual dispute over exactly how Gramm accessed the data will be adjudicated. Gramm says he used his own authorized account, bypassed no security protocol and did not conceal his identity. HISA says something materially different. Lazarus said publicly that the idea this consisted simply of changing a horse number in a URL is “patently false,” and HISA alleges Gramm used an automated browser and code to obtain records at scale in a way designed to avoid detection. According to reporting from the press conference, HISA says records were downloaded in batches of 500 or fewer around a security-alert threshold; Gramm has not conceded that avoiding the threshold was his purpose.

There is due process ahead. Let it play out. But this much shouldn’t require a hearing: a vulnerability is not an invitation.

There is a difference between discovering a flaw and exploiting one. There is a difference between accidentally seeing information and systematically gathering it. There is a difference between telling the custodian, You have a problem, and continuing to collect the information. That distinction seems to have disappeared from much of the conversation because HISA is involved.

Everybody Hates the Umpire

I have criticized HISA plenty. I will again. I don’t work for HISA. They don’t write my articles. Lisa Lazarus doesn’t tell me what to say, and when I think HISA gets something wrong I say it. Anyone who has followed Past the Wire knows that. But intellectual honesty shouldn’t depend upon which jersey somebody is wearing.

There is an irony bordering on comedy in watching racing’s reaction to this. For decades this sport demonstrated that it could not effectively regulate itself nationally. Rules changed when you crossed state lines. Enforcement changed. Medication rules changed. Testing changed. Penalties changed. Jurisdiction changed. Racing repeatedly demonstrated an inability to create the uniformity, accountability and enforcement structure necessary to convince the federal government to stay out of its business. Eventually Washington stopped waiting.

HISA wasn’t created because racing’s system worked. HISA was created because racing’s system didn’t.

That doesn’t make HISA infallible. It doesn’t excuse bad technology. It doesn’t excuse waste. It doesn’t excuse mistakes. It certainly doesn’t excuse a vulnerability involving confidential veterinary information. But think about the position some people have managed to construct. For years: Nobody catches the real cheaters. HISA catches what it alleges is a prominent owner, respected horseplayer, tournament champion, professor, Jockey Club member and racing insider improperly obtaining confidential veterinary information.

Now: How could HISA do this? Fire Lisa Lazarus. You can’t make this stuff up. Again GTFOH.

The organization operates under budget constraints while being asked to create and enforce something American racing itself never successfully created: a national regulatory framework. It does so in an industry where a significant percentage of the participants didn’t want it created, don’t particularly want it succeeding and will criticize virtually every move it makes. Does that mean HISA gets a pass? Absolutely not. It means judge the damn play.

And on this play, HISA found the problem, expanded the investigation, brought in outside forensic expertise, confronted the person it believed responsible, attempted a settlement, refused a settlement when it believed transparency was being compromised, filed charges when negotiations collapsed, went public, said it would seek restitution, referred the matter to outside authorities and put its CEO in front of the media to answer questions.

I was in that press conference.

Lisa Lazarus stayed until the questions were exhausted. Thirty minutes became roughly 36. She answered questions about the technology, the investigation, the claiming activity, restitution, the outside forensic examination, law enforcement referrals, the settlement negotiations and what comes next. When she wasn’t a cybersecurity expert, she didn’t pretend to be one. HISA’s attorney addressed due process and potential penalties. Nobody shut down the room when the clock expired.

I have dealt with racing regulators for a long time. Again. High marks.

You can hold two thoughts in your head simultaneously. HISA was responsible for protecting the data, and its system failed to prevent the access HISA now alleges. HISA also appears to have responded aggressively and transparently after discovering what happened. Those statements aren’t contradictory. They’re what happened.

Two Pieces Worth Reading

Two of the more thoughtful pieces I have read since this exploded came from Robin Howlett and Novak. I don’t agree with everything in either one. That’s precisely why they’re worth reading.

Robin Howlett — Big Data Meets the Backstretch

Howlett recognizes something desperately missing from most of the shouting: the vulnerability and the alleged exploitation can both matter. One does not erase the other. The technical failure deserves examination. So does the conduct of the person HISA says discovered and exploited it.

Novak — HISA: A Clear Lack of Integrity and Safety

Novak comes down much harder on HISA than I do, and I think some of his conclusions outrun what has been publicly established. But his central technical criticism deserves consideration. Authentication—proving you are an authorized user—isn’t the same thing as authorization to access every record behind the door. If an authenticated user could obtain confidential records belonging to horses he had no legitimate connection to, HISA had an access-control problem.

That’s fair. Calling Gramm a scapegoat is where you lose me. HISA didn’t manufacture the leaked past performances. HISA says Gramm admitted he created them. HISA didn’t force him to gather the data. HISA didn’t enter the handicapping contests for him. HISA didn’t make his wagers. HISA didn’t submit the claims. Those activities during the six-week period are part of HISA’s public allegations and investigation. Fix the technology. Then deal with the person alleged to have exploited it. We are capable of doing two things at once. At least I hope we still are.

The Call

One detail from the press conference has stayed with me. On the morning of the day HISA confronted Gramm, he participated in an approximately hour-long call organized by The Jockey Club specifically to discuss how the industry should respond to the leaked PPs and whether policies should be changed as a consequence. Lisa Lazarus was there. Patrick Cummings was there. Jim Gagliano, Charlotte Clement and other Jockey Club representatives were there. Marshall Gramm was there. According to Lazarus, Gramm spent the hour contributing ideas about where the industry should go from there without once disclosing that he was the person responsible for the very circumstances that had brought everyone onto the call. That may be the biggest tell in the whole story.

Read that again.

I know Pat Cummings. I know there is a friendship between Pat and Marshall. Mike Repole has publicly acknowledged that he and Pat know and like Gramm. Friendship isn’t evidence of wrongdoing. Sitting on a call with somebody who hasn’t told you what he has done isn’t wrongdoing either. There is no basis I have seen to say Pat knew what Gramm had allegedly been doing, and I won’t insinuate otherwise. Quite the opposite: if Lazarus says the other participants didn’t know, that matters.

Pat’s position now is an unenviable one. He has a professional role in racing, a personal relationship with Gramm and a story exploding around both. Sometimes silence isn’t conspiracy. Sometimes it is discretion.

Repole chose another route.

He acknowledged the relationship and then unloaded on HISA and The Jockey Club, demanding answers about who else had access, how often, what they saw, what they did with it and calling for an independent investigation. Some of those are perfectly legitimate questions.

But Mike has been fighting HISA and The Jockey Club for a long time. Pretending that history doesn’t affect the lens through which he sees this would be silly. Every horse has a trip.

Then Ray and Mike Found Each Other

Eventually Mike Repole and Ray Paulick managed to turn the Gramm controversy into something resembling an old-fashioned neighborhood argument. Mike went after Ray over HISA, The Jockey Club and industry leadership. Ray responded by asking Mike about Pat Cummings’ friendship with Gramm, whether Gramm had advised Pat or Repole’s organization and whether Repole would disclose financial records. Maybe some of those questions are worth asking. Maybe some of Mike’s are too. But watching it unfold reminded me why racing can never resist making an institutional crisis personal. Confidential veterinary information. Wagering integrity. Claiming. Tournament competition. Cybersecurity. Potential law-enforcement referrals. And somehow we’re back to: Yeah? Well what about your guy? Now, Mike from Queens is the self appointed Commissioner in a sport without one. He has no power and fights for the betterment of the game how he sees it, with his own money, no official authority and his National Thoroughbred Alliance. Mike from Queens can talk that way. He labels himself a disruptor. Ray is supposed to be a professional. Only one of the two appeared to know their lane and stay in it. Cheap gotcha attempts are just that and say more about the one taking them than the target.

This has gotta happen every five years or so—ten years—helps to get rid of the bad blood.

A Little Hypocrisy With Your Outrage?

There is another part of this that hasn’t escaped me. Some people expressing righteous indignation about Marshall Gramm are perfectly comfortable consuming proprietary racing information they didn’t buy and have no legal right to possess. Past performances. Speed figures. Workout reports. Other handicapping products. They show up free in somebody’s inbox and suddenly nobody asks too many questions. No, distributing pirated handicapping information is not the same conduct HISA alleges against Gramm. I’m not making that comparison. I’m making another one. Spare me the gossiping about the sanctity of information while you’re opening somebody else’s proprietary work for free because somebody added you to a mailing list.

Wrong doesn’t become right because the attachment arrived in an email instead of through a portal. There are a lot of stones flying around racing this week. Some people might want to check whether they’re standing inside a glass house before throwing the next one.

Marshall’s Statement

Gramm has denied HISA’s characterization and says he intends to defend himself. He says he accessed the information through his authorized HISA account, did not conceal his identity, circumvent security or initially understand the full scope of the dataset. He says his mistake was failing to alert HISA after the vulnerability became public and argues that making him the focus distracts from HISA’s system problems. He is entitled to make that case. I’m entitled not to buy it.

The part I have the most difficulty reconciling is the combination of sophistication and innocence. Gramm isn’t somebody who accidentally clicked the wrong link while trying to renew his owner’s license. He is an economics professor and data analyst whose academic work includes gambling and pari-mutuel market efficiency. He is an accomplished horseplayer, a Breeders’ Cup Betting Challenge winner and an experienced owner and claiming participant. That background doesn’t prove misconduct. It makes I didn’t really understand what I had a harder sell. And HISA’s allegations, if proven, make it harder still.

The Questions That Actually Matter

There should be scrutiny of HISA’s technology. Absolutely.

How long did the vulnerability exist? What specifically failed? Could another user have exploited it previously? How far backward were logs examined? What controls have been added? Should some veterinary information ultimately become public? Should HISA commission an additional independent review of its access-control architecture? Ask all of it. HISA says its investigation found no evidence anyone else used the same method and that the method Gramm allegedly used has been closed. That is reassuring. It isn’t a reason to stop asking.

But there is another set of questions I care about just as much. What wagers did Gramm make during those six weeks? What contests did he enter? What information did he possess when he entered them? Did confidential information influence any wager? What were his results? Did anyone else wager with him or for him? Were any betting accounts outside the obvious ones involved? What happens to tournament players who finished behind him like Mike Rennie? What happens to bettors who competed against his money in pari-mutuel pools?

And how much money, if any, changed hands because one participant possessed information everybody else was prohibited from seeing?

Horseplayers are not collateral damage in this story. We may be the story.

Nobody Wants the Whole Horse

That’s ultimately what bothers me about the reaction. Everybody sees the piece he wants. HISA opponents see proof HISA is incompetent. HISA supporters see proof HISA works. Owners see confidential information they were required to surrender. Cybersecurity people see an authorization failure. Horseplayers see an information advantage. Tournament players see potentially compromised competition. The establishment sees an embarrassing member. The anti-establishment sees another insider scandal. Friends see their friend. Enemies see an opportunity. And social media sees content.

Nobody wants the whole horse.

My view isn’t complicated. HISA had a vulnerability. It shouldn’t have. HISA needs to own that. It has. HISA needs to fix it. It says it has. HISA needs to determine whether anyone else exploited it. It says its investigation found no evidence that anyone did through the method it investigated.

And if Marshall Gramm deliberately exploited that vulnerability for an advantage in claiming, wagering, tournaments or anything else, then Marshall Gramm owns that. Not Lisa Lazarus. Not HISA. Not the programmer. Not the bank manager. Marshall Gramm. The hearings will determine what HISA can prove.

Until then, there is something almost surreal about an industry that spent decades failing to police itself complaining that its national regulator doesn’t catch enough serious wrongdoing, and then, when the regulator brings fraud charges against one of racing’s most sophisticated and respected insiders, deciding the regulator is the bad guy for catching him. Had racing effectively policed itself, HISA probably wouldn’t exist. That part of the history seems to have disappeared remarkably quickly. You wanted somebody to police the game. Well, somebody finally walked through the door. Be careful what you wish for.

And Finally…

I have wondered for years where technology ultimately takes horse racing. Computer-assisted wagering. Algorithms. Proprietary data. Veterinary databases. Artificial intelligence. Predictive models. Automated scraping. Information advantages measured in milliseconds. We have built a sport where information may eventually become as important as the horses generating it. Maybe more important. The technology keeps getting better. The people using it remain people.

That brings me to the last one.

In the year 2525…

Maybe Zager and Evans were the best handicappers of all…….

Are you watching closely?

Contributing Authors

"Jon Stettin at the Breeders' Cup draw at Del Mar"

Jonathan "Jon" Stettin

Jonathan “Jon” Stettin is the founder and publisher of Past the Wire and one of horse racing’s most respected professional handicappers, known industry-wide as the...

View Jonathan "Jon" Stettin

All you folks that didn't get in on the @jonathanstettin webinar are missing out. Amazing stuff here. Time to get hot tomorrow!!

Drawls E Moore @dmoore9350 View testimonials

Facebook

Comments

Leave a Comment