Hacker stehlen $300.000 bei DraftKings-Angriff zum Ausfüllen von Zugangsdaten

Teilen:

Sports betting company DraftKings said today that it would make whole customers affected by a credential stuffing attack that led to losses of up to $300,000.

The statement follows an early Monday morning tweet saying that DraftKings was investigating reports [1234] of customers experiencing issues with their accounts.

The common denominator for all accounts that got hijacked seems to be an initial $5 deposit followed by the attackers changing the password, enabling two-factor authentication (2FA) on a different phone number, and then withdrawing as much as possible from the victims’ linked bank accounts.

 

Some victims have also expressed their frustration on social media because they were unable to get in contact with anyone at DraftKings while having to watch the attackers repeatedly withdrawing money from their bank accounts.

“We currently believe that the login information of these customers was compromised on other websites and then used to access their DraftKings accounts where they used the same login information,” revealed DraftKings President and Cofounder Paul Liberman more than 12 hours later.

“We have seen no evidence that DraftKings’ systems were breached to obtain this information. We have identified less than $300,000 of customer funds that were affected, and we intend to make whole any customer that was impacted.”

The company advised customers never to use the same password for more than one online service and never to share their credentials with third-party platforms, including betting trackers and betting apps besides the ones provided by DraftKings.

DraftKings customers who haven’t yet been affected by this credential-stuffing campaign are advised to immediately turn on 2FA on their accounts and remove any banking details or, even better, unlink their bank accounts to block fraudulent withdrawal requests.

​In credential stuffing, threat actors use automated tools to make repeated attempts (up to millions at a time) to gain access to user accounts using credentials (commonly in user/password pairs) stolen from other online services.

This works particularly well against the accounts whose owners have reused credentials across multiple platforms.

The goal is to take over as many accounts as possible to steal associated personal and financial info that can later be sold on the dark web or on hacking forums.

The attackers will also use the stolen info in future identity theft scams to make unauthorized purchases or—as it happened in the case of hijacked DraftKings accounts—transfer money in linked banking accounts to accounts under their control.

As the FBI warned recently, these attacks are quickly growing in volume thanks to readily available aggregated lists of leaked credentials and automated tools.

Okta also reported that the situation has drastically worsened this year as it recorded more than 10 billion credential-stuffing events on its platform during the first three months of 2022.

The number represents approximately 34% of the overall authentication traffic tracked by Okta, meaning that one-third of all sign-in attempts are malicious and fraudulent.

https://www.bleepingcomputer.com/news/security/hackers-steal-300-000-in-draftkings-credential-stuffing-attack/

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
5:18 am, Juli 12, 2025
Wetter-Symbol 18°C
L: 16° | H: 19°
klarer Himmel
Luftfeuchtigkeit: 80 %
Druck: 1017 mb
Wind: 7 mph E
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 0%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:57 am
Sonnenuntergang: 9:14 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
16° | 19°°C 0 mm 0% 10 mph 77 % 1018 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
17° | 28°°C 0.51 mm 51% 6 mph 66 % 1014 mb 0 mm/h
Mo. Juli 14 10:00 pm
Wetter-Symbol
19° | 26°°C 0.3 mm 30% 15 mph 60 % 1015 mb 0 mm/h
Di. Juli 15 10:00 pm
Wetter-Symbol
15° | 21°°C 0 mm 0% 12 mph 68 % 1018 mb 0 mm/h
Mi. Juli 16 10:00 pm
Wetter-Symbol
17° | 20°°C 1 mm 100% 13 mph 93 % 1017 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
18° | 18°°C 0 mm 0% 4 mph 77 % 1018 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
23° | 25°°C 0 mm 0% 5 mph 62 % 1017 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
29° | 29°°C 0 mm 0% 7 mph 32 % 1015 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
30° | 30°°C 0 mm 0% 10 mph 29 % 1014 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
25° | 25°°C 0 mm 0% 10 mph 37 % 1014 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
21° | 21°°C 0 mm 0% 6 mph 46 % 1015 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
19° | 19°°C 0 mm 0% 4 mph 57 % 1014 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
17° | 17°°C 0 mm 0% 5 mph 66 % 1013 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€100,795.87
0.99%
Ethereum(ETH)
€2,536.83
-0.02%
XRP(XRP)
€2.40
9.29%
Fesseln(USDT)
€0.86
0.02%
Solana(SOL)
€139.64
-0.77%
USDC(USDC)
€0.86
0.01%
Dogecoin(DOGE)
€0.174432
3.02%
Shiba Inu(SHIB)
€0.000011
-0.39%
Pepe(PEPE)
€0.000010
-2.04%
Peanut das Eichhörnchen(PNUT)
€0.246209
7.19%
Nach oben scrollen