Hackers steal $300,000 in DraftKings credential stuffing attack

Share:

Sports betting company DraftKings said today that it would make whole customers affected by a credential stuffing attack that led to losses of up to $300,000.

The statement follows an early Monday morning tweet saying that DraftKings was investigating reports [1234] of customers experiencing issues with their accounts.

The common denominator for all accounts that got hijacked seems to be an initial $5 deposit followed by the attackers changing the password, enabling two-factor authentication (2FA) on a different phone number, and then withdrawing as much as possible from the victims’ linked bank accounts.

 

Some victims have also expressed their frustration on social media because they were unable to get in contact with anyone at DraftKings while having to watch the attackers repeatedly withdrawing money from their bank accounts.

“We currently believe that the login information of these customers was compromised on other websites and then used to access their DraftKings accounts where they used the same login information,” revealed DraftKings President and Cofounder Paul Liberman more than 12 hours later.

“We have seen no evidence that DraftKings’ systems were breached to obtain this information. We have identified less than $300,000 of customer funds that were affected, and we intend to make whole any customer that was impacted.”

The company advised customers never to use the same password for more than one online service and never to share their credentials with third-party platforms, including betting trackers and betting apps besides the ones provided by DraftKings.

DraftKings customers who haven’t yet been affected by this credential-stuffing campaign are advised to immediately turn on 2FA on their accounts and remove any banking details or, even better, unlink their bank accounts to block fraudulent withdrawal requests.

​In credential stuffing, threat actors use automated tools to make repeated attempts (up to millions at a time) to gain access to user accounts using credentials (commonly in user/password pairs) stolen from other online services.

This works particularly well against the accounts whose owners have reused credentials across multiple platforms.

The goal is to take over as many accounts as possible to steal associated personal and financial info that can later be sold on the dark web or on hacking forums.

The attackers will also use the stolen info in future identity theft scams to make unauthorized purchases or—as it happened in the case of hijacked DraftKings accounts—transfer money in linked banking accounts to accounts under their control.

As the FBI warned recently, these attacks are quickly growing in volume thanks to readily available aggregated lists of leaked credentials and automated tools.

Okta also reported that the situation has drastically worsened this year as it recorded more than 10 billion credential-stuffing events on its platform during the first three months of 2022.

The number represents approximately 34% of the overall authentication traffic tracked by Okta, meaning that one-third of all sign-in attempts are malicious and fraudulent.

https://www.bleepingcomputer.com/news/security/hackers-steal-300-000-in-draftkings-credential-stuffing-attack/

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
11:25 pm, Jul 11, 2025
weather icon 23°C
L: 22° | H: 24°
clear sky
Humidity: 62 %
Pressure: 1018 mb
Wind: 8 mph E
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 1%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:56 am
Sunset: 9:15 pm
DailyHourly
Daily ForecastHourly Forecast
Tomorrow 10:00 pm
weather icon
22° | 24°°C 0 mm 0% 10 mph 65 % 1018 mb 0 mm/h
Sun Jul 13 10:00 pm
weather icon
17° | 29°°C 0 mm 0% 7 mph 66 % 1015 mb 0 mm/h
Mon Jul 14 10:00 pm
weather icon
19° | 28°°C 0 mm 0% 14 mph 71 % 1017 mb 0 mm/h
Tue Jul 15 10:00 pm
weather icon
15° | 25°°C 0 mm 0% 13 mph 68 % 1020 mb 0 mm/h
Wed Jul 16 10:00 pm
weather icon
18° | 25°°C 1 mm 100% 13 mph 83 % 1019 mb 0 mm/h
Tomorrow 1:00 am
weather icon
20° | 22°°C 0 mm 0% 3 mph 61 % 1018 mb 0 mm/h
Tomorrow 4:00 am
weather icon
17° | 19°°C 0 mm 0% 4 mph 61 % 1018 mb 0 mm/h
Tomorrow 7:00 am
weather icon
19° | 19°°C 0 mm 0% 5 mph 65 % 1018 mb 0 mm/h
Tomorrow 10:00 am
weather icon
26° | 26°°C 0 mm 0% 6 mph 44 % 1017 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
29° | 29°°C 0 mm 0% 6 mph 32 % 1016 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
29° | 29°°C 0 mm 0% 10 mph 30 % 1014 mb 0 mm/h
Tomorrow 7:00 pm
weather icon
25° | 25°°C 0 mm 0% 9 mph 41 % 1014 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
21° | 21°°C 0 mm 0% 6 mph 55 % 1015 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€100,552.98
1.12%
Ethereum(ETH)
€2,529.65
-0.47%
XRP(XRP)
€2.33
6.77%
Tether(USDT)
€0.86
0.03%
Solana(SOL)
€138.23
-1.89%
USDC(USDC)
€0.86
0.02%
Dogecoin(DOGE)
€0.172953
5.14%
Shiba Inu(SHIB)
€0.000011
0.99%
Pepe(PEPE)
€0.000010
1.49%
Peanut the Squirrel(PNUT)
€0.246234
7.19%
Scroll to Top