Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

DraftKings Warns Users of Credential Stuffing Attacks

Hackers accessed user accounts and compromised names, addresses, phone numbers, email addresses, and other information.

DraftKings hack

Sports betting firm DraftKings is notifying users of a recent credential stuffing campaign targeting their online accounts.

The attacks, the company says in a notification letter to the impacted users, were discovered on September 2, and relied on credentials harvested from other sources to log into users’ accounts.

“By stealing login credentials from a non-DraftKings source and using them in this attack, the bad actor may have temporarily been able to log into certain DraftKings customers’ account,” reads a copy of the notification letter that was submitted to the Massachusetts OCABR.

The attackers likely accessed users’ names, addresses, email addresses, phone numbers, dates of birth, profile photos, the last four digits of payment cards, transaction information, account balances, and details on when passwords were last changed.

“Importantly, our investigation to date has observed no evidence that your login credentials were obtained from DraftKings or that DraftKings’ computer systems or networks were breached as part of this incident,” the company says.

DraftKings also notes that it has no evidence that information such as government-issued ID numbers, financial account numbers, or other sensitive information was compromised in the attack.

Advertisement. Scroll to continue reading.

The company has launched an investigation into the campaign and is requiring the potentially impacted individuals to reset their account passwords. It is also requiring multifactor authentication for logins to DraftKings Horse accounts.

The sports betting firm has not disclosed the number of impacted users. SecurityWeek has emailed DraftKings for additional information on the campaign and will update this article if the company responds.

In 2022, DraftKings disclosed a credential stuffing campaign that hit roughly 68,000 user accounts. In early 2024, Joseph Garrison was sentenced to 18 months in prison, and two other individuals, Nathan Austad and Kamerin Stokes, were indicted over the attacks.

Related: Discord Says User Information Stolen in Third-Party Data Breach

Related: Mainline Health, Select Medical Each Disclose Data Breaches Impacting 100,000 People

Related: Many Attacks Aimed at EU Targeted OT, Says Cybersecurity Agency

Related: A Massive Telecom Threat Was Stopped Right As World Leaders Gathered at UN Headquarters in New York

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

SolarWinds has appointed Justin Henkel as Chief Information Security Officer.

J. Paul Haynes has joined Cinchy as Chief Executive Officer.

Hatem Naguib has become Chief Executive Officer at Sysdig.

More People On The Move

Expert Insights

Four decades of incident response experience suggest that exploits are often the symptom, not the root cause, of today’s cybersecurity failures.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.