Original Article Text

Click to Toggle View

DraftKings warns of account breaches in credential stuffing attacks. Sports betting giant DraftKings has notified an undisclosed number of customers that their accounts had been hacked in a recent wave of credential stuffing attacks. DraftKings, a gambling company based in Boston and founded in 2012, provides sportsbook and daily fantasy sports (DFS) services and is an official partner of the NFL, NHL, PGA TOUR, WNBA, UFC, and NASCAR. DraftKings employs over 5,100 people and reported revenues of $4.77 billion at the end of 2024. In data breach notification letters sent on Thursday, October 2, DraftKings informed affected customers that attackers had gained access to their accounts and a "limited amount" of their data in attacks that bore all the signs of a credential stuffing campaign. Credential stuffing involves attackers using automated tools to breach user accounts with stolen username/password pairs from other online services, a tactic that is especially effective against those who reuse credentials across multiple platforms. The threat actors aim to take over accounts to steal personal and financial information, which can later be sold on the dark web or used for identity theft and other malicious purposes. However, the company said the attackers didn't access sensitive data like "government-issued identification numbers, full financial account numbers," or other information that would've enabled them to breach customers' bank accounts or commit identity theft. "By stealing login credentials from a non-DraftKings source and using them in this attack, however, the bad actor may have temporarily been able to log into certain DraftKings customers' accounts," DraftKings said. "In the event your account was accessed, the attacker may have been able to view your name, address, date of birth, phone number, email address, last four digits of a payment card, profile photo, information about prior transactions, account balance, and date your password was last changed." In response to these attacks, the company will require potentially affected customers to reset their DraftKings account passwords and enable multifactor authentication for logins to DK Horse accounts. DraftKings also advised customers to change their account passwords, review their bank accounts and credit reports, place security freezes on their credit reports, and set up fraud alerts on their credit files as a precaution. A DraftKings spokesperson was not immediately available for comment when contacted by BleepingComputer earlier today. DraftKings also revealed in November 2022 that up to $300,000 was stolen from accounts breached in another credential stuffing campaign. One month later, the sports betting company refunded hundreds of thousands of dollars to 67,995 customers whose accounts had been hacked in the incident. The FBI has warned for years that credential stuffing attacks are a massively increasing threat due to readily available aggregated lists of leaked credentials and automated tools. The Security Validation Event of the Year: The Picus BAS Summit Join the Breach and Attack Simulation Summit and experience the future of security validation. Hear from top experts and see how AI-powered BAS is transforming breach and attack simulation. Don't miss the event that will shape the future of your security strategy

Daily Brief Summary

DATA BREACH // DraftKings Faces Credential Stuffing Attacks Compromising Customer Accounts

DraftKings, a major sports betting company, reported a breach affecting an undisclosed number of customer accounts due to credential stuffing attacks.

Attackers accessed limited customer data, including names, addresses, and partial payment card details, but did not obtain sensitive information like full financial account numbers.

Credential stuffing involves using stolen credentials from other platforms to access accounts, a tactic that exploits password reuse among users.

In response, DraftKings is mandating password resets and multifactor authentication for affected accounts to enhance security measures.

Customers are advised to change passwords, monitor financial accounts, and consider credit freezes and fraud alerts as precautionary steps.

The FBI has long warned about the rising threat of credential stuffing, driven by the availability of leaked credentials and automated hacking tools.

DraftKings previously experienced a similar attack in November 2022, resulting in significant financial losses and subsequent customer reimbursements.