A DraftKings hacker has been sentenced to 18 months in prison for helping carry out a large credential stuffing attack that compromised thousands of customer accounts. Nathan Austad, who operated online under the alias “Snoopy,” admitted participating in the 2022 cyberattack that resulted in stolen funds and the sale of hacked accounts. The case highlights the growing threat of credential reuse attacks against online betting platforms.

Hacker Admitted Role in DraftKings Attack

Nathan Austad, a 21-year-old from Minnesota, pleaded guilty in December 2025 to conspiracy to commit computer intrusion. Prosecutors said he worked with several co-conspirators to compromise approximately 60,000 DraftKings customer accounts.

During the attack, the group added payment methods under their control to roughly 1,600 compromised accounts. They then stole approximately $600,000 from affected users.

DraftKings operates one of the largest fantasy sports and online sports betting platforms in the United States. Users compete in fantasy contests and place wagers using personal accounts that often contain payment information.

Credential Stuffing Enabled the Breach

The cyberattack took place in November 2022 through a credential stuffing campaign. Rather than exploiting a security flaw in DraftKings, the attackers relied on usernames and passwords stolen from previous data breaches.

Many users reuse passwords across multiple online services. Attackers take advantage of this habit by testing leaked credentials against popular websites until they find matching accounts.

DraftKings initially reported that fewer than $300,000 had been stolen. However, the company later confirmed that 67,995 customer accounts had been compromised during the attack.

The incident demonstrated how password reuse continues to create significant risks for online platforms and their customers.

Stolen Accounts Were Sold Online

Federal investigators said Austad operated an online marketplace that sold access to compromised accounts. He also used other underground platforms to distribute stolen credentials.

According to the US Department of Justice, his shop was named after Snoopy, the well-known comic strip character that inspired his online alias.

Investigators also found messages in which Austad discussed fraudulent activity with other members of the operation and warned them to prepare for law enforcement attention.

Authorities traced approximately $465,000 in cryptocurrency assets to accounts under Austad’s control. While officials did not disclose how much money he earned from selling stolen account access, the cryptocurrency evidence became an important part of the investigation.

Authorities Continue Targeting Cybercrime Groups

The DraftKings investigation has resulted in multiple criminal convictions.

Joseph Garrison became the first member of the group to receive an 18-month prison sentence in January 2024. Prosecutors later charged additional suspects, including Kamerin Stokes, known online as “TheMFNPlug,” and Nathan Austad.

Stokes received a 30-month prison sentence in April 2026 for his involvement in the scheme.

The series of prosecutions reflects the continued effort by US authorities to dismantle cybercriminal groups that profit from credential theft, account takeovers, and online fraud.

Court Orders Restitution and Supervised Release

In addition to serving 18 months in prison, Austad will remain under supervised release for three years after completing his sentence.

The court also ordered him to forfeit $463,684 and pay more than $1.3 million in restitution to compensate victims and recover criminal proceeds.

The financial penalties demonstrate that cybercriminals may face significant consequences beyond prison time when authorities successfully trace stolen assets.

Conclusion

The DraftKings hacker case serves as another reminder that credential stuffing remains an effective attack technique when users recycle passwords across multiple services. Although law enforcement has secured convictions against several members of the operation, the incident exposed tens of thousands of customer accounts and caused substantial financial losses. Strong, unique passwords and multi-factor authentication remain among the most effective defenses against account takeover attacks.


0 responses to “DraftKings Hacker Sentenced to 18 Months for Account Breach”