Bleepingcomputer DraftKings Hacker 'Snoopy' Sentenced for $600K Credential Stuffing Attack
Article Content
- •Nathan Austad sentenced to 18 months for hacking 60,000 DraftKings accounts.
- •Attack method involved credential stuffing, leading to $600,000 in theft.
- •Austad operated a shop selling access to stolen accounts and faces significant restitution.
Nathan Austad, a 21-year-old from Minnesota using the alias 'Snoopy', was sentenced to 18 months in prison for his role in a November 2022 cyberattack on DraftKings. The attack involved credential stuffing, compromising approximately 60,000 user accounts and stealing around $600,000. Austad and his co-conspirators added their own payment methods to 1,600 accounts and withdrew existing funds. He pleaded guilty to conspiracy to commit computer intrusion in December 2025. In addition to his prison sentence, he was ordered to pay over $1.3 million in restitution and forfeiture. Austad operated a shop for selling access to the hacked accounts, profiting significantly from the scheme. His sentencing follows similar sentences for other co-conspirators, including Joseph Garrison and Kamerin Stokes. The attack highlighted vulnerabilities in user account security, particularly regarding weak passwords and credential reuse.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (6)
Following this threat?
Track DraftKings in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…