Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

Third DraftKings Hacker Pleads Guilty

Nathan Austad admitted in court to launching a credential stuffing attack against a fantasy sports and betting website.

DraftKings hack

Nathan Austad is the third individual to plead guilty to launching a credential stuffing attack against a fantasy sports and betting website, the DoJ announced.

Austad, 21, of Farmington, Minnesota, also known as ‘Snoopy’, admitted in court to his role in a scheme to hack thousands of user accounts and sell access to them to drain their funds.

According to documents and statements presented in court, Austad and his co-conspirators compromised over 60,000 user accounts at the betting website.

The hackers added a new payment method to the compromised accounts, stealing roughly $600,000 from approximately 1,600 victims.

Additionally, the documents show, the hackers sold access to the victim accounts through various online shops.

Austad controlled one such shop, as well as cryptocurrency accounts that received roughly $465,000 worth of virtual assets, including proceeds from the scheme.

Advertisement. Scroll to continue reading.

The court documents also show that Austad messaged his co-conspirators about the existence of an investigation into their campaign.

Austad, who pleaded guilty to computer intrusion conspiracy, faces up to five years in prison.

While the impacted betting website was not named, it is likely DraftKings, which in November 2022 announced that approximately 68,000 user accounts were compromised in a credential stuffing attack.

Two other individuals were arrested and indicted as part of the DraftKings hacks, namely Joseph Garrison and Kamerin Stokes.

Garrison pled guilty in November 2023 and was sentenced to 18 months in prison in early 2024. Stokes pled guilty in April 2024.

In October 2025, DraftKings warned of a new wave of credential stuffing attacks targeting its users.

As part of such an attack, threat actors use credential pairs obtained from past data breaches to log into user accounts on unrelated websites. The attacks bank on the use of the same usernames and passwords for multiple accounts.

Related: Former Accenture Employee Charged Over Cybersecurity Fraud

Related: US Indicts Extradited Ukrainian on Charges of Aiding Russian Hacking Groups

Related: Australian Man Sentenced to Prison for Wi-Fi Attacks at Airports and on Flights

Related: Recent GeoServer Vulnerability Exploited in Attacks

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

SolarWinds has appointed Justin Henkel as Chief Information Security Officer.

J. Paul Haynes has joined Cinchy as Chief Executive Officer.

Hatem Naguib has become Chief Executive Officer at Sysdig.

More People On The Move

Expert Insights

Four decades of incident response experience suggest that exploits are often the symptom, not the root cause, of today’s cybersecurity failures.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.