A man accused of hacking UK National Lottery accounts via credential stuffing attacks has been sentenced to nine months in prison, the UK’s National Crime Agency reported on Friday.
Anwar Batson, 29, of London, has been sentenced for fraud and four violations under the Computer Misuse Act of 1990. The man was arrested in May 2017 and initially denied any involvement, claiming that he had been a victim of trolls and hackers, but later pleaded guilty after investigators found on his devices conversations between him and other members of the conspiracy.
According to the NCA, Batson used a tool called Sentry MBA to launch credential stuffing attacks on accounts belonging to National Lottery customers. Sentry MBA allows cybercriminals to quickly and easily attempt to access online accounts using millions of usernames and passwords.
These credentials are often obtained as a result of third-party breaches and the credential stuffing attacks can have a high success rate given that many people use the same username and password combination for multiple online accounts.
The NCA said Batson used Sentry MBA to launch attacks against Camelot, the company that runs the National Lottery, and also provided instructions to others on how to do so.
Other individuals who launched these types of attacks against Camelot included Daniel Thompson, 27, of Newcastle, and Idris Kayode Akinwunmi, 21, of Birmingham. Thompson and Akinwunmi were sentenced in July 2018 to eight and four months in prison, respectively.
When the attack against the National Lottery was announced by Camelot in November 2016, the company said hackers had accessed roughly 26,500 accounts. The NCA says there are approximately 9 million records in the National Lottery customer database.
Camelot pointed out at the time that the attackers had not breached any of its systems, and it had been confident that affected customers could not suffer any financial losses directly as a result of the cyberattack.
However, the NCA said on Friday that Akinwunmi had stolen £13 from the account of one lottery player whose username and password he had received from Batson.
Related: British Hacker Sentenced for Blackmailing Apple
Related: UK Hacker Sentenced to 20 Months in Prison
Related: Former Contractor Sentenced to Prison for Hacking British Airline Jet2

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.
More from Eduard Kovacs
- Industrial Giant ABB Confirms Ransomware Attack, Data Theft
- Zyxel Firewalls Hacked by Mirai Botnet
- New Russia-Linked CosmicEnergy ICS Malware Could Disrupt Electric Grids
- Drop in Insider Breaches Drives Decline in Intrusions at OT Organizations
- Zero-Day Vulnerability Exploited to Hack Barracuda Email Security Gateway Appliances
- OAuth Vulnerabilities in Widely Used Expo Framework Allowed Account Takeovers
- New Honeywell OT Cybersecurity Solution Helps Identify Vulnerabilities, Threats
- Rheinmetall Says Military Business Not Impacted by Ransomware Attack
Latest News
- Industrial Giant ABB Confirms Ransomware Attack, Data Theft
- Organizations Worldwide Targeted in Rapidly Evolving Buhti Ransomware Operation
- Google Cloud Users Can Now Automate TLS Certificate Lifecycle
- Zyxel Firewalls Hacked by Mirai Botnet
- Watch Now: Threat Detection and Incident Response Virtual Summit
- NCC Group Releases Open Source Tools for Developers, Pentesters
- Memcyco Raises $10 Million in Seed Funding to Prevent Website Impersonation
- New Russia-Linked CosmicEnergy ICS Malware Could Disrupt Electric Grids
