DraftKings said it will refund customers affected by a credential stuffing attack that led to losses of up to $300,000.
See also: North Face: 200,000 accounts compromised through credential stuffing

Amid reports of issues , DraftKings issued a statement early Monday morning.
All of the compromised accounts had one thing in common: the attackers deposited $5, changed the password, enabled two-factor authentication on a different phone number, and then withdrew as much money as possible from the victims' linked bank accounts.
Several victims took to social media to vent their frustration after seeing their attackers continuously withdrawing money from their bank accounts while they were unable to contact anyone at DraftKings.
More than 12 hours after the incident, DraftKings President and Co-Founder Paul Libermanrevealed that “we currently believe that these customers’ login information was compromised on other websites and then used to gain access to their DraftKings accounts, where they used the same login information.”
See also: FBI: Home proxies exploited in credential stuffing attacks
The company advised customers to never use the same password for different online services and to never share their credentials with platforms not provided by DraftKings, including betting tracking devices and apps.

If you are a DraftKings customer and have not been affected by this credential hiding campaign, enable 2FA for your account immediately. You should also remove any banking information or disconnect your bank accounts to block fraudulent withdrawal requests.
In credential stuffing attacks, hackers use stolen username and password combinations to gain access to user accounts on various websites and services. This is done by using automated bots that repeatedly try different username and password combinations until they find a match, at which point they gain access to the account.
The goal of hackers is to take over as many accounts as possible to steal personal information and financial data that can later be sold on the dark web or on hacker forums.
See also: General Motors (GM): Credential stuffing attack exposed customer data
With the stolen information, future identity theft scams could be committed, such as unauthorized purchases or—as happened in the DraftKings case—transferring funds from linked bank accounts to accounts controlled by the attacker.
As the FBI warns, attacks are increasing in volume due to easily accessible credential leak lists and automated tools.
