Betting company DraftKings was the victim of a credential stuffing attack last month and today revealed that the personal information of 67,000 people was exposed.
In credential stuffing attacks, automated tools are used to make multiple attempts (up to millions at a time) to log into accounts using credentials (username/password) stolen from other online services.
See also: DraftKings: $300,000 lost to credential stuffing

It’s common knowledge that we shouldn’t use the same password on every site. If you don’t, you’ll be an easy target for a potential credential stuffing attack.
Hackers try to take over as many accounts as possible so they can steal personal and financial information. This information can then be sold on hacking forums or the dark web.
However, stolen information can also be used in identity theft to make unauthorized purchases or empty compromised bank accounts.
Nearly 68,000 DraftKings customers affected
In a data breach notification filed with the Maine Attorney General, DraftKings revealed that the data of 67,995 people was exposed after last month’s attack.
The company said the hackers obtained the information they needed to log into their customers’ accounts from an external party, not directly from them.
The notification states that the attackers were able to see, among other things, the name, address, number, email, the last 4 digits of the payment card, as well as many other details from the compromised accounts.
What appears to have been unaffected are the social security number, driver's license number and account . After the attack was detected, the company rushed to reset the passwords of the accounts that had been exposed.
See also: Users of the Ukrainian military system DELTA are targeted by info-stealing malware

All of the compromised accounts had one thing in common: the attackers deposited $5, changed the password, enabled two-factor authentication on a different phone number, and then withdrew as much money as possible from the victims’ linked bank accounts. The sportsbook hasn’t shared any more details about how this happened, but BleepingComputer has learned that a threat actor was selling the stolen accounts for between $10 and $35. The sales package also included instructions on how buyers could make a $5 deposit and withdraw all of the money from the compromised DraftKings user accounts. When DraftKings announced the credential stuffing attack, it locked the compromised accounts, with the attackers saying their campaign had stopped working. The company advises users not to use the same password for multiple online services, not to share their credentials with third-party platforms, to immediately enable 2FA on accounts, to delete bank details or to deactivate bank accounts. As reported by both the FBI and Okta , the situation with credential stuffing attacks has worsened recently. In the first months of 2022, they recorded over 10 billion credential stuffing events. This number corresponds to about 34% of the authentications recorded by Okta, which means that about 1 in 3 login attempts is malicious . Source of information: bleepingcomputer.com
