The case of the cyberattack on the DraftKings continues to concern American authorities, as another person involved was convicted for his participation in the organized scheme to hack user accounts.

Nathan Austad, 21, of Minnesota, known online as “ Snoopy ,” was sentenced to 18 months in prison after pleading guilty to conspiracy to gain unauthorized access to computer systems . He admitted to being part of a cybercriminal group that managed to hack into about 60,000 DraftKings user accounts
Dor also: DraftKings: Account compromise via credential stuffing
How the attack took place
The cyberattack occurred in November 2022 and was based on the technique credential stuffing. This is a particularly widespread breach method in which perpetrators use lists of stolen login credentials from previous data leaks and test them en masse on other services.
In the case of DraftKings, the attackers primarily exploited weak passwords and the practice of reusing the same credentials across multiple platforms. This method proved to be highly effective, as thousands of user accounts were exposed without requiring the use of advanced hacking techniques.
According to judicial authorities, the hackers added their own payment methods to approximately 1,600 accounts and managed to extract more than $600,000.
The market for stolen accounts
Investigations revealed that the case was not just about stealing money, but also about creating an illegal ecosystem for trading compromised accounts. The perpetrators allegedly sold access to DraftKings accounts through online marketplaces such as the “Goat Shop,” creating a parallel economy around the stolen digital data.
Prosecutors allege that Austad operated his own online store, which he named “Snoopy,” after the popular Peanuts comic strip character. Through this platform, he trafficked login credentials to compromised accounts and made significant financial profits.
See also: Apple: Privacy Rules for Third-Party Access to Live Activities and Notifications
Although the exact amount of the illicit profits has not been made known, the US Department of Justice reports that cryptocurrency accounts linked to Austad received approximately $465,000 worth of digital assets.

User errors and the perennial problem of security
The DraftKings case highlights one of the biggest problems of the digital age: poor password management. Despite repeated warnings from experts, millions of users still use the same passwords across different services, dramatically increasing the risk of a breach.
Credential stuffing attacks have become one of the most effective forms of cybercrime, as they do not require sophisticated hacking techniques. Instead, they rely primarily on human negligence and the inability of many users to implement basic cybersecurity practices.
The use of strong and unique passwords, the use of password managers and, above all, the activation of multi-factor authentication are now essential protection measures.
See also: Nintendo: Employee data breach via third-party provider
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Another message to the cybercrime market
In addition to the prison sentence, Nathan Austad was sentenced to three years of supervised releaseand ordered to pay more than $1.7 million in forfeiture and restitution. This is the third significant conviction related to the case, following the sentences imposed on Joseph Garrison and Kamerin Stokes.
This case demonstrates that digital service platforms continue to be an attractive target for organized cybercriminal networks. At the same time, it reminds us that cybersecurity is not solely the responsibility of companies, but also of users themselves, who are called upon to treat their personal accounts as valuable digital assets.
