# DraftKings Hacker "Snoopy" Sentenced: Inside a $600K Credential-Stuffing Fraud Ring
A Minnesota man who orchestrated a criminal marketplace selling stolen DraftKings accounts has been sentenced to 18 months in federal prison, marking the conclusion of a high-profile prosecutorial effort against one of the perpetrators behind a 2022 cyberattack that compromised over 67,000 customer accounts. The case illuminates how organized cybercriminals transform stolen credentials into profit through specialized underground marketplaces—and reveals gaps in how quickly law enforcement can dismantle such operations.
## The November 2022 Attack: Scale and Initial Response
In November 2022, DraftKings, one of the largest fantasy sports and sports betting platforms in North America, disclosed a significant security breach. Attackers used credential stuffing techniques to compromise customer accounts—a method where adversaries attempt to login using previously leaked username and password combinations, relying on users' tendency to reuse credentials across multiple platforms.
The scope of the incident expanded significantly in the weeks following disclosure:
The discrepancy between initial and revised figures underscores a common pattern in breach response: early estimates often underestimate both the number of affected accounts and the financial damage. For DraftKings customers, this meant a prolonged period of uncertainty about whether their financial data and account balances remained at risk.
## The Attack Method: Credential Stuffing Explained
Credential stuffing is a remarkably effective and relatively low-effort attack vector. Attackers obtain databases of previously compromised usernames and passwords from data breaches on other platforms, then use automated tools to attempt login to target services at scale.
Why this works against DraftKings specifically:
| Factor | Impact |
|--------|--------|
| Password reuse | Users often employ identical or similar passwords across multiple accounts |
| Financial incentive | Sports betting and fantasy sports accounts contain stored payment methods and cash balances |
| Scale of attempts | Botnets enable attackers to try millions of credentials in minutes |
| Detection difficulty | Moderate volume of login attempts may blend into normal traffic if monitoring thresholds are poorly tuned |
Once attackers gained access, they added their own payment methods to 1,600 accounts—a critical step that allowed them to withdraw stolen funds without exposing the original account holders' financial instruments.
## The Criminal Enterprise: "Snoopy's Shop" and Underground Markets
This case demonstrates that account compromise is only the first step in the cybercriminal supply chain. The real profit comes from monetizing stolen access through specialized underground marketplaces.
Nathan Austad, operating under the alias "Snoopy" (named after the Peanuts character), did not simply keep the stolen access for himself. Instead, he established his own marketplace where he sold access to compromised DraftKings accounts. The U.S. Department of Justice noted that Austad "directly controlled and profited from his own shop," alongside using other platforms such as the "Goat Shop" to distribute stolen credentials.
The monetization pipeline:
1. Compromise accounts through credential stuffing
2. Extract maximum value (drain balances, add attacker payment methods)
3. Sell remaining account access to other criminals
4. Distribute through multiple dark web marketplaces
5. Receive payment in cryptocurrency, creating a semi-anonymous financial trail
Austad's cryptocurrency accounts received approximately $465,000 in assets—evidence that even a mid-level actor in this ecosystem could accumulate substantial criminal proceeds.
## The Investigation and Prosecution Timeline
Unlike some cybercrime cases that go unsolved for years, federal authorities moved methodically but deliberately against the DraftKings attack conspirators:
The extended timeline—nearly four years from initial attack to Austad's sentencing—reflects the complexity of identifying perpetrators across jurisdictions, building digital evidence chains, and prosecuting conspiracy charges. Austad's own communications with co-conspirators proved damaging: direct messages where he "openly admitted to perpetrating fraudulent activity and warned others to prepare" provided prosecutors with clear intent evidence.
## Sentencing and Restitution Requirements
Austad's sentencing package included both punishment and remediation:
The restitution amount exceeds the confirmed stolen funds, reflecting broader legal liability for the conspiracy and acknowledged damages. However, the practical question of whether Austad can actually pay this amount—given his age (21 at sentencing), likely lack of legitimate income during prosecution, and criminal background—remains unclear. Restitution orders in cybercrime cases frequently go partially uncollected.
## Implications for Organizations and Defenders
This case offers critical lessons for both DraftKings-like services and organizations broadly:
Credential stuffing remains viable: Despite high-profile breaches and industry awareness, organizations continue to experience successful credential stuffing attacks, indicating that:
Account takeover markets are organized: The existence of dedicated marketplaces for stolen accounts suggests a mature criminal supply chain. Defenders should assume that any credential compromise will eventually be monetized somewhere.
Law enforcement capacity is limited: The nearly four-year gap between attack and final sentencing means that by the time consequences arrive, the ecosystem has evolved and new attacks have launched.
## HackWire Analysis: What This Case Reveals—and What It Misses
The DraftKings prosecution represents important work by federal authorities, but the narrative around it obscures a deeper reality: credential stuffing remains astonishingly profitable precisely because it's low-sophistication, high-volume, and hard to prevent without imposing friction on legitimate users.
Austad's 18-month sentence is proportionate to the harm caused, yet it fails to deter an ecosystem where thousands of similar actors operate undetected. The *cost* of getting caught—18 months in federal prison—is acceptable to many cybercriminals when weighed against the *profit potential*: Austad accumulated $465,000 in cryptocurrency during his operation. The expected value calculation favors the crime.
More troubling is what the prosecution narrative omits: infrastructure providers and dark web marketplaces that facilitated account sales received no charges. Austad sold through established platforms; those platforms remain operational and will host the next operator who replaces him. The indictment focuses on the criminal who committed the fraud, not the ecosystem that enabled it.
For defenders, the strategic takeaway is stark. Credential stuffing will continue until one of two conditions holds: either organizations implement mandatory multi-factor authentication (reducing account takeover profitability below threshold), or law enforcement dramatically increases consequences for marketplace operators and facilitators. Neither appears imminent.
Organizations handling financial data should treat credential stuffing as a persistent, background threat and deploy accordingly: aggressive rate-limiting on login endpoints, behavioral anomaly detection on account access following compromise, and mandatory MFA for any account with stored payment methods. DraftKings' exposure of 67,000 accounts happened in 2022; similar attacks are occurring right now at scale against less-public targets.
— HackWire Editorial
## Related Coverage