# Federal Court Sentences Third DraftKings Hacker to 18 Months in Prison
A federal judge has sentenced Nathan Austad to 18 months in federal prison for his role in unauthorized access to the DraftKings online gaming platform, marking the third individual prosecuted in connection with a series of breaches that exposed sensitive customer data. The sentencing, which also includes $1.8 million in forfeiture and restitution alongside three years of supervised release, represents ongoing law enforcement action against cybercriminals targeting the rapidly growing sports betting and fantasy sports industry.
## The DraftKings Security Breaches
DraftKings, one of North America's largest daily fantasy sports and online sportsbook platforms with millions of registered users, has faced multiple significant security incidents in recent years. The breaches that led to Austad's prosecution resulted in the compromise of customer data including names, encrypted passwords, email addresses, and phone numbers. The unauthorized access occurred between 2018 and 2019, during a period when the platform was rapidly expanding its user base across newly regulated markets.
The compromised information was subsequently exposed on dark web marketplaces, creating significant potential for identity theft, credential stuffing attacks, and targeted phishing campaigns against DraftKings customers. The platform serves both casual fantasy sports enthusiasts and serious bettors with significant financial stakes, making the breach particularly concerning given the sensitive nature of account information linked to payment methods and financial transactions.
## Nathan Austad's Role and Criminal Activity
Nathan Austad was identified as a key participant in the unauthorized access scheme, leveraging his technical knowledge to compromise DraftKings' systems. According to court documents, Austad and his co-conspirators obtained access to the platform through a combination of techniques, including credential compromise and exploitation of system vulnerabilities. His actions went beyond passive possession of stolen data—Austad actively participated in the initial breach and subsequent unauthorized access activities.
The prosecution revealed that Austad operated within a network of cybercriminals who specialized in targeting high-value online platforms, particularly those in the gaming and financial sectors. His technical skills enabled him to persist within compromised networks, maintain access over extended periods, and extract large volumes of customer data. The case underscores how organized cybercriminal groups systematically target digital platforms that handle financial transactions and store valuable personal information.
## Sentencing Details and Legal Consequences
The 18-month federal prison sentence handed down by the court reflects the serious nature of Austad's crimes, which included unauthorized computer access under the Computer Fraud and Abuse Act (CFAA). The $1.8 million in combined forfeiture and restitution represents reimbursement to DraftKings for incident response costs, security improvements, customer notification expenses, and credit monitoring services provided to affected users.
The sentencing is significant because it balances punitive measures with restitution obligations—Austad must compensate victims and the organization for concrete harms caused by the breach. The three-year supervised release period includes standard conditions such as restrictions on computer and internet access, regular check-ins with a probation officer, and prohibitions on further unauthorized computer use. These conditions, typical in computer crime cases, prevent reoffense by limiting the defendant's ability to access the tools and platforms that facilitated the original crime.
## Pattern of Prosecutions in the DraftKings Case
Austad's sentencing marks the third individual prosecuted in connection with the DraftKings breaches, indicating a sustained law enforcement effort to hold multiple participants accountable. The progression of prosecutions suggests a coordinated investigation that has systematically identified and pursued members of the cybercriminal network responsible for the attacks.
| Aspect | Details |
|--------|---------|
| Platform Targeted | DraftKings (daily fantasy sports/sportsbook platform) |
| Breach Period | 2018-2019 |
| Data Compromised | Names, emails, encrypted passwords, phone numbers |
| Defendants Prosecuted | Multiple individuals across different charges |
| Current Sentence | 18 months federal prison + $1.8M restitution + 3 years supervision |
The multi-defendant approach reflects standard federal cybercrime investigations, which often require time to identify conspiracy members, collect evidence, and coordinate with other jurisdictions. Each prosecution sends an incremental message to would-be cybercriminals that breaching major platforms carries significant personal consequences.
## Broader Implications for Online Gaming Industry
The DraftKings prosecutions occur amid rapid expansion of online sports betting and daily fantasy sports across North America. Major platforms in this sector handle substantial amounts of customer financial data, personal information, and payment details, making them attractive targets for cybercriminals. The combination of high-value customer data and financial transaction capabilities creates compelling incentives for breach attempts.
Online gaming platforms face particular security challenges due to:
DraftKings and competitors have significantly increased security investments following these breaches, but the incident demonstrates that determined threat actors continue targeting the sector. The availability of stolen gaming platform credentials on dark web marketplaces continues to fuel secondary attacks against those platforms' users.
## Law Enforcement and Deterrence
Federal prosecutors have consistently pursued Computer Fraud and Abuse Act charges against individuals who breach major platforms, treating such crimes as serious federal offenses rather than minor technical transgressions. The sentencing length and restitution amounts reflect judicial recognition that data breaches cause measurable harm to organizations and individuals beyond simple financial loss.
The investigation and prosecution process typically involves coordination between federal law enforcement (FBI, Secret Service), the affected company's internal investigations team, and digital forensics specialists. In the DraftKings case, investigators traced unauthorized access patterns, identified persistence mechanisms, and connected individual defendants to specific portions of the breach activity through log analysis and network forensics.
---
## HackWire Analysis
The Austad sentencing represents an important enforcement milestone in the DraftKings investigation, but it also illustrates a painful reality for the online gaming industry: determined adversaries will target platforms handling valuable customer data, and remediation requires years of investigation and prosecution. What's notable here is the *pattern* dimension—three defendants across the same breach network suggests this wasn't opportunistic hackers but an organized operation with division of labor. Someone accessed systems, someone exfiltrated data, someone marketed it.
This timing matters because online sports betting is still relatively young in the U.S. regulatory environment. Each new state legalization brings a rush of platform expansion and investment, sometimes ahead of mature security practices. The DraftKings breaches remind platforms that shortcuts on infrastructure security carry not just financial cost (incident response, fines, customer remediation) but *criminal prosecution risk* for employees and contractors who cut corners. The $1.8 million restitution sends a message: breach a major platform, and you'll spend years and significant personal resources in court and supervised release.
For defenders: the case underscores that credential compromise remains a serious entry point. The breach chain likely began with weak password practices, credential reuse across platforms, or phishing—all preventable with baseline hygiene. For platforms themselves, the multi-year investigation window shows that breach response is not a single incident but a sustained process of investigation, prosecution, and deterrence.
— HackWire Editorial
---
## Related Coverage