Executive Summary
In October 2025, DraftKings, a prominent sports betting company, disclosed that less than 30 customer accounts were compromised via credential stuffing attacks. Threat actors utilized previously stolen username and password combinations from breaches of unrelated services, leveraging automated tools to gain unauthorized access to DraftKings user accounts. While the attackers obtained personal data such as names, addresses, dates of birth, contact details, and the last four digits of payment cards, there was no evidence of access to sensitive government-issued IDs or full financial account numbers. DraftKings responded swiftly by notifying affected users, requiring password resets, and recommending the use of multifactor authentication to mitigate further risk.
This incident highlights the persistent threat of credential stuffing—an attack vector that exploits widespread password reuse. With large troves of leaked credentials available and automated attack tools on the rise, organizations across industries face increasing regulatory pressure to implement layered authentication and robust account monitoring to defend against identity-driven threats.
Why This Matters Now
Credential stuffing remains a fast-growing and highly effective attack method as users continue to reuse passwords across services. The DraftKings breach underscores the urgent need for organizations to enforce stronger authentication controls, educate customers on password hygiene, and monitor for unusual access patterns to stay ahead of evolving identity-based threats.
Attack Path Analysis
Attackers initiated the breach by using automated credential stuffing to access DraftKings user accounts with valid credentials from previous breaches. No privilege escalation was observed as attackers operated with the compromised user's permissions. Lateral movement within the cloud environment was not detected, with activity focused on harvested accounts. Attackers maintained access and issued commands to view or alter account data, but no advanced C2 infrastructure or persistence methods were evident. They attempted to exfiltrate personal user data and account details for financial gain. Ultimately, the impact was limited to the exposure of account information and potential fraud, with no evidence of financial loss or destructive actions.
Kill Chain Progression
Initial Compromise
Description
Attackers used automated credential stuffing attacks to gain unauthorized access to DraftKings accounts by leveraging previously leaked username and password pairs.
MITRE ATT&CK® Techniques
Brute Force: Credential Stuffing
Valid Accounts
Modify Authentication Process: Multi-factor Authentication
Account Discovery: Domain Account
Data from Local System
Email Collection
Steal Web Session Cookie
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Strong Authentication for Users
Control ID: 8.3.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy and Access Controls
Control ID: 500.03, 500.07
CISA ZTMM 2.0 – Identity Verification and Threat Detection
Control ID: IDENTITY-2, DETECT-4
NIS2 Directive – Access Control and Management
Control ID: Article 21(2)(d)
DORA (Digital Operational Resilience Act) – ICT Risk Management
Control ID: Article 9
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Gambling/Casinos
DraftKings credential stuffing attacks directly impact gambling sector, exposing customer financial data and requiring enhanced authentication controls and egress security measures.
Financial Services
Credential stuffing threats target financial platforms with reused passwords, necessitating zero trust segmentation, threat detection capabilities, and multicloud visibility controls.
Entertainment/Movie Production
Sports entertainment platforms face account takeover risks from automated credential attacks, requiring encrypted traffic protection and anomaly detection for customer data.
Information Technology/IT
IT sectors supporting online platforms need inline IPS, cloud firewall capabilities, and secure hybrid connectivity to prevent credential stuffing attacks effectively.
Sources
- DraftKings warns of account breaches in credential stuffing attackshttps://www.bleepingcomputer.com/news/security/draftkings-warns-of-account-breaches-in-credential-stuffing-attacks/Verified
- DraftKings alerts customers to account breaches from credential stuffinghttps://www.investing.com/news/stock-market-news/draftkings-alerts-customers-to-account-breaches-from-credential-stuffing-93CH-4275596Verified
- DraftKings Defends Against Credential Stuffing Attack, Urges Users to Reset Passwords and Enable MFAhttps://www.thaicert.or.th/en/2025/10/10/draftkings-defends-against-credential-stuffing-attack-urges-users-to-reset-passwords-and-enable-mfa/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Applying Zero Trust Network Segmentation, egress policy enforcement, and centralized anomaly detection would have limited account abuse and increased detection of unauthorized access. Fine-grained visibility and segmentation could curb the attack surface, restrict account data access, and rapidly surface credential-based misuse.
Control: Zero Trust Segmentation
Mitigation: Prevents broad account compromise by enforcing least-privilege access and segmenting exposed surfaces.
Control: Multicloud Visibility & Control
Mitigation: Detects anomalous privilege use and highlights unauthorized access scope changes.
Control: East-West Traffic Security
Mitigation: Prevents access to other internal systems or accounts in case of attempted pivot.
Control: Threat Detection & Anomaly Response
Mitigation: Rapid detection of suspicious account activity associated with automation or bulk access.
Control: Egress Security & Policy Enforcement
Mitigation: Restricts data flows and prevents unauthorized PII or account data exfiltration.
Contains breach scope and quickly isolates affected accounts or services.
Impact at a Glance
Affected Business Functions
- User Account Management
- Customer Support
Estimated downtime: 1 days
Estimated loss: N/A
Unauthorized access to customer accounts resulted in exposure of personal information including names, addresses, dates of birth, phone numbers, email addresses, last four digits of payment cards, profile photos, transaction histories, account balances, and password change dates. No sensitive data such as government-issued identification numbers or full financial account numbers were accessed.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce Zero Trust Segmentation to isolate user accounts and reduce exposure in the event of credential compromise.
- • Implement fine-grained egress security policies to monitor and restrict unauthorized data exports from user profiles.
- • Leverage anomaly detection and centralized visibility to flag suspicious account access and credential stuffing attempts.
- • Require and monitor for multifactor authentication (MFA), enforcing modern identity controls to deter automated account abuse.
- • Regularly review privilege assignments and segment internal flows with east-west security controls to block lateral movement risks.



