DraftKings, a major American sports betting and daily fantasy sports provider, experienced a credential stuffing attack that resulted in unauthorized access to some customer accounts. The attack was detected on September 2, 2025, when the company noticed suspicious login activity consistent with credential stuffing, a technique where attackers use stolen username and password pairs from previous breaches to gain access to user accounts on other platforms. DraftKings promptly launched an investigation and took steps to contain the incident, including notifying affected users and requiring password resets. The company emphasized that there was no evidence of a breach of its internal systems or networks, and that sensitive customer data such as government-issued identification numbers and full financial account numbers were not accessed. However, attackers may have viewed personal information including names, addresses, dates of birth, phone numbers, email addresses, the last four digits of payment cards, profile photos, transaction details, account balances, and the date the password was last changed. DraftKings stated that the login credentials used in the attack were not obtained from their own systems, but rather from external sources, highlighting the risks associated with password reuse across multiple online services. The company reassured customers that there was no indication of identity theft or unauthorized access to bank accounts as a result of this incident. In response, DraftKings required all potentially affected users to reset their passwords and strongly urged the adoption of multi-factor authentication (MFA) to enhance account security. The company also communicated transparently with its user base through data breach notification letters, outlining the nature of the attack and the steps being taken to protect customer information. DraftKings' swift response and containment measures were aimed at minimizing the impact of the attack and preventing further unauthorized access. The incident underscores the ongoing threat posed by credential stuffing attacks, particularly for organizations with large user bases and valuable personal data. DraftKings' experience serves as a reminder for all users to avoid reusing passwords and to enable MFA wherever possible. The company continues to monitor its systems for suspicious activity and is working to strengthen its security posture in light of this event. No evidence has emerged to suggest that the attackers were able to monetize the accessed information or that any widespread fraud has occurred. DraftKings' handling of the incident has been characterized by prompt action, clear communication, and a focus on user security. The attack highlights the importance of robust authentication practices and user education in defending against credential-based threats. DraftKings remains committed to safeguarding customer data and maintaining trust in its platform.

See attribution, scope, and your downstream exposure.
2 events from the most recent confirmed update back to the earliest known activity.
After detecting the attacks, DraftKings notified affected users, warned that some accounts had been breached, and advised customers to reset passwords. The company also urged users to enable multi-factor authentication to better protect their accounts from reused-credential attacks.
DraftKings identified credential stuffing activity targeting customer accounts, in which attackers attempted logins using usernames and passwords exposed in breaches at other services. The activity led to unauthorized access to some accounts before the company moved to contain it.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecurityaffairs.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.