Nathan Austad, a 21-year-old Minnesota man who used the alias "Snoopy", was sentenced to 18 months in prison for his role in the 2022 credential-stuffing attack that compromised DraftKings customer accounts. U.S. prosecutors said Austad pleaded guilty to conspiracy to commit computer intrusion and admitted participating in a scheme that used usernames and passwords from other breaches to access DraftKings accounts protected by weak or reused credentials. He was also sentenced to three years of supervised release and ordered to pay roughly $1.8 million in restitution and forfeiture.
Authorities said the group compromised about 60,000 accounts, while DraftKings previously disclosed that 67,995 customer accounts were affected. The attackers added payment methods they controlled to roughly 1,600 accounts, stole about $600,000, and sold access to compromised accounts through online marketplaces including Goat Shop and Austad’s own Snoopy-branded site. Investigators also traced about $465,000 in cryptocurrency tied to Austad, and his sentencing makes him the third defendant convicted in the case after Joseph Garrison and Kamerin Stokes received prison terms.

See the reporting duties and controls this puts on the clock.
6 events from the most recent confirmed update back to the earliest known activity.
Kamerin Stokes, also known as “TheMFNPlug,” was sentenced in April to 30 months in prison for his role in the 2022 DraftKings hacking case. The sentencing made him one of the defendants punished in connection with the credential-stuffing scheme against DraftKings accounts.
The U.S. Department of Justice announced that Nathan Austad was sentenced to 18 months in prison for his role in the 2022 DraftKings credential-stuffing attack. He was also ordered to serve three years of supervised release and pay restitution and forfeiture totaling roughly $1.8 million.
U.S. authorities charged Joseph Garrison in May 2023 for his role in the DraftKings account hacking campaign. He was one of the defendants tied to the credential-stuffing operation.
In December 2025, Nathan Austad pleaded guilty to conspiracy to commit computer intrusion in connection with the DraftKings hacking campaign. He admitted participating in the compromise of 60,000 DraftKings accounts.
In January 2024, U.S. authorities charged Nathan Austad and Kamerin Stokes for their alleged roles in the DraftKings credential-stuffing scheme. Prosecutors linked them to the theft of funds and the sale of access to hacked accounts.
In November 2022, attackers used usernames and passwords from other breaches to compromise DraftKings accounts through credential stuffing. The scheme affected tens of thousands of accounts, with criminals stealing funds from about 1,600 accounts and selling access to compromised accounts online.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
7 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecyberscoop.com
Open sourcesecurityaffairs.com
Open sourcehelpnetsecurity.com
Open sourcesecurityweek.com
Open sourcebleepingcomputer.com
Open sourcejustice.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.