logo

DraftKings warns of account breaches in credential stuffing attacks

ID: 891a811a-3651-5388-9fda-c545d09820c2

STIX ID: report--891a811a-3651-5388-9fda-c545d09820c2

Feed Name: Bleeping Computer

Threat Score
30/100

Date Published: 2025-10-07

Date Updated: 2026-07-18

Author: Sergiu Gatlan

...
...

DraftKings notified customers that a credential-stuffing campaign allowed attackers to access a small number of accounts and view limited personal data (name, address, DOB, phone, email, profile photo, last four card digits, transaction info). The company said its systems were not breached, sensitive financial or government ID data were not accessed, required password resets and MFA for affected users, and later reported the incident impacted fewer than 30 customers with no reported financial loss.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.