Online sports betting platform DraftKings has disclosed a credential stuffing attack that occurred on September 2, 2025, resulting in unauthorized access to certain user accounts. The incident involved attackers using login credentials obtained from external sources to gain entry to DraftKings accounts, though the company’s internal systems and networks remained secure. The security breach comes at a time when online gaming platforms are increasingly implementing sophisticated identity verification measures, with companies like Socure expanding their KYC solutions across multiple US states to enhance security in digital gaming operations.
According to the notification, the compromised information potentially accessed by attackers included customer names, addresses, email addresses, phone numbers, dates of birth, profile photos, last four digits of payment cards, transaction details, account balances, and password change dates. DraftKings emphasized that government-issued ID numbers, complete financial account numbers, and other sensitive data remained protected.
The attack was identified as a credential stuffing campaign, which matches the MITRE ATT&CK technique T1110 (Brute Force). The method involves automated attempts to access accounts using username and password combinations stolen from other data breaches. Security teams detected the attack through multiple indicators, including suspicious IP addresses, unusual user agent strings, and patterns of failed login attempts followed by successful access.
In response to the incident, DraftKings implemented several security measures. The company mandated password resets for affected accounts and required multi-factor authentication (MFA) for DraftKings Horse accounts. The enhancement follows an industry-wide trend of strengthening authentication measures, similar to Riot Games’ recent implementation of mobile verification to enhance account security. Additionally, the platform advised all customers to enable MFA and monitor their credit reports for potential fraudulent activity.
“By stealing login credentials from a non-DraftKings source and using them in this attack, the bad actor may have temporarily been able to log into certain DraftKings customers’ accounts,” DraftKings stated in their official notification letter to the Massachusetts Office of Consumer Affairs and Business Regulation (OCABR). “Importantly, our investigation to date has observed no evidence that your login credentials were obtained from DraftKings or that DraftKings’ computer systems or networks were breached as part of this incident.”
The security event demonstrates the ongoing risks associated with password reuse across multiple online platforms and reinforces the importance of implementing unique passwords and multi-factor authentication for online accounts. The incident highlights why gaming platforms are increasingly investing in advanced verification technologies, including AI-powered solutions and robust identity verification systems, to protect user accounts and maintain platform integrity.
Sources: TechRadar, FireCompass, SecurityWeek