ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

DraftKings hacker charged in US Court for enabling the theft of $600K from customer accounts

The US Department of Justice charged an 18-year-old man for hacking into and selling access to the accounts of thousands of DraftKings users in November 2022.

According to a criminal complaint, Joseph Garrison of Madison, Wisconsin, is accused of being the mastermind behind the credential-stuffing attack on sports betting site DraftKings in November 2022 that affected around 68,000 individuals.DraftKings believed that an amount close to $300,000 was stolen by the hackers and the company had committed to reimburse all affected customers in due course.Paul Liberman, the co-founder of DraftKings, said, “We currently believe that the login information of these customers was compromised on other websites and then used to access their DraftKings accounts where they used the same login information.“We have seen no evidence to suggest that DraftKings’ systems were breached to obtain this information.”The fresh complaint mentions that Garrison gathered an extensive list of credentials, accumulated from other breaches, and used them to gain access to DraftKings accounts. He also sold the hacked accounts to other fraudsters who withdrew approximately $600,000 from the victims’ accounts. Garrison personally earned in excess of $5,000 by carrying out credential stuffing on DraftKings’ website.In February 2023, law enforcement agencies searched Garrison’s residence and found OpenBullet and SilverBullet, tools commonly used in credential-stuffing attacks, on his computer. “To launch a credential stuffing attack using OpenBullet or SilverBullet, an individual needs both a “wordlist” and a “config.” A “wordlist” contains a series of username and password combinations, while a “config” is a script that will run the wordlist through the log-in page of a particular website.“On the Garrison Computer, law enforcement located 11 separate Betting Website configs. Metadata shows that the earliest creation date for one of those configs was November 17, 2022, approximately one day before the Betting Website Attack,” the document read.Law enforcement agencies also found logs of chats between Garrison and his co-conspirators, discussing how to execute the credential stuffing attack on the betting websites, where Garrison said “fraud is fun.”“As alleged, Garrison attained unauthorised access to victim accounts using a sophisticated cyber-breaching attack to steal hundreds of thousands of dollars. Cyber intrusions aiming to steal private individuals’ funds represent a serious risk to our economic security,” said FBI Assistant Director in Charge Michael J. Driscoll.Previously, Garrison was questioned by the Wisconsin police for running a website named “Goat Shop” that sold access to hacked accounts from where he made around $800,000. Garrison, however, claimed that he was no longer involved with the cybercrime world.“On the Garrison Phone, law enforcement located an undated picture showing that Goat Shop had sold 225,247 products for total sales revenue of $2,135,150.09,” the complaint read.Garrison is now charged with conspiracy to commit computer intrusions, unauthorised access to a protected computer to further intended fraud, two counts of wire fraud, and aggravated identity theft.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543