breach
DraftKings Hacker "Snoopy" Sentenced to 18 Months
2026-06-25

Nathan Austad, a 21-year-old from Minnesota who went by the alias Snoopy, has been sentenced to 18 months in prison for his role in the November 2022 DraftKings hack. He and his co-conspirators worked their way into roughly 60,000 customer accounts, attached their own payment methods to about 1,600 of them, and walked away with around $600,000.
There was no zero-day. No clever exploit. No insider on the take. The crew ran a credential stuffing attack: feeding usernames and passwords leaked from other breaches into the DraftKings login page and seeing which ones still worked. A lot of them did, because a lot of people use the same password on the sports betting app that they use on their email, their cloud storage, and the forum they signed up to in 2014.
A shop named after a cartoon beagle
Austad ran his own marketplace selling access to the compromised accounts, named, apparently sincerely, after the Peanuts character. His crypto wallets took in about $465,000. He also messaged co-conspirators bragging about the fraud and telling them to brace for what was coming. That kind of paper trail tends to read poorly in a courtroom, and it did.
He joins two others already sentenced for the same scheme. Joseph Garrison got 18 months last year. Kamerin Stokes, who used the handle TheMFNPlug, got 30 months in April. Austad picks up $463,684 in forfeiture, $1.32 million in restitution, and three years of supervised release on top of the prison time.
DraftKings was never really breached
This is the awkward bit about credential stuffing attacks. The company on the headline didn't lose the passwords. The passwords were lost somewhere else, sometimes years earlier, on a site the customer barely remembers signing up to. By the time those credentials end up in a list traded on a forum, the original breach is old news. The damage shows up at whatever new login page the attacker decides to try next.
For DraftKings, the front door was wide open and there was nothing especially clever required to walk through it. The login page worked exactly as designed. The customers had simply handed out keys to their account, unknowingly, by reusing a password that had been compromised elsewhere.
Why this keeps working
Credential stuffing remains popular for the same reason phishing remains popular: it is cheap, easy to automate, and the success rate only needs to be tiny to be worth the effort. Attackers buy lists of leaked credentials, run them through cheap proxies to dodge rate limits, and see what hits. With password reuse rates as high as they are, something always hits.
- 60,000 accounts opened in the DraftKings incident
- 1,600 drained of around $600,000
- Three people now sentenced, with sentences ranging from 18 to 30 months
The technical defences against this, MFA, anomaly detection on logins, blocking known-breached passwords at signup, are well understood. The human side, getting people to stop using the same password in fifteen places, is the part that never quite gets solved. Snoopy and friends built a business out of that gap. They now have eighteen months to think about it.