On June 23, 2026, Nathan Austad of Minnesota was sentenced to 18 months in federal prison for his role in a credential-stuffing conspiracy that compromised approximately 60,000 accounts at a major fantasy sports and betting platform and led to roughly $600,000 in thefts from about 1,600 user balances.
Although court filings refer to the victim only as a "fantasy sports and betting website," the attack details match the November 2022 credential-stuffing incident publicly disclosed by DraftKings. Austad, who operated online under the alias "Snoopy," pleaded guilty in December 2025 to conspiring to commit computer intrusion.
What credential stuffing is
Credential stuffing is not hacking in the Hollywood sense. Attackers buy or collect username-and-password pairs leaked in unrelated breaches, then automate login attempts elsewhere, betting that users reused passwords. When a match succeeds, the attacker controls the account.
According to prosecutors, Austad and co-conspirators launched the attack around November 18, 2022. On roughly 1,600 accounts, they added payment methods they controlled, made small verification deposits, and withdrew existing balances — a pattern DraftKings customers reported at the time.
Sentences in the wider case
Austad was ordered to serve three years of supervised release and pay substantial restitution and forfeiture. Two other defendants had previously been sentenced in the same investigation: Joseph Garrison received 18 months in prison in early 2024, and Kamerin Stokes, known online as "TheMFNPlug," received 30 months in April 2026.
U.S. Attorney Jay Clayton for the Southern District of New York said the case showed that reused passwords remain a practical weapon against betting accounts even on well-resourced platforms.
What players should take from this
Licensed sportsbooks and casinos cannot fully protect accounts when customers reuse credentials exposed elsewhere. Unique passwords and two-factor authentication remain the most effective user-side defenses. This case also shows that account takeover can drain real balances quickly — not merely steal loyalty points.
