Man gets 30 months for selling thousands of hacked DraftKings accounts
嗯,用户让我总结一下这篇文章的内容,控制在100字以内,而且不需要用“文章内容总结”这样的开头。好的,我先快速浏览一下文章。 文章讲的是一个叫Kamerin Stokes的年轻人,23岁,来自田纳西州的孟菲斯。他因为出售被黑客入侵的DraftKings账户而被判30个月监禁。这些账户是在2022年11月被Nathan Austad和Joseph Garrison通过 credential-stuffing 攻击获取的,总共影响了近6.8万个账户。 然后,Stokes通过自己的“商店”转卖这些账户,从中获利。后来他被逮捕,在保释期间又重新开了店,并用“欺诈很有趣”的标语宣传。最后他再次被捕,并被判刑、赔偿和没收财产。 我需要把这些信息浓缩到100字以内。重点包括:Stokes被判刑的原因、涉及的黑客攻击、金额、以及他的行为。 可能的结构是:Stokes因出售被黑DraftKings账户获刑30个月,涉及6.8万账户,涉案金额超过63万美元。他在保释期间重新开店继续犯罪活动。 检查一下字数是否在限制内,并确保信息准确无误。 </think> 23岁的Kamerin Stokes因出售被黑DraftKings账户获刑30个月,涉及近6.8万个账户和超63万美元损失。他通过网络商店转卖这些账户,并在保释期间重新开店继续犯罪活动。 2026-4-17 07:16:38 Author: www.bleepingcomputer.com(查看原文) 阅读量:11 收藏

Hacker

23-year-old Kamerin Stokes of Memphis, Tennessee, was sentenced to 30 months in prison for selling access to tens of thousands of hacked DraftKings accounts.

According to court documents, the accounts were hijacked by Nathan Austad (aka Snoopy) with the help of Joseph Garrison (a third accomplice charged in May 2023) in a massive November 2022 credential-stuffing attack that compromised nearly 68,000 DraftKings accounts.

U.S. prosecutors said Austad and Garrison used a list of credentials stolen in multiple breaches to hack into DraftKings accounts, then sold access to others who stole around $635,000 from roughly 1,600 compromised accounts.

Wiz

While they made over $2.1 million selling some of these hijacked DraftKings accounts (as well as FanDuel and Chick-fil-A accounts) through their own "shops," they also sold many in bulk to Stokes (also known online as TheMFNPlug), who resold them through his own "shop." 

One month later, the sports betting giant said it had to refund hundreds of thousands of dollars stolen from hacked accounts, after all available funds were withdrawn following the addition of a new payment method and a $5 deposit to verify its validity.

DraftKings "cash-out" instructions
DraftKings "cash-out" instructions (BleepingComputer)

​After being arrested, pleading guilty, and released while awaiting trial, Stokes reopened his shop with a new "fraud is fun" tagline and continued selling access to compromised accounts for various retailers.

Prosecutors said he also admitted "he had been running these types of shops for three years" and that he relaunched the shop because he needed money to pay his attorney.

"Kamerin Stokes victimized thousands of users of an online betting website though [sic] a cyberattack," U.S. Attorney Jay Clayton noted in a Thursday press release.

"After pleading guilty to federal crimes, Stokes audaciously reopened his criminal business, marketed using the tagline' fraud is fun,' and said that he opened the new Shop in part because 'gotta pay my attorneys,' referring to his prosecution in this case."

After reopening his website, Stokes was again remanded into federal custody after being arrested for violating the conditions of his pretrial release.

In addition to 30 months in prison, Stokes was given 3 years of supervised release and ordered to pay $1,327,061 in restitution and $125,965.53 in forfeiture.

tines

99% of What Mythos Found Is Still Unpatched.

AI chained four zero-days into one exploit that bypassed both renderer and OS sandboxes. A wave of new exploits is coming.

At the Autonomous Validation Summit (May 12 & 14), see how autonomous, context-rich validation finds what's exploitable, proves controls hold, and closes the remediation loop.


文章来源: https://www.bleepingcomputer.com/news/security/man-gets-30-months-for-selling-thousands-of-hacked-draftkings-accounts/
如有侵权请联系:admin#unsafe.sh