Accounts on the popular app DraftKings, used by sports enthusiasts to play fantasy sports, were breached by an unknown attacker in order to perpetrate digital theft. The attack managed to gain access to accounts and drain funds that were stored in the account. On top of stealing stored funds, the threat actor was also able to use the linked credit card or bank account on file to add more funds to the account and then withdraw them into their own account almost instantly. According to DraftKings, no breach of the app itself occurred; it is believed that the attacker managed to steal login credentials from other websites, and prey on those who reused their passwords. When some users went to change their passwords to stop the attack, they had found that the attacker changed the phone number on file, used to reset passwords, preventing targeted users from stopping the attacks.
12 Essentials for a Successful SOC Partnership
As cyber threats continue to impact businesses of all sizes, the need for round-the-clock security