Third DraftKings Credential-Stuffing Conspirator Sentenced to 18 Months

Nathan Austad gets a year and a half in federal prison, plus $1.8 million in forfeiture and restitution, closing out the last of the DraftKings account-takeover prosecutions.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 2 min read
Third DraftKings Credential-Stuffing Conspirator Sentenced to 18 Months
Share

Key points

  • Nathan Austad was sentenced to 18 months in federal prison for his role in a credential-stuffing campaign against DraftKings.
  • The sentence includes three years of supervised release and approximately $1.8 million in combined forfeiture and restitution.
  • Austad is the third and final defendant sentenced in the scheme.
  • The attack relied on reused passwords, not a novel exploit, and drained real money from real user accounts.
  • Mandatory MFA is no longer a UX debate for platforms handling real money; it is the floor.

What did Austad actually do?

The method was not complicated. Attackers obtained username-password pairs from earlier third-party breaches, ran them against DraftKings login endpoints, and cashed out accounts whose owners had reused credentials. No zero-day, no novel technique. Just the grinding consequence of password reuse meeting an authentication surface that wasn't rate-limited or MFA-enforced tightly enough at the time.

This pattern keeps showing up. We first covered credential stuffing at scale in our FortiBleed report on 23 June, where harvested credentials fed brute-force runs against exposed FortiGate appliances. Different sector, same root cause.

Should you worry about the detection problem?

Yes, and the $1.8 million figure is the reason. That is court-ordered forfeiture and restitution combined, meaning the government's harm calculation in front of a judge represented real money leaving real accounts, not a theoretical blast radius.

Credential stuffing sits in a frustrating middle zone for security teams. The traffic looks almost legitimate. It arrives from residential proxies and bot networks that defeat naive IP-block rules. Gambling platforms process high-velocity transactions constantly, so a stuffing run that stays inside normal transaction envelopes is genuinely hard to distinguish from a busy football weekend. By the time a SIEM alerts on anomalous login volume, the payments processor has already logged the damage.

The gap between first compromised account and platform-wide response is where the real cost accumulates.

What should auth teams take from this?

Three defendants sentenced, prosecution closed. The practical lesson is short: if your platform touches real money, mandatory MFA is the minimum viable control, not a UX tradeoff. Adaptive authentication on AWS Cognito, Azure AD B2C or Google Identity Platform can enforce step-up challenges on high-risk login signals without friction on clean sessions. The tooling exists. The DraftKings case is what happens when you defer it.

© 2026 Threat Vectr