Third DraftKings Credential-Stuffing Conspirator Sentenced to 18 Months
Nathan Austad gets a year and a half in federal prison, plus $1.8 million in forfeiture and restitution, closing out the last of the DraftKings account-takeover prosecutions.

Key points
- Nathan Austad was sentenced to 18 months in federal prison for his role in a credential-stuffing campaign against DraftKings.
- The sentence includes three years of supervised release and approximately $1.8 million in combined forfeiture and restitution.
- Austad is the third and final defendant sentenced in the scheme.
- The attack relied on reused passwords, not a novel exploit, and drained real money from real user accounts.
- Mandatory MFA is no longer a UX debate for platforms handling real money; it is the floor.
What did Austad actually do?
The method was not complicated. Attackers obtained username-password pairs from earlier third-party breaches, ran them against DraftKings login endpoints, and cashed out accounts whose owners had reused credentials. No zero-day, no novel technique. Just the grinding consequence of password reuse meeting an authentication surface that wasn't rate-limited or MFA-enforced tightly enough at the time.
This pattern keeps showing up. We first covered credential stuffing at scale in our FortiBleed report on 23 June, where harvested credentials fed brute-force runs against exposed FortiGate appliances. Different sector, same root cause.
Should you worry about the detection problem?
Yes, and the $1.8 million figure is the reason. That is court-ordered forfeiture and restitution combined, meaning the government's harm calculation in front of a judge represented real money leaving real accounts, not a theoretical blast radius.
Credential stuffing sits in a frustrating middle zone for security teams. The traffic looks almost legitimate. It arrives from residential proxies and bot networks that defeat naive IP-block rules. Gambling platforms process high-velocity transactions constantly, so a stuffing run that stays inside normal transaction envelopes is genuinely hard to distinguish from a busy football weekend. By the time a SIEM alerts on anomalous login volume, the payments processor has already logged the damage.
The gap between first compromised account and platform-wide response is where the real cost accumulates.
What should auth teams take from this?
Three defendants sentenced, prosecution closed. The practical lesson is short: if your platform touches real money, mandatory MFA is the minimum viable control, not a UX tradeoff. Adaptive authentication on AWS Cognito, Azure AD B2C or Google Identity Platform can enforce step-up challenges on high-risk login signals without friction on clean sessions. The tooling exists. The DraftKings case is what happens when you defer it.



