惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
DataBreaches.Net
B
Blog
博客园_首页
C
Check Point Blog
Microsoft Security Blog
Microsoft Security Blog
MyScale Blog
MyScale Blog
P
Proofpoint News Feed
Engineering at Meta
Engineering at Meta
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
B
Blog RSS Feed
M
MIT News - Artificial intelligence
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
WordPress大学
WordPress大学
宝玉的分享
宝玉的分享
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
The Cloudflare Blog
量子位
V
V2EX
Y
Y Combinator Blog
Hugging Face - Blog
Hugging Face - Blog
Martin Fowler
Martin Fowler
Recent Announcements
Recent Announcements
I
InfoQ
博客园 - 【当耐特】

Security Affairs

Digital attacks drive a new wave of cargo theft, FBI says Carding service Jerry’s Store leak exposes 345,000 stolen payment cards Anthropic launches Claude Security to counter rapid AI-Powered exploits SonicWall patches three SonicOS flaws in Gen 6, 7 and 8 firewalls. Patch them now Copy Fail: New Linux bug enables Root via page‑cache corruption Agent’s claims on WhatsApp access spark security concerns Meta accused of violating DSA by failing to safeguard minors Large-scale Roblox hacking operation shut down by Ukrainian authorities CVE-2026-42208: LiteLLM bug exploited 36 hours after its disclosure Internet censorship index reveals Russia’s lead and widespread content blocking All supported cPanel versions hit by critical auth bug, now patched U.S. CISA adds Microsoft Windows Shell and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog ShinyHunters exploit Anodot incident to target Vimeo CVE-2026-3854 GitHub flaw enables remote code execution Signal Phishing Campaign Targets German Officials in Suspected Russian Operation Microsoft fixes Entra ID flaw enabling privilege escalation New Android spyware Morpheus linked to Italian surveillance firm NCSC launches SilentGlass, a plug-in device to secure HDMI and DisplayPort links Medtronic discloses security incident after ShinyHunters claimed theft of 9M+ records Chinese spy posed as researcher in spear-phishing campaign targeting NASA to steal defense software LINKEDIN BROWSERGATE Firefox bug CVE-2026-6770 enabled cross-site tracking and Tor fingerprinting Fast16: Pre-Stuxnet malware that targeted precision engineering software Italy moves to extradite Chinese national to the U.S. over hacking charges U.S. utility giant Itron discloses a security breach Critical bug in CrowdStrike LogScale let attackers access files GopherWhisper: new China-linked APT targets Mongolia with Go-based malware SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 94 Trigona ransomware adopts custom tool to steal data and evade detection Security Affairs newsletter Round 574 by Pierluigi Paganini – INTERNATIONAL EDITION
DraftKings hacker sentenced to prison, ordered to pay $1....
Pierluigi Pa · 2026-04-17 · via Security Affairs

A DraftKings hacker got 30 months in prison for selling stolen credentials and must pay over $1.4 million in fines and restitution.

Kamerin Stokes, 23, from Memphis (aka TheMFNPlug), received a 30-month prison sentence for his role in a 2022 credential stuffing attack against DraftKings. He continued selling stolen login data online even after pleading guilty. The court also ordered three years of supervised release, $125,000 in forfeiture, and $1.3 million in restitution, highlighting the financial impact of the breach and the consequences of ongoing cybercrime activity.

“United States Attorney for the Southern District of New York, Jay Clayton, announced today that KAMERIN STOKES, a/k/a “TheMFNPlug,” was sentenced to 30 months in prison for his role in a scheme to hack user accounts on a fantasy sports and betting website (the “Betting Website”) and sell access to those accounts, resulting in losses of hundreds of thousands of dollars to the users.  STOKES was sentenced today before U.S. District Judge Naomi Reice Buchwald.” reads the press release published by DoJ.

In November 2022, attackers carried out a credential stuffing attack against DraftKings using large sets of stolen usernames and passwords bought on the dark web. They tested these credentials across accounts, targeting users who reused the same login details. The attackers managed to access around 60,000 accounts. In some cases, they added new payment methods, deposited small amounts to verify them, and then withdrew the full balance to accounts they controlled. This allowed them to steal funds directly from victims, showing how dangerous password reuse can be and how easily attackers can exploit compromised credentials at scale.

The man sold access to stolen DraftKings accounts through his own online shop under the alias “TheMFNPlug,” handling accounts worth over $125,000. Even after pleading guilty, he reopened the shop, selling stolen accounts from various platforms and promoting it with the slogan “fraud is fun.” He admitted running such operations for years and said he needed money for legal fees. Authorities arrested him again for violating release conditions and placed him back in custody.

“In addition to the prison term, STOKES, 23, of Memphis, Tennessee, was sentenced to three years of supervised release and ordered to pay $125,965.53 in forfeiture and $1,327,061 in restitution.” concludes DoJ. “Mr. Clayton praised the outstanding work of the Federal Bureau of Investigation.” 

In November 2022, DraftKings announced that approximately 68,000 accounts had been compromised in another credential stuffing attack.

In November 2023, US teenager Joseph Garrison pleaded guilty to his involvement in the credential stuffing attack. In January 2024, Garrison was sentenced to 18 months in prison.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, cybercrime)