Back to News
Regulation & Legislation
2 min read

US Court Sentences Man for Reselling Hacked DraftKings Accounts

US Court Sentences Man for Reselling Hacked DraftKings Accounts
Share:

US Court Sentences Man for Reselling Hacked DraftKings Accounts

A federal court in the Southern District of New York has sentenced 23-year-old Kamerin Stokes of Memphis, known online as TheMFNPlug, to 30 months in prison for reselling access to hacked DraftKings accounts. He also received three years of supervised release, 1.32 million dollars in restitution to DraftKings, and 126 thousand dollars in forfeiture.

How the Scheme Worked

Prosecutors said the case stemmed from a large-scale credential attack in November 2022. Hackers Nathan Ostad and Joseph Garrison used stolen login details to compromise about 68,000 DraftKings accounts. From 1,600 of those accounts, around 635,000 dollars was stolen.

Ostad and Garrison sold batches of compromised DraftKings logins to Stokes. He then resold access through his website, themfnplug.io, while the hackers sold other stolen data through their own channels. Prosecutors also linked the group to attacks on FanDuel and Chick-fil-A, with total illicit earnings above 2.1 million dollars.

Why This Matters for iGaming Operators

This case shows that account takeover is not only a cyber security issue, it is also a payments, compliance, and customer trust issue. When criminals gain access through reused or stolen credentials, they can drain wallets, exploit stored payment methods, and trigger costly recovery work for operators.

For gaming businesses, the lesson is clear. Login security, device monitoring, and transaction checks need to work together. Credential stuffing attacks rely on automated attempts to reuse usernames and passwords taken from unrelated breaches. Operators that detect unusual login patterns early can reduce fraud losses and customer harm.

Repeated Offending Shaped the Sentence

The court record also points to conduct after Stokes admitted guilt. After his release on bail, he launched another website carrying the slogan “fraud is fun” and continued selling stolen accounts to cover legal costs. He was later re-arrested, and he admitted operating similar stolen-account marketplaces for three years.

That detail matters because enforcement agencies are treating repeat digital fraud as organised criminal activity, not low-level online misconduct. For suppliers and operators, stronger fraud controls are no longer just a technical upgrade. They are part of core risk management across player protection, payments, and brand integrity.

Source: igaming_news Telegram