1
Published signals
currently linked to this company
Company intelligence
draftkings.com
This company page brings together public reporting currently associated with Draftkings. It reflects signals published by Shadow Tier and should not be read as a complete incident history.
Company links
1
currently linked to this company
0
recent published signals
0
recent published signals
0
confidence classifications
July 22, 2026
most recent published signal
Explore related intelligence
Based on all published signals currently linked to Draftkings. Affected countries come from victim data; the company country above remains a separate profile fact. Counts describe this reporting set, not overall incident prevalence.
Company signals
Weekly Cybersecurity Intelligence Report Cyber Threats & Breaches 7 Oct – 13 Oct 2025 This week witnessed four significant cybersecurity incidents affecting major organizations across multiple sectors. The period from October 7-13, 2025, was marked by sophisticated attack campaigns targeting authentication systems, zero-day vulnerabilities, and supply chain compromises. DraftKings Credential Stuffing Attack (September 2, 2025): Targeted under 30 customer accounts through automated credential reuse Kido International Nursery Ransomware (September 25, 2025): Compromised sensitive data of over 8,000 children and families Discord Third-Party Data Breach (September 20, 2025): Exposed government IDs and support data for 70,000 users Harvard University Oracle Zero-Day Exploit (August 9, 2025): Leveraged CVE-2025-61882 for data exfiltration All incidents demonstrate evolving threat landscapes targeting authentication weaknesses, supply chain vulnerabilities, and zero-day exploits in enterprise systems. >> Outpace Attackers With AI-Based Automated Penetration Testing 1. DraftKings Credential Stuffing Account Breach DraftKings, the Boston-based sports betting platform, experienced a credential stuffing attack affecting fewer than 30 customer accounts. Attackers utilized automated tools to test stolen username-password combinations from external data breaches against DraftKings authentication systems. The attack leveraged MITRE ATT&CK technique T1110 (Brute Force) under the Initial Access tactic. Threat actors deployed automated scripts conducting rapid sequential login attempts across multiple accounts using credential pairs likely obtained from underground forums or previous data breaches. The attack pattern showed: High-volume login attempts from suspicious IP addresses Anomalous user agent strings in authentication logs Sequential failed authentication events (Windows Event ID 4625) followed by successful logins (Event ID 4624) No evidence of malware deployment or lateral movement within DraftKings infrastructure Compromised customer data included names, addresses, dates of birth, phone numbers, email addresses, last four digits of payment cards, profile photos, transaction history, account balances, and password modification timestamps. No government-issued identification numbers or complete financial account details were accessed. Suspicious IP ranges conducting multiple authentication attempts Elevated failed login event volumes preceding successful access Account lockout patterns followed by credential validation No evidence of malicious file execution or registry modifications Mandatory password resets for affected accounts Multi-factor authentication enforcement for DK Horse accounts Enhanced fraud detection algorithms implementation Additional technical measures to prevent similar credential-based attacks 13th October – Threat Intelligence Report For the latest discoveries in cyber research for the week of 13th October, please download our Threat Intelligence Bulletin . Qilin ransomware group has claimed responsibility for targeting Asahi, Japan’s largest brewing company, that had been hacked on September 29 th . The attack resulted in the exfiltration of over 9,300 files totaling 27GB of sensitive data, including financial documents, employee IDs, contracts, and internal reports. The attack disrupted operations at six breweries, impacting the production of thirty labels and potentially causing hundreds of millions in losses. Check Point Threat Emulation provides protection against this threat (Ransomware.Wins.Qilin) Sugar Land city in Texas has been a victim of a cyber-attack that resulted in outages to several online municipal services, including bill pay, permit payments, and utility billing systems, but did not affect critical infrastructure or emergency services. The incident impacted the digital access of nearly 110,000 residents, exposing service interruptions but with no disclosed evidence of data theft. American law firm Williams & Connolly has confirmed a cyber attack that resulted in unauthorized access to email accounts belonging to a small number of attorneys. The firm reported no evidence that confidential client data was stolen from central databases, and the scope of the compromised information appears limited to email accounts. The attack has been attributed to suspected China affiliated threat actors. Crimson Collective threat group, who claimed the Red Hat intrusion last week, is now targeting AWS environments for data theft and extortion. The group harvests exposed AWS credentials, creates new IAM users and access keys, assigns AdministratorAccess for privilege escalation and enumerates cloud assets. Afterwards, the group resets RDS master passwords and snapshots EBS volumes to spin up EC2 instances under permissive security groups, then delivers extortion notes through SES from within AWS victim accounts. Post-disclosure, Crimson Collective partnered with “Scattered Lapsus$ Hunters” to amplify pressure and has reused IPs across incidents, aiding cross-case correlation. Electronic components maker Avnet has suffered a data breach that resulted in unauthorized access to an externally hosted EMEA internal-sales database. A threat actor has claimed responsibility for stealing 1.3TB of compressed data and demanding ransom, but most data is reportedly unreadable without proprietary tools, and the total number of affected individuals remains unknown. American gambling company DraftKings has experienced a data breach that resulted in unauthorized access to customer accounts through credential stuffing attacks, exposing personal information such as names, phone numbers, email addresses, last four digits of payment cards and more. The breach has reportedly impacted fewer than 30 customers, and no sensitive data was accessed. A new large-scale botnet campaign, RondoDox, is actively exploiting 56 vulnerabilities – including RCE and command injection CVEs like CVE-2023-1389, CVE-2024-3721, and CVE-2024-12856 – across 30+ device types (DVRs, NVRs, CCTV, web servers). Active since June, it exploits new and legacy bugs (including unpatched EOL devices), weaponizes Pwn2Own code, and uses an “exploit shotgun” to maximize infections and seize device/network control. Check Point IPS provides protection against this threat (TP-Link Archer AX21 Command Injection (CVE-2023-1389); TBK DVR Devices Command Injection (CVE-2024-3721); Four-Faith F3x Series Command Injection (CVE-2024-12856)) Oracle E-Business Suite zero-day CVE-2025-61882 enables unauthenticated RCE via the BI Publisher Integration component with a single low-complexity HTTP request, allowing data theft from internet-exposed EBS apps. The flaw is actively leveraged by Cl0p and other threat actors for extortion. Check Point IPS provides protection against this threat (Oracle Concurrent Processing Remote Code Execution (CVE-2025-61882)) Redis has patched CVE-2025-49844, a critical use-after-free RCE in the default-enabled Lua engine affecting all versions. Authenticated exploits enable sandbox escape and full host compromise (reverse shells, credential theft, lateral movement, malware); at least 60k of ~330k Internet-exposed Redis servers lack auth, and the flaw is already being abused by botnets and ransomware. Check Point IPS provides protection against this threat (Redis Use After Free (CVE-2025-49844)) StealthLoader Malware Leveraging Log4Shell
FAQ
It combines a reviewed organization profile with all current published Shadow Tier signals explicitly linked to Draftkings.
No. A signal must contain a reliable company connection and meet the publication criteria; incidental or ambiguous mentions are excluded.
The page follows current published reporting. Counts change as new evidence is added, classifications are reviewed, or older signals leave the reporting window.