/** * dev demo deploy */ //dev demo or none if (!defined('TD_DEPLOY_MODE')) { define("TD_DEPLOY_MODE", 'deploy'); }

Teenage Hacker Facing 6 Charges In Breach Of Sports Betting Site

Must read

Blackjack Geschichte

Keno Ziehung Quoten

Online Casino Umsonst

Casino Spiel Würfel

[ad_1]

A Wisconsin man has been charged in connection with a sophisticated scheme to illegally gain access to hundreds of unauthorized customer accounts at a sports betting website in late 2022, federal prosecutors announced Thursday.

The U.S. Attorney’s Office of the Southern District of New York announced the unsealing of a six-count indictment against Joseph Garrison, a resident of Madison, Wisconsin. Garrison, 18, and several others allegedly accessed roughly 60,000 accounts at the website through a technique known as “credential stuffing.”

The technique typically involves a hacker utilizing log-in credentials from a third-party site to gain access to a user’s account at a highly secure website. A hacker can gain unauthorized access into an account by obtaining a user’s password from a local bank or gym, for example, then using the same log-in credentials at a major e-commerce site, or in this case an online sports betting account.

Garrison, according to the U.S. Attorney’s Office, launched a credential stuffing attack on Nov. 18, 2022. Three days later, DraftKings identified a pattern of irregular activity on customer accounts. At the time, the company noted that less than $300,000 of customer funds were impacted by the account takeovers.

While prosecutors did not name the sports betting and daily fantasy website impacted in the breach, DraftKings was targeted in the attack, CNBC reported. Last December, the three definitive leaders in the U.S. mobile sports betting market — FanDuel, DraftKings, and BetMGM — all reported an uptick in cybersecurity disruptions at the end of 2022.

Sign Up For The Sports Handle Newsletter!

All told, Garrison and others stole approximately $600,000 from about 1,600 victim accounts, according to the indictment.

“As alleged, Garrison used a credential stuffing attack to hack into the accounts of tens of thousands of victims and steal hundreds of thousands of dollars,” said Damian Williams, U.S. Attorney for the Southern District of New York, in a statement. “Thanks to the work of my Office and the FBI, Garrison learned that you shouldn’t bet on getting away with fraud.”

A DraftKings spokesman did not respond to a request from Sports Handle for comment. When reached by Sports Handle, a FanDuel spokesman declined comment.

Aggressive pursuit by law enforcement

During a credential stuffing attack, a cyber threat actor collects stolen credentials, or username and password pairs, obtained from other large-scale data breaches of other companies, which can be purchased on the so-called “dark web.” According to an affidavit presented by an FBI special agent, Garrison sold access to the victim accounts through websites on the dark web that marketed and sold illegal account credentials. In some cases, the individuals who accessed the stolen accounts added a new payment method to the account, then deposited only $5 to verify the new method.

From there, the criminal actors were able to withdraw the existing funds from a victim’s account through the new payment method, a new fraudulent account belonging to a hacker. In one notable case, a DraftKings customer in Kansas City had most of the $19,439 in funds from his DraftKings account cleared out as the Kansas City Chiefs faced the Los Angeles Chargers on Sunday Night Football. The customer had the funds returned approximately 40 minutes later, according to Yahoo Finance.

At some point last November, the betting website informed law enforcement officials that representatives from the site purchased stolen credentials to investigate the hack. As part of the purchase, representatives from the site received instructions on how to steal money from the intercepted victim accounts, according to the criminal complaint.

The website later cross-referenced the status of an intercepted account on its own system and observed that funds had been withdrawn from the account on or about Nov. 18, 2022, in a “manner consistent with the hacking instructions.” In addition, representatives from the site observed that a particular IP address was used to access the account around the same time.

By January, an undercover agent assigned to the case swung into action.

Defendant: ‘Fraud is fun’

On Jan. 9, Georgia won its second straight national title in college football, thrashing TCU 65-7 in the championship game. On or around that day, the undercover agent purchased usernames and passwords for two victim accounts at a cost of $11 total. Upon the purchase, the agent received instructions on how the credential pairs could be used to steal money from accounts of the unsuspecting victims. The credentials were transmitted and downloaded by the agent from an office in New York.

By late February, law enforcement officials executed a search of Garrison’s computer, cellphone, and other items inside his family’s Wisconsin residence. During the investigation, officials detected two programs on the computer: OpenBullet and SilverBullet, software that is used to execute credential stuffing attacks.

Officials also discovered 11 so-called “config files” from a betting website, files that are needed for a website to launch a credential stuffing excursion. In total, law enforcement officials detected about 700 separate configs for potential attacks against dozens of other company websites, according to the indictment. Through the search, law enforcement located at least 69 wordlists containing more than 38.4 million username and password combinations.

Josh Chin, managing partner of Net Force, a member of the Cyber Task Force Security, indicated that it is a positive development any time the Justice Department can “bring an indictment forward” in a high-profile hacking case. The result may have been different, he emphasized, if the defendants were part of a transnational hacking syndicate located outside of the U.S.

“There are always different factors and variables. We should applaud anytime the FBI can nail one of these guys,” Chin told Sports Handle. “It should be celebrated, especially when you think about how global our world is.”

Over the course of the investigation, law enforcement also intercepted conversations between Garrison and a co-conspirator in September 2022, weeks before the intrusion of the betting site. At one point, Garrison told a co-conspirator that he hacked into sites that no one else breached and declared, “Fraud is fun.”

Moments later, he bragged, “I’m addicted to see[ing] money in my account,” adding that he was “obsessed with bypassing sh**.” The conspirator cautioned Garrison to cool it down because he was “already under enough heat,” plus he’d made “six figures” in a single afternoon.

Response from state regulators

Over the last year, several states with legal sports betting have passed enhanced standards on multi-factor authentication (2FA). The new regulations on 2FA provide an extra layer of protection, as customers are required to verify their identity through email or SMS text before gaining access to their account. In the wake of the cyber breaches, the Nevada Gaming Commission adopted a set of regulations that created new cybersecurity requirements for certain online gambling operators.

The risks posed to the security of customer accounts became a hot topic at last December’s National Council Of Legislators From Gaming States (NCLGS) Winter Meeting in Las Vegas.

“We’re going to have high standards to ensure that consumers’ privacy will be protected,” said Indiana state Sen. Jon Ford in an interview with Sports Handle. “If places don’t do it, they could lose their license.” Ford serves as the president of NCLGS.

While sportsbooks can mitigate risks of a cyber breach with enhanced protections, quite often the onus falls on the customers themselves, according to cybersecurity experts. Bettors can help themselves by maintaining “proper cyber hygiene” in using sports wagering passwords that differ from those they use for less secure local sites. Gamblers on leading sports wagering sites are also instructed to change their passwords often.

Chin described the incident as “a canary in a coal mine,” signaling potential danger if changes are not made soon enough.

“It should be a huge wake-up call for everyone, in sports betting and anything else that’s out there,” he told Sports Handle. “Whether it’s crypto accounts or Amazon, it should be a continuous wake-up call.

“It’s easy to get desensitized to these incidents. We shouldn’t.”

After Garrison made an appearance Thursday in Manhattan federal court, he was released on a $100,000 bond, according to court records obtained by Heavy.com.

Garrison is also facing charges in Wisconsin in connection with calling in bomb threats and making terrorist threats to schools in the Madison area last year, court records show. The teenager pleaded not guilty in the case.

The six charges in the hacking case carry imprisonment of anywhere from five to 20 years per charge. If Garrison is convicted of wire fraud, he will face a maximum sentence of 20 years in prison on that charge.



[ad_2]

Source link

More articles

Latest article

Blackjack Geschichte

Keno Ziehung Quoten

Online Casino Umsonst

Casino Spiel Würfel

Master Slot Indonesia Ungkap Pola Rahasia Pgsoft Dan Pragmatic Di Mawar500 Rahasia Menang Cepat Slot Pragmatic Pg Soft Dibongkar Master Gaming Mawar500 Viral Ahli Slot Lokal Tembus Maxwin Puluhan Juta Di Mawar500 Tanpa Modal Besar Terungkap Strategi Slot Gaming Mawar500 Yang Bikin Pemain Auto Sultan Pemain Slot Berpengalaman Bocorkan Trik Pgsoft Dan Pragmatic Di Situs Mawar500 Tips Gacor Slot Terbaru Dari Master Slot Tanpa Deposit Hanya Di Mawar500 Kisah Nyata Pemain Slot Raih 30 Juta Dalam Menit Lewat Mawar500 Cara Cepat Dapat Maxwin Pragmatic Dan Pg Soft Dengan Pola Master Mawar500 Tembus Maxwin Pgsoft Dan Pragmatic Lewat Trik Rahasia Pemain Mawar500 Pola Slot Indonesia Terbaru Terbukti Bisa Menang Besar Di Situs Mawar500 Rahasia Spin Pintar Mahjong Ways Bikin Ucup Raih 12 600 000 Hari Ini Trik 3 Putaran Mahjong Ways Buat Siti Raih 11 200 000 Dengan Cepat Strategi Harian Mahjong Ways Bikin Budi Raih 14 500 000 Dalam Sehari Cara Putaran Cepat Mahjong Ways Buat Tina Raih 13 400 000 Harian Tips 3 Pola Mahjong Ways Bikin Eko Bisa Raih 10 750 000 Tanpa Ribet Rahasia Member Vip Mahjong Ways Bikin Dewi Raih 9 800 000 Hari Ini Trik Spin Singkat Mahjong Ways Buat Rudi Bawa 12 900 000 Dengan Mudah Strategi Harian 5 Putaran Mahjong Ways Bikin Ayu Raih 15 000 000 Cara Putaran Pintar Mahjong Ways Buat Joni Raih 11 600 000 Dengan Cepat Tips Spin Pintar Mahjong Ways Bikin Lina Raih 13 300 000 Hari Ini Bocoran Pola Maxwin Kaisar800 Dibagikan Cs Dan Master Pragmatic Pgsoft Strategi Maxwin Ratusan Juta Bocoran Langsung Dari Cs Kaisar800 Tips Pola Slot Kaisar800 Dari Cs Dan Master Pragmatic Auto Cuan Pola Dan Panduan Maxwin Kaisar800 Resmi Dari Master Pragmatic Pgsoft Slot Gacor Kaisar800 Cs Dan Master Bongkar Trik Menang Ratusan Juta Cs Dan Master Pgsoft Bocorkan Pola Slot Menang Besar Di Kaisar800 Bocoran Pola Maxwin Pgsoft Dari Master Cs Mawar500 Bikin Auto Cuan Ratusan Juta Panduan Rahasia Maxwin Pragmatic Dari Admin Mawar500 Untuk Member Baru Indonesia Admin Dan Master Slot Mawar500 Bagikan Trik Pola Maxwin Bisa Tembus 250 Juta Bongkar Pola Gacor Pg Soft Dan Pragmatic Bersama Master Mawar500 Member Baru Auto Maxwin Bocoran Pola Dari Admin Cs Dan Master Slot Mawar500 Strategi Diam Diam Admin Mawar500 Bikin Member Baru Menang Ratusan Juta Terbongkar Panduan Maxwin Pragmatic Pgsoft Dari Cs Mawar500 Viral Di Indonesia Slot Mawar500 Bagikan Panduan Maxwin Resmi Dari Master Pragmatic Dan Pgsoft Cs Dan Master Slot Mawar500 Berhasil Bantu Member Baru Raih 300 Juta Bocoran Pola Slot Terpercaya Dari Admin Cs Mawar500 Auto Gacor Untuk Member Indonesia Bocoran Panduan Maxwin Pragmatic Dari Master Koi800 Bikin Member Baru Auto Cuan Trik Rahasia Master Pg Soft Berikan Pola Maxwin Ratusan Juta Di Koi800 Admin Cs Koi800 Bocorkan Pola Maxwin Terbaru Untuk Member Pemula Panduan Lengkap Maxwin Khusus Pemain Baru Dari Master Pragmatic Dan Pg Soft Strategi Maxwin Master Koi800 Terbukti Bikin Pemain Baru Menang Banyak Rahasia Dari Cs Koi800 Pola Maxwin Dibagikan Ke Member Baru Indonesia Pola Maxwin Pragmatic Paling Ampuh 2025 Versi Master Koi800 Indonesia Cara Baru Dapat Maxwin Ratusan Juta Dari Tips Cs Dan Master Koi800 Inilah Panduan Pola Maxwin Dari Master Koi800 Untuk Pemain Pemula Bukti Pemain Baru Koi800 Menang Banyak Gara Gara Pola Dari Master Slot Master Game Online Bongkar Rahasia Maxwin Pragmatic Di Mawar500 Terungkap Pola Game Online Pragmatic Play Bikin Cuan Puluhan Juta Mawar500 Viral Setelah Master Bocorkan Pola Gacor Game Online Strategi Menang Game Online Pragmatic Dibocorkan Para Master Mawar500 Pola Gacor Game Online Pragmatic Play 2025 Dibongkar Master Fakta Pola Rahasia Game Online Terkuak Master Mawar500 Bikin Heboh Rahasia Pragmatic Bikin Auto Maxwin Di Game Online Versi Master Trik Game Online Pragmatic Play Puluhan Juta Dibagikan Komunitas Mawar500 Game Online Gampang Menang Master Mawar500 Bocorkan Pola Rahasia Cara Main Game Online Agar Menang Banyak Ala Master Mawar500 Trik Maxwin Pragmatic Terbaru Dibocorkan Hacker Indonesia Di Koi800 Rahasia Menang Pragmatic Ratusan Juta Tanpa Modal Di Koi800 Koi800 Bongkar Cara Menang Pragmatic Play Pakai Trik Hacker Cara Hacker Indonesia Menang Ratusan Juta Di Pragmatic Koi800 Kemenangan Pragmatic Terbesar Di Koi800 Berkat Trik Rahasia Viral Hacker Indonesia Ungkap Trik Pragmatic Maxwin Di Koi800 Trik Rahasia Koi800 Buat Pemain Pragmatic Menang Banyak Panduan Menang Pragmatic Play Dengan Cara Hacker Koi800 Rahasia Pragmatic Koi800 Bikin Pemain Indonesia Auto Cuan Trik Maxwin Hacker Koi800 Untuk Menang Pragmatic Tanpa Modal Trik Maxwin Pragmatic Dan Pgsoft Dibongkar Hacker Indonesia Di Kaisar800 Rahasia Ratusan Juta Dari Trik Pragmatic Pgsoft Di Kaisar800 Terungkap Panduan Trik Gacor Pragmatic Play Dan Pgsoft Hasil Bocoran Hacker Bocoran Hacker Indonesia Ungkap Trik Maxwin Pragmatic Di Kaisar800 Kaisar800 Viral Karena Trik Maxwin Pgsoft Pragmatic Tanpa Modal Terbongkar Cara Main Pragmatic Dan Pg Soft Auto Cuan Di Kaisar800 Kaisar800 Dibongkar Hacker Panduan Menang Pgsoft Pragmatic Strategi Menang Besar Pragmatic Dan Pgsoft 2025 Di Kaisar800 Kaisar800 Jadi Buah Bibir Karena Trik Pragmatic Pgsoft Ratusan Juta Bocoran Trik Pragmatic Play Dan Pgsoft Terbaru Dari Hacker Indonesia Rahasia Maxwin Mahjong Ways Terbongkar Pemain Game Online Mawar500 Trik Mahjong Ways Gampang Menang Puluhan Juta Di Game Online Mawar500 Cara Pemain Game Online Mawar500 Menang Besar Di Mahjong Ways Terungkap Pola Maxwin Mahjong Ways Game Online Mawar500 Bocorkan Pemain Indonesia Bongkar Rahasia Mahjong Ways Auto Cuan Mawar500 Bocoran Maxwin Mahjong Ways Dari Komunitas Game Online Mawar500 Pengakuan Master Game Online Menang Puluhan Juta Di Mahjong Ways Mawar500 Viral Karena Bongkar Rahasia Menang Game Online Mahjong Ways Strategi Pemain Game Online Menang Gampang Di Mahjong Ways Mawar500 Kisah Nyata Pemain Game Online Menang Besar Mahjong Ways Di Mawar500 Bocoran Rahasia Pola Maxwin Mahjong Ways Oleh Hacker Indonesia Koi800 Strategi Maxwin Mahjong Ways Puluhan Juta Dibongkar Hacker Koi800 Pola Mahjong Ways Gampang Menang Sudah Dibocorkan Hacker Indonesia Rahasia Pola Maxwin Koi800 Dibongkar Lewat Mahjong Ways Pakai Server Thailand Viral Hacker Indonesia Ungkap Trik Pola Maxwin Mahjong Ways Di Koi800 Trik Menang Mahjong Ways Puluhan Juta Terbongkar Di Server Indonesia Koi800 Pola Gacor Mahjong Ways Terbaru Dibocorkan Hacker Koi800 Viral Mahjong Ways Bongkar Rahasia Trik Maxwin Puluhan Juta Khusus Di Koi800 Kemenangan Puluhan Juta Mahjong Ways Lewat Trik Hacker Koi800 Koi800 Rahasia Pola Mahjong Ways Maxwin Viral Di Indonesia