/** * dev demo deploy */ //dev demo or none if (!defined('TD_DEPLOY_MODE')) { define("TD_DEPLOY_MODE", 'deploy'); }

Teenage Hacker Facing 6 Charges In Breach Of Sports Betting Site

Must read

Blackjack Geschichte

Keno Ziehung Quoten

Online Casino Umsonst

Casino Spiel Würfel

[ad_1]

A Wisconsin man has been charged in connection with a sophisticated scheme to illegally gain access to hundreds of unauthorized customer accounts at a sports betting website in late 2022, federal prosecutors announced Thursday.

The U.S. Attorney’s Office of the Southern District of New York announced the unsealing of a six-count indictment against Joseph Garrison, a resident of Madison, Wisconsin. Garrison, 18, and several others allegedly accessed roughly 60,000 accounts at the website through a technique known as “credential stuffing.”

The technique typically involves a hacker utilizing log-in credentials from a third-party site to gain access to a user’s account at a highly secure website. A hacker can gain unauthorized access into an account by obtaining a user’s password from a local bank or gym, for example, then using the same log-in credentials at a major e-commerce site, or in this case an online sports betting account.

Garrison, according to the U.S. Attorney’s Office, launched a credential stuffing attack on Nov. 18, 2022. Three days later, DraftKings identified a pattern of irregular activity on customer accounts. At the time, the company noted that less than $300,000 of customer funds were impacted by the account takeovers.

While prosecutors did not name the sports betting and daily fantasy website impacted in the breach, DraftKings was targeted in the attack, CNBC reported. Last December, the three definitive leaders in the U.S. mobile sports betting market — FanDuel, DraftKings, and BetMGM — all reported an uptick in cybersecurity disruptions at the end of 2022.

Sign Up For The Sports Handle Newsletter!

All told, Garrison and others stole approximately $600,000 from about 1,600 victim accounts, according to the indictment.

“As alleged, Garrison used a credential stuffing attack to hack into the accounts of tens of thousands of victims and steal hundreds of thousands of dollars,” said Damian Williams, U.S. Attorney for the Southern District of New York, in a statement. “Thanks to the work of my Office and the FBI, Garrison learned that you shouldn’t bet on getting away with fraud.”

A DraftKings spokesman did not respond to a request from Sports Handle for comment. When reached by Sports Handle, a FanDuel spokesman declined comment.

Aggressive pursuit by law enforcement

During a credential stuffing attack, a cyber threat actor collects stolen credentials, or username and password pairs, obtained from other large-scale data breaches of other companies, which can be purchased on the so-called “dark web.” According to an affidavit presented by an FBI special agent, Garrison sold access to the victim accounts through websites on the dark web that marketed and sold illegal account credentials. In some cases, the individuals who accessed the stolen accounts added a new payment method to the account, then deposited only $5 to verify the new method.

From there, the criminal actors were able to withdraw the existing funds from a victim’s account through the new payment method, a new fraudulent account belonging to a hacker. In one notable case, a DraftKings customer in Kansas City had most of the $19,439 in funds from his DraftKings account cleared out as the Kansas City Chiefs faced the Los Angeles Chargers on Sunday Night Football. The customer had the funds returned approximately 40 minutes later, according to Yahoo Finance.

At some point last November, the betting website informed law enforcement officials that representatives from the site purchased stolen credentials to investigate the hack. As part of the purchase, representatives from the site received instructions on how to steal money from the intercepted victim accounts, according to the criminal complaint.

The website later cross-referenced the status of an intercepted account on its own system and observed that funds had been withdrawn from the account on or about Nov. 18, 2022, in a “manner consistent with the hacking instructions.” In addition, representatives from the site observed that a particular IP address was used to access the account around the same time.

By January, an undercover agent assigned to the case swung into action.

Defendant: ‘Fraud is fun’

On Jan. 9, Georgia won its second straight national title in college football, thrashing TCU 65-7 in the championship game. On or around that day, the undercover agent purchased usernames and passwords for two victim accounts at a cost of $11 total. Upon the purchase, the agent received instructions on how the credential pairs could be used to steal money from accounts of the unsuspecting victims. The credentials were transmitted and downloaded by the agent from an office in New York.

By late February, law enforcement officials executed a search of Garrison’s computer, cellphone, and other items inside his family’s Wisconsin residence. During the investigation, officials detected two programs on the computer: OpenBullet and SilverBullet, software that is used to execute credential stuffing attacks.

Officials also discovered 11 so-called “config files” from a betting website, files that are needed for a website to launch a credential stuffing excursion. In total, law enforcement officials detected about 700 separate configs for potential attacks against dozens of other company websites, according to the indictment. Through the search, law enforcement located at least 69 wordlists containing more than 38.4 million username and password combinations.

Josh Chin, managing partner of Net Force, a member of the Cyber Task Force Security, indicated that it is a positive development any time the Justice Department can “bring an indictment forward” in a high-profile hacking case. The result may have been different, he emphasized, if the defendants were part of a transnational hacking syndicate located outside of the U.S.

“There are always different factors and variables. We should applaud anytime the FBI can nail one of these guys,” Chin told Sports Handle. “It should be celebrated, especially when you think about how global our world is.”

Over the course of the investigation, law enforcement also intercepted conversations between Garrison and a co-conspirator in September 2022, weeks before the intrusion of the betting site. At one point, Garrison told a co-conspirator that he hacked into sites that no one else breached and declared, “Fraud is fun.”

Moments later, he bragged, “I’m addicted to see[ing] money in my account,” adding that he was “obsessed with bypassing sh**.” The conspirator cautioned Garrison to cool it down because he was “already under enough heat,” plus he’d made “six figures” in a single afternoon.

Response from state regulators

Over the last year, several states with legal sports betting have passed enhanced standards on multi-factor authentication (2FA). The new regulations on 2FA provide an extra layer of protection, as customers are required to verify their identity through email or SMS text before gaining access to their account. In the wake of the cyber breaches, the Nevada Gaming Commission adopted a set of regulations that created new cybersecurity requirements for certain online gambling operators.

The risks posed to the security of customer accounts became a hot topic at last December’s National Council Of Legislators From Gaming States (NCLGS) Winter Meeting in Las Vegas.

“We’re going to have high standards to ensure that consumers’ privacy will be protected,” said Indiana state Sen. Jon Ford in an interview with Sports Handle. “If places don’t do it, they could lose their license.” Ford serves as the president of NCLGS.

While sportsbooks can mitigate risks of a cyber breach with enhanced protections, quite often the onus falls on the customers themselves, according to cybersecurity experts. Bettors can help themselves by maintaining “proper cyber hygiene” in using sports wagering passwords that differ from those they use for less secure local sites. Gamblers on leading sports wagering sites are also instructed to change their passwords often.

Chin described the incident as “a canary in a coal mine,” signaling potential danger if changes are not made soon enough.

“It should be a huge wake-up call for everyone, in sports betting and anything else that’s out there,” he told Sports Handle. “Whether it’s crypto accounts or Amazon, it should be a continuous wake-up call.

“It’s easy to get desensitized to these incidents. We shouldn’t.”

After Garrison made an appearance Thursday in Manhattan federal court, he was released on a $100,000 bond, according to court records obtained by Heavy.com.

Garrison is also facing charges in Wisconsin in connection with calling in bomb threats and making terrorist threats to schools in the Madison area last year, court records show. The teenager pleaded not guilty in the case.

The six charges in the hacking case carry imprisonment of anywhere from five to 20 years per charge. If Garrison is convicted of wire fraud, he will face a maximum sentence of 20 years in prison on that charge.



[ad_2]

Source link

More articles

Latest article

Blackjack Geschichte

Keno Ziehung Quoten

Online Casino Umsonst

Casino Spiel Würfel

Admin Pusat Dan Koi800 Luncurkan Akun Pro Berlisensi Resmi Berhadiah Maxwin Puluhan Juta Breaking News Koi800 Umumkan Akun Pro Premium Berlisensi Resmi Dengan Hadiah Besar Admin Pusat Ungkap Inovasi Akun Pro Berlisensi Koi800 Dengan Peluang Maxwin Puluhan Juta Heboh Komunitas Game Koi800 Buka Akun Pro Berlisensi Terbaik Dengan Kuota Terbatas Resmi Dirilis Akun Pro Koi800 Terbuka Untuk Semua Pengguna Dengan Bonus Maxwin Koi800 Dan Admin Pusat Rilis Akun Pro Berlisensi Resmi Untuk Semua Member Aktif Inovasi Terbaru Koi800 Akun Pro Berlisensi Dengan Peluang Maxwin Lebih Tinggi Program Akun Pro Koi800 Jadi Perbincangan Hangat Berlisensi Dan Aman Untuk Member Admin Pusat Konfirmasi Rilis Akun Pro Koi800 Berlisensi Resmi Dengan Hadiah Maxwin Besar Terbukti Aman Koi800 Rilis Akun Pro Berlisensi Resmi Dengan Peluang Maxwin Untuk Member Setia Admin Pg Soft Rilis Akun Vip Terbaru Berlisensi Resmi Member Mawar500 Auto Cuan Pg Soft Umumkan Akun Vip Eksklusif Di Mawar500 Dijamin Auto Profit Setiap Hari Heboh Akun Vip Pg Soft Kini Bisa Diklaim Lewat Mawar500 Cuan Melimpah Admin Pg Soft Resmi Buka Akun Vip Baru Untuk Member Mawar500 Peluang Emas Auto Menang Rahasia Cuan Pg Soft Terungkap Akun Vip Mawar500 Dapat Lisensi Resmi Dari Admin Pusat Mawar500 Buka Pendaftaran Akun Vip Pg Soft Resmi Klaim Sekarang Sebelum Ditutup Rilis Terbaru Pg Soft Akun Vip Mawar500 Tawarkan Fitur Eksklusif Dan Bonus Auto Cuan Akun Vip Pg Soft Di Mawar500 Jadi Buruan Para Player Hadiah Besar Menanti Admin Pg Soft Kasih Kejutan Akun Vip Berlisensi Kini Resmi Tersedia Di Mawar500 Kabar Gembira Pg Soft Rilis Akun Vip Premium Lewat Mawar500 Cuan Besar Di Depan Mata Jihan Bikin Heboh Dapat Maxwin 45 Juta Di Mahjong Ways Lewat Akun Vip Resmi Dari Admin Pusat Mawar500 Viral Akun Baru Jihan Langsung Maxwin 45 Juta Di Mahjong Ways Lewat Situs Mawar500 Tanpa Sekali Pun Kalah Pengakuan Jihan Main Mahjong Ways Cuma 20 Menit Langsung Maxwin 45 Juta Dari Akun Vip Mawar500 Heboh Di Medsos Jihan Klaim Menang 45 Juta Di Mahjong Ways Dari Admin Resmi Mawar500 Tanpa Kekalahan Fakta Di Balik Kemenangan Jihan 45 Juta Di Mahjong Ways Akun Vip Dari Admin Pusat Mawar500 Jadi Sorotan Jihan Ungkap Rahasia Bisa Maxwin 45 Juta Di Mahjong Ways Hanya Dengan Akun Baru Dari Situs Mawar500 Tidak Ada Kekalahan Akun Vip Jihan Dari Mawar500 Berhasil Raup Maxwin 45 Juta Di Mahjong Ways Mengejutkan Jihan Dapat Maxwin 45 Juta Dari Mahjong Ways Hanya Lewat Akun Baru Resmi Admin Mawar500 Kisah Viral Jihan Main Mahjong Ways Sekali Langsung Maxwin 45 Juta Lewat Situs Resmi Mawar500 Admin Pusat Mawar500 Konfirmasi Akun Vip Jihan Raih Maxwin 45 Juta Di Mahjong Ways Tanpa Sekali Pun Kalah Cek Pola Maxwin Terbaru Di Koi800 Langsung Dari Admin Pusat Mahjong Ways Dan Gates Of Olympus Sebelum Terlambat Bocoran Pola Maxwin Koi800 Hari Ini Langsung Dari Admin Pusat Mahjong Ways Gates Of Olympus Update Resmi Pola Maxwin Terbaru Mahjong Ways Gates Of Olympus Versi Admin Koi800 Rahasia Pola Maxwin Asli Dari Admin Pusat Koi800 Di Mahjong Ways Dan Gates Of Olympus Jangan Lewatkan Pola Maxwin Terbaru Dari Admin Koi800 Untuk Mahjong Ways Gates Of Olympus Admin Pusat Koi800 Rilis Pola Maxwin Ampuh Di Mahjong Ways Gates Of Olympus Pola Maxwin Hari Ini Dari Admin Pusat Koi800 Terbukti Di Mahjong Ways Dan Gates Of Olympus Viral Pola Maxwin Koi800 Ini Bikin Pemain Mahjong Ways Gates Of Olympus Auto Menang Cek Sekarang Pola Maxwin Koi800 Yang Diumumkan Admin Mahjong Ways Gates Of Olympus Admin Koi800 Bocorkan Pola Maxwin Rahasia Mahjong Ways Gates Of Olympus Sebelum Ditutup Rahasia Trik Maxwin Puluhan Juta Dibongkar Mael Penjual Bakso Asal Aceh Di Mahjong Ways Bikin Heboh Viral Mael Penjual Bakso Dari Aceh Bongkar Pola Rahasia Mahjong Ways Pemain Kaisar800 Auto Maxwin Heboh Di Aceh Trik Mahjong Ways Mael Penjual Bakso Raup Puluhan Juta Di Kaisar800 Mael Penjual Bakso Aceh Bongkar Trik Mahjong Ways Yang Bikin Pemain Kaisar800 Panen Maxwin Trik Rahasia Mahjong Ways Dari Mael Penjual Bakso Aceh Pemain Kaisar800 Kaget Lihat Hasilnya Mahjong Ways Heboh Lagi Trik Mael Penjual Bakso Asal Aceh Bikin Pemain Kaisar800 Dapat Puluhan Juta Terbongkar Cara Mael Penjual Bakso Aceh Raih Maxwin Puluhan Juta Di Mahjong Ways Kaisar800 Dari Gerobak Bakso Ke Maxwin Puluhan Juta Kisah Viral Mael Dari Aceh Di Mahjong Ways Kaisar800 Pola Gacor Mahjong Ways Versi Mael Penjual Bakso Aceh Trik Ini Bikin Kaisar800 Ramai Dicoba Mael Penjual Bakso Dari Aceh Jadi Viral Usai Bongkar Pola Maxwin Mahjong Ways Di Kaisar800 Bocoran Pola Admin Master Pgsoft Rahasia Mahjong Ways Modal 100k Di Mawar500 Terbongkar Hari Ini Viral Pola Gacor Mahjong Ways Admin Pgsoft Member Baru Mawar500 Modal 100ribu Langsung Maxwin Bocoran Pgsoft Asli Pola Mahjong Ways Modal 100k Mawar500 Member Baru Menang Besar Admin Pgsoft Bocorkan Pola Mahjong Ways 2025 Modal 100k Di Mawar500 Bisa Raih Scatter Pola Mahjong Ways Terbaru Admin Pgsoft Member Baru Mawar500 Modal 100k Jadi Jutaan Exclusive Bocoran Rahasia Mahjong Ways Pgsoft Pemain Baru Mawar500 Modal 100k Langsung Profit Wajib Coba Pola Mahjong Ways Modal 100k Admin Master Pgsoft Khusus Member Baru Mawar500 Bocoran Terpanas Hari Ini Pola Pgsoft Mahjong Ways Modal 100k Mawar500 Auto Cuan Fakta Bocoran Pola Mahjong Ways Admin Pgsoft Modal 100k Mawar500 Langsung Pecah Scatter Bocoran Pgsoft Resmi Member Baru Mawar500 Pola Mahjong Ways Modal 100k Viral Di Tiktok Koi800 Bagikan Trik Mahjong Ways Dan Gates Of Olympus Untuk Member Baru Dijamin Maxwin Ratusan Juta Rahasia Trik Koi800 Mahjong Ways Gates Of Olympus Bikin Member Baru Auto Maxwin Tanpa Nunggu Lama Strategi Koi800 Bongkar Cara Main Mahjong Ways Gates Of Olympus Yang Bisa Bikin Maxwin Cepat Viral Koi800 Bagikan Tips Mahjong Ways Dan Gates Of Olympus Untuk Member Baru Auto Menang Cara Baru Dari Koi800 Agar Member Baru Mahjong Ways Dan Gates Of Olympus Tembus Maxwin Ratusan Juta Panduan Koi800 Trik Ampuh Mahjong Ways Gates Of Olympus Bikin Member Baru Sukses Menang Kabar Gembira Member Baru Koi800 Bisa Raih Maxwin Mahjong Ways Dan Gates Of Olympus Dengan Trik Ini Trik Koi800 Buat Member Baru Menang Cepat Di Mahjong Ways Gates Of Olympus Tanpa Nunggu Jackpot Koi800 Buka Rahasia Trik Main Mahjong Ways Gates Of Olympus Yang Lagi Trending Di Google Discover Tips Viral Koi800 Mahjong Ways Gates Of Olympus Bikin Member Baru Auto Maxwin Dalam Hitungan Menit