Snoopy case: the credentials fraud that left 60,000 hacked accounts and the lesson not to reuse passwords

Author: Published 4 min de lectura 167 reading

The images in this article were generated with artificial intelligence. How we publish

The case known publicly by the alias "Snoopy" has a double lesson: on the one hand, the criminal consequence for those who monetize accounts; on the other, the technical and human persistence of a vector that continues to be exploited on a large scale: the credental stuffin. According to the Public Prosecutor's Office, Nathan Austad, 21, pleaded guilty and was sentenced to 18 months in prison after admitting that his group committed around 60,000 accounts from DraftKings users in the November 2022 attack, with 1,600 accounts manipulated to add payment methods and an effective loot close to the $60,000.

Beyond the figures, there are two realities that should be emphasized: the first is that these incidents are rarely isolated and feed on parallel markets where access to stolen accounts is bought and sold. The Office of the Prosecutor mentions that Austad managed its own "shop" to market access to accounts, and that its cryptomoneda coins received approximately $465,000. The second reality is that the companies concerned, although initially reporting minor losses, ended up recognizing a greater impact on the volume of accounts committed; this highlights the difference between the immediate visible impact and the total damage when the data and accesses are redistributed on the web dark.

Snoopy case: the credentials fraud that left 60,000 hacked accounts and the lesson not to reuse passwords
Image generated with IA.

For users the lesson is direct: do not reuse passwords and activate additional authentication factors. The vector used was not a sophisticated software vulnerability, but the massive exploitation of repeated or weak credentials. Public tools like Have I Been Pwned allow to check if a mail or password appears in leaks; consult and rotate credentials is a digital hygiene measure that drastically reduces the risk.

For companies that manage accounts with balance or payment instruments, the case is a reminder that the defenses must be multifaceted: detection of bots, limits and alerts in changes of payment methods, enhanced verification of fund withdrawal and monitoring of abnormal patterns. The widespread adoption of MFA and the continuous review of anti-automation mechanisms are good practices supported by agencies such as CISA; more information on multi-factor authentication and its implementation is available on the CISA website at CISA: Multi-Factor Authentication.

Snoopy case: the credentials fraud that left 60,000 hacked accounts and the lesson not to reuse passwords
Image generated with IA.

In the regulatory and enforcement field, judgments like this show that authorities can and will pursue both operators and vendors of stolen access. However, technical prevention and reduction of "success attack" require continuous investments in attack simulation and screening tests so that security teams do not depend only on static indicators. The practice of break and attack simulation helps identify IMS / EDR rules that fail to detect side movements or credentials abuse, and is a tool that management should assess as part of the security budget.

For users who are victims of a similar incident, it is appropriate to act quickly: change passwords, review and revoke additional payment methods without authorization, file complaints to the service provider and the bank, monitor extracts and consider alerts of fraud or card freezing. If you used activity-related cryptomonedas, document transactions and consult legal advice: forfeiture and restitution that accompany these convictions are part of the process, such as the obligation of Austad to pay hundreds of thousands in restitution and confiscation.

The Snoopy episode is not just a story of punishment: it is a practical reminder that security is a shared responsibility between suppliers and users. While judges prosecute the attackers, organizations must tighten controls and educate their clients; users must apply the basic defences and actively monitor their accounts. To read the statement of the Office of the Prosecutor detailing the sentence and the charges, see the note by the Department of Justice at doj.gov which summarizes the investigation and the sanctions imposed.

Coverage

Related

More news on the same subject.