Remember our post from November using Multi-Factor Authentication (MFA) is a bad bet which covered the credential stuffing attack launched against DraftKings? It turns out both the FBI and Joseph Garrison remember the incident. The Department of Justice just charged Garrison with compromising 1,600 accounts and stealing $800,000.
When the FBI searched his residence, they found computers loaded with credential stuffing tools OpenBullet and SilverBullet. They also discovered lists of over 38 million usernames and passwords he'd been feeding into the tools to see if anyone was guilty of password reuse.
While going through his phone, the FBI found additional evidence implicating Garrison, including these:
Here's the liquidating the accounts once compromised:
Takeaways:
Source: Department of Justice