shutterstock_490960141-1

Industry News: ESG5

      Know Your Breach: DraftKings

      Nov 25, 2022 9:31:14 AM

      The Target: DraftKings, a U.S based sports betting website.

      The Take: $300,000 USD of customer funds.

      The Vector: Via a credential stuffing attack, where user passwords that have been exposed elsewhere were also used as a login for DraftKings, enabled attackers to login and steal the funds.

      This breach is a stark reminder of how critical authentication controls are in an overall robust cybersecurity posture. Credential stuffing attacks can be avoided by enforcing multi-factor authentication and reasonably paced password resets. It is important to employ effective strategies to mitigate these kinds of breaches to protect a firm’s customer base.

      Read more...

      Topics:Know Your Breach

      About Castle Hall Diligence

      Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

      Subscribe to Cyber Updates