Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
DraftKings Inc.

DraftKings Inc. Vendor Cyber Rating & Cyber Score

draftkings.com

It's simple, we believe life is more fun when you're in on the action. For that reason, we’re committed to responsibly creating the world’s favorite games and betting experiences. At DraftKings, The Crown Is Yours. We are driven by the thrill of the future and the pull of possibility. As an original, continuous gamechanger, we’re shaping the present and future of sports entertainment and digital experiences, leading the way into new markets with new products, and providing the ultimate experience to our customers. Here, we believe in the power and impact that comes from innovation, collaboration, and a winning culture. We’re a strong and dedicated global team of 4,000+ teammates driven to achieve great things. From your very first


DraftKings Inc. A.I CyberSecurity Scoring

DraftKings Inc.
Company Information
Website:https://careers.draftkings.com/
Employees number:5,698
Number of followers:161,144
NAICS:511261
Industry Type:Mobile Gaming Apps
Homepage:draftkings.com
DraftKings Inc. Risk Score (AI oriented)
Between 700 and 749
logo
DraftKings Inc.Mobile Gaming Apps
Updated:
03/04/2026
730/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
DraftKings Inc. Global Score (TPRM)
xxxx
logo
DraftKings Inc.Mobile Gaming Apps
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

DraftKings Inc.
DraftKings Inc.Moderate
Current Score
730Ba (MODERATE)
01000
5 incidents
-59.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
649Before Incident
MAY 2026
642Before Incident
APRIL 2026
730Before Incident
MARCH 2026
729Before Incident
FEBRUARY 2026
731Before Incident
JANUARY 2026
727Before Incident
DECEMBER 2025
728Before Incident
NOVEMBER 2025
726Before Incident
Breach
28 Nov 2025DraftKings Inc.
23andMe Nets Approval for Bankruptcy Plan With Data Breach Deals

23andMe Data Breach and Bankruptcy Settlement

624After Incident
CRITICAL-102
23A1764346412
Fallen DNA testing firm 23andMe won court approval of a bankruptcy plan that includes settlements to provide up to $62 million to resolve thousands of data breach claims. Judge Brian C. Walsh of the US Bankruptcy Court for the Eastern District of Missouri approved the plan in a Wednesday order, overruling most creditor objections and challenges from data breach victims. Many of those former customers’ objections were deemed moot or premature, and several of them didn’t appear at a court hearing on the plan. Objections from the Justice Department’s bankruptcy watchdog and a coalition of state attorneys general were resolved ...
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Financial Loss: $62 million (settlement amount)
DATA BREACH
Type Of Data Compromised: Customer Data (likely including genetic and personally identifiable information)Sensitivity Of Data: High (genetic and personal data)
OCTOBER 2025
727Before Incident
SEPTEMBER 2025
741Before Incident
Cyber Attack
02 Sep 2025DraftKings Inc.
DraftKings

DraftKings Account Compromise via Credential Stuffing/Brute-Force Attack

724After Incident
CRITICAL-17
DRA4092140100825
DraftKings suffered a credential stuffing or brute-force attack on September 2, 2025, compromising customer accounts. While the company confirmed its systems were not directly breached, attackers used stolen credentials from external sources to access accounts. Exposed data included names, email addresses, phone numbers, dates of birth, last four digits of payment cards, profile photos, transaction histories, account balances, and password change dates—though DraftKings claimed no government-issued IDs, full financial details, or data enabling direct identity theft were accessed.The incident poses risks of financial fraud, targeted phishing, SIM-swap attacks, social engineering, and extortion, as the leaked information can be weaponized for follow-up attacks. DraftKings advised users to reset passwords, enable two-factor authentication (2FA), monitor credit reports, and consider security freezes. The attack highlights vulnerabilities in reused credentials and underscores the need for stronger authentication measures. No ransomware was involved, but the scale of exposed personal and financial fragments raises concerns over long-term misuse.
INCIDENT DETAILS -
TYPE
Account TakeoverData Breach
MOTIVATION
Financial FraudIdentity TheftAccount TakeoverPhishingExtortion
IMPACT
Operational Impact: Low (No direct system breach; customer account access only)Customer Complaints: Likely (urged to reset passwords and monitor accounts)Brand Reputation Impact: Moderate (public disclosure of account compromises)Identity Theft Risk: High (exposed PII enables phishing, SIM-swap, social engineering)Payment Information Risk: Partial (last four digits of payment cards exposed)
DATA BREACH
NamesEmail AddressesPhone NumbersDates of BirthLast Four Digits of Payment CardsProfile PhotosTransaction HistoryAccount BalancesLast Password Change DatesSensitivity Of Data: Moderate to High (PII but no full financial/account details)
AUGUST 2025
741Before Incident
JULY 2025
740Before Incident
NOVEMBER 2022
757Before Incident
Breach
18 Nov 2022DraftKings Inc.
DraftKings Inc.

Credential Stuffing Incident at DraftKings Inc.

690After Incident
LOW-67
DRA440072925
The Maine Office of the Attorney General reported a credential stuffing incident involving DraftKings Inc. on December 16, 2022. The breach began on November 18, 2022, affecting a total of 67,995 individuals, although only 125 are specifically identified as residents of Maine.
INCIDENT DETAILS -
TYPE
Credential Stuffing
JUNE 2022
770Before Incident
Cyber Attack
16 Jun 2022DraftKings Inc.
DraftKings

DraftKings Thwarts Credential Stuffing Attack, Urges Password Reset and MFA

752After Incident
HIGH-18
DRA5192751100825
DraftKings, a leading American sports gambling company, detected and thwarted a credential stuffing attack on September 2, 2025. The attack involved unauthorized access to user accounts using stolen login credentials obtained from external breaches, not from DraftKings’ systems. While no evidence suggested a direct breach of DraftKings’ infrastructure or theft of highly sensitive data (e.g., full financial details, government-issued IDs, or data enabling identity theft), attackers may have temporarily accessed certain customer accounts.Potentially exposed information included names, addresses, dates of birth, phone numbers, email addresses, last four digits of payment cards, profile photos, transaction details, account balances, and password change dates. DraftKings responded by forcing password resets, enabling multifactor authentication (MFA) for affected accounts, and implementing additional technical safeguards. Users were notified and advised to secure their accounts. The company emphasized that no systemic breach occurred, and no critical financial or identification data was compromised. This incident follows a similar 2022 attack where 68,000 accounts were compromised via credential stuffing.
INCIDENT DETAILS -
TYPE
Credential StuffingUnauthorized Access
MOTIVATION
Account TakeoverFraud (potential)
IMPACT
NamesAddressesDates of birthPhone numbersEmail addressesLast four digits of payment cardsProfile photosTransaction detailsAccount balancesPassword change datesUser accounts (limited subset)Operational Impact: Minimal (contained quickly)Brand Reputation Impact: Low (proactive response, no sensitive data exposed)Identity Theft Risk: Low (no full financial/ID data exposed)Payment Information Risk: Low (only last four digits of cards exposed)
DATA BREACH
Personal Identifiable Information (PII)Partial Payment InformationAccount MetadataSensitivity Of Data: Moderate (no full financial/ID data)
APRIL 2021
785Before Incident
Cyber Attack
01 Apr 2021DraftKings Inc.
FanDuel, BetMGM and DraftKings: Men charged in FanDuel scheme fueled by thousands of stolen identities

Two Connecticut Men Charged in $3M Online Gambling Fraud Scheme Using Stolen Identities

759After Incident
CRITICAL-26
DRABETFAN1770637923
Two Connecticut Men Charged in $3M Online Gambling Fraud Scheme Using Stolen Identities Two Connecticut residents, 29-year-old Amitoj Kapoor and Siddharth Lillaney of Glastonbury, were arrested on Thursday after a federal grand jury indicted them on 45 counts related to a multi-year fraud scheme targeting online gambling platforms. The pair allegedly defrauded FanDuel, DraftKings, BetMGM, and other sites of $3 million using stolen personally identifiable information (PII) from approximately 3,000 victims. Between April 2021 and 2026, Kapoor and Lillaney purchased stolen PII including names, dates of birth, addresses, Social Security numbers, and contact details from darknet markets and Telegram. They then used this data to create thousands of fraudulent gambling accounts, leveraging background-check services like TruthFinder and BeenVerified to bypass verification processes. Kapoor maintained a spreadsheet, "Tracker.xlsx," to organize the stolen information, as evidenced by text messages discussing the use of reverse phone searches to match identities. The scheme exploited promotional bonuses offered to new users, allowing the defendants to place bets with stolen funds. When winnings were secured, they transferred the proceeds to virtual stored-value cards and then into personal bank and investment accounts. The indictment includes charges of conspiracy to commit wire and identity fraud, wire fraud (23 counts), identity fraud (8 counts), aggravated identity theft (2 counts), and money laundering (11 counts). If convicted, Kapoor and Lillaney face decades in prison, with aggravated identity theft carrying a mandatory two-year consecutive sentence. U.S. Attorney David X. Sullivan stated that the defendants "used thousands of stolen identities to open online gambling accounts and exploit new user incentives," while IRS Special Agent in Charge Thomas Demeo emphasized the "immeasurable hardship" caused to victims. Both were released on $300,000 bond pending trial.
INCIDENT DETAILS -
TYPE
Fraud Scheme
MOTIVATION
Financial gain
IMPACT
Financial Loss: $3,000,000Data Compromised: Personally identifiable information (PII) including names, dates of birth, addresses, Social Security numbers, and contact detailsSystems Affected: Online gambling platforms (FanDuel, DraftKings, BetMGM, and others)Legal Liabilities: Potential decades in prison for the defendants; aggravated identity theft charges carry a mandatory two-year consecutive sentenceIdentity Theft Risk: High (3,000 victims affected)
DATA BREACH
Type Of Data Compromised: Personally identifiable information (PII)Number Of Records Exposed: Approximately 3,000Sensitivity Of Data: High (names, dates of birth, addresses, Social Security numbers, contact details)Data Exfiltration: Purchased from darknet markets and TelegramPersonally Identifiable Information: Names, dates of birth, addresses, Social Security numbers, contact details

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for DraftKings Inc. ?
?
What was DraftKings Inc.'s A.I Rankiteo Cyber Score in May 2026 ?
?
What was DraftKings Inc.'s A.I Rankiteo Cyber Score in April 2026 ?
?
What was DraftKings Inc.'s A.I Rankiteo Cyber Score in March 2026 ?
?
What was DraftKings Inc.'s A.I Rankiteo Cyber Score in February 2026 ?
?
What was DraftKings Inc.'s A.I Rankiteo Cyber Score in January 2026 ?
?
What was DraftKings Inc.'s A.I Rankiteo Cyber Score in December 2025 ?
?
What was DraftKings Inc.'s A.I Rankiteo Cyber Score in November 2025 ?
?
What was DraftKings Inc.'s A.I Rankiteo Cyber Score in October 2025 ?
?
What was DraftKings Inc.'s A.I Rankiteo Cyber Score in September 2025 ?
?
What was DraftKings Inc.'s A.I Rankiteo Cyber Score in August 2025 ?
?
What was DraftKings Inc.'s A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on DraftKings Inc.'s A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with DraftKings Inc. ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view DraftKings Inc.'s profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
DraftKings Inc. Cyber Scoring History | Rankiteo