DraftKings Inc. A.I CyberSecurity Scoring
DraftKings Inc.
Company Information
Website:https://careers.draftkings.com/
Employees number:5,698
Number of followers:161,144
NAICS:511261
Industry Type:Mobile Gaming Apps
Homepage:draftkings.com
DraftKings Inc. Risk Score (AI oriented)
Between 700 and 749
DraftKings Inc.Mobile Gaming Apps
Updated:
03/04/2026
03/04/2026
730/1000
Moderate
Ba
DraftKings Inc. Global Score (TPRM)
xxxx
DraftKings Inc.Mobile Gaming Apps
Score locked

DraftKings Inc.Moderate
Current Score
730Ba (MODERATE)
01000
5 incidents
-59.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
649
MAY 2026
642
APRIL 2026
730
MARCH 2026
729
FEBRUARY 2026
731
JANUARY 2026
727
DECEMBER 2025
728
NOVEMBER 2025
726
Breach
28 Nov 2025 • DraftKings Inc.
23andMe Nets Approval for Bankruptcy Plan With Data Breach Deals
23andMe Data Breach and Bankruptcy Settlement
624
CRITICAL-102
23A1764346412
Fallen DNA testing firm 23andMe won court approval of a bankruptcy plan that includes settlements to provide up to $62 million to resolve thousands of data breach claims.
Judge Brian C. Walsh of the US Bankruptcy Court for the Eastern District of Missouri approved the plan in a Wednesday order, overruling most creditor objections and challenges from data breach victims.
Many of those former customers’ objections were deemed moot or premature, and several of them didn’t appear at a court hearing on the plan.
Objections from the Justice Department’s bankruptcy watchdog and a coalition of state attorneys general were resolved ...
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
OCTOBER 2025
727
SEPTEMBER 2025
741
Cyber Attack
02 Sep 2025 • DraftKings Inc.
DraftKings
DraftKings Account Compromise via Credential Stuffing/Brute-Force Attack
724
CRITICAL-17
DRA4092140100825
DraftKings suffered a credential stuffing or brute-force attack on September 2, 2025, compromising customer accounts. While the company confirmed its systems were not directly breached, attackers used stolen credentials from external sources to access accounts. Exposed data included names, email addresses, phone numbers, dates of birth, last four digits of payment cards, profile photos, transaction histories, account balances, and password change dates—though DraftKings claimed no government-issued IDs, full financial details, or data enabling direct identity theft were accessed.The incident poses risks of financial fraud, targeted phishing, SIM-swap attacks, social engineering, and extortion, as the leaked information can be weaponized for follow-up attacks. DraftKings advised users to reset passwords, enable two-factor authentication (2FA), monitor credit reports, and consider security freezes. The attack highlights vulnerabilities in reused credentials and underscores the need for stronger authentication measures. No ransomware was involved, but the scale of exposed personal and financial fragments raises concerns over long-term misuse.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
AUGUST 2025
741
JULY 2025
740
NOVEMBER 2022
757
Breach
18 Nov 2022 • DraftKings Inc.
DraftKings Inc.
Credential Stuffing Incident at DraftKings Inc.
690
LOW-67
DRA440072925
The Maine Office of the Attorney General reported a credential stuffing incident involving DraftKings Inc. on December 16, 2022. The breach began on November 18, 2022, affecting a total of 67,995 individuals, although only 125 are specifically identified as residents of Maine.
INCIDENT DETAILS -
TYPE
REFERENCES
JUNE 2022
770
Cyber Attack
16 Jun 2022 • DraftKings Inc.
DraftKings
DraftKings Thwarts Credential Stuffing Attack, Urges Password Reset and MFA
752
HIGH-18
DRA5192751100825
DraftKings, a leading American sports gambling company, detected and thwarted a credential stuffing attack on September 2, 2025. The attack involved unauthorized access to user accounts using stolen login credentials obtained from external breaches, not from DraftKings’ systems. While no evidence suggested a direct breach of DraftKings’ infrastructure or theft of highly sensitive data (e.g., full financial details, government-issued IDs, or data enabling identity theft), attackers may have temporarily accessed certain customer accounts.Potentially exposed information included names, addresses, dates of birth, phone numbers, email addresses, last four digits of payment cards, profile photos, transaction details, account balances, and password change dates. DraftKings responded by forcing password resets, enabling multifactor authentication (MFA) for affected accounts, and implementing additional technical safeguards. Users were notified and advised to secure their accounts. The company emphasized that no systemic breach occurred, and no critical financial or identification data was compromised. This incident follows a similar 2022 attack where 68,000 accounts were compromised via credential stuffing.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
APRIL 2021
785
Cyber Attack
01 Apr 2021 • DraftKings Inc.
FanDuel, BetMGM and DraftKings: Men charged in FanDuel scheme fueled by thousands of stolen identities
Two Connecticut Men Charged in $3M Online Gambling Fraud Scheme Using Stolen Identities
759
CRITICAL-26
DRABETFAN1770637923
Two Connecticut Men Charged in $3M Online Gambling Fraud Scheme Using Stolen Identities
Two Connecticut residents, 29-year-old Amitoj Kapoor and Siddharth Lillaney of Glastonbury, were arrested on Thursday after a federal grand jury indicted them on 45 counts related to a multi-year fraud scheme targeting online gambling platforms. The pair allegedly defrauded FanDuel, DraftKings, BetMGM, and other sites of $3 million using stolen personally identifiable information (PII) from approximately 3,000 victims.
Between April 2021 and 2026, Kapoor and Lillaney purchased stolen PII including names, dates of birth, addresses, Social Security numbers, and contact details from darknet markets and Telegram. They then used this data to create thousands of fraudulent gambling accounts, leveraging background-check services like TruthFinder and BeenVerified to bypass verification processes. Kapoor maintained a spreadsheet, "Tracker.xlsx," to organize the stolen information, as evidenced by text messages discussing the use of reverse phone searches to match identities.
The scheme exploited promotional bonuses offered to new users, allowing the defendants to place bets with stolen funds. When winnings were secured, they transferred the proceeds to virtual stored-value cards and then into personal bank and investment accounts.
The indictment includes charges of conspiracy to commit wire and identity fraud, wire fraud (23 counts), identity fraud (8 counts), aggravated identity theft (2 counts), and money laundering (11 counts). If convicted, Kapoor and Lillaney face decades in prison, with aggravated identity theft carrying a mandatory two-year consecutive sentence.
U.S. Attorney David X. Sullivan stated that the defendants "used thousands of stolen identities to open online gambling accounts and exploit new user incentives," while IRS Special Agent in Charge Thomas Demeo emphasized the "immeasurable hardship" caused to victims. Both were released on $300,000 bond pending trial.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for DraftKings Inc. ??
What was DraftKings Inc.'s A.I Rankiteo Cyber Score in May 2026 ??
What was DraftKings Inc.'s A.I Rankiteo Cyber Score in April 2026 ??
What was DraftKings Inc.'s A.I Rankiteo Cyber Score in March 2026 ??
What was DraftKings Inc.'s A.I Rankiteo Cyber Score in February 2026 ??
What was DraftKings Inc.'s A.I Rankiteo Cyber Score in January 2026 ??
What was DraftKings Inc.'s A.I Rankiteo Cyber Score in December 2025 ??
What was DraftKings Inc.'s A.I Rankiteo Cyber Score in November 2025 ??
What was DraftKings Inc.'s A.I Rankiteo Cyber Score in October 2025 ??
What was DraftKings Inc.'s A.I Rankiteo Cyber Score in September 2025 ??
What was DraftKings Inc.'s A.I Rankiteo Cyber Score in August 2025 ??
What was DraftKings Inc.'s A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on DraftKings Inc.'s A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with DraftKings Inc. ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view DraftKings Inc.'s profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?