2026-04-16 DOJ SDNY press_release 117 KB 4,918 chars

Defendant Sentenced To Prison For Hacking Betting Website

Caption
United States v. Credential Stuffing Attack, et al.
summary

Kamerin Stokes was sentenced to 30 months in prison for a credential stuffing attack on a betting website that compromised 60,000 accounts and resulted in over $1.3 million in restitution.

paragraph

Kamerin Stokes, known as 'TheMFNPlug,' was sentenced to 30 months in prison for conspiring to commit computer intrusion via a credential stuffing attack. The scheme compromised approximately 60,000 accounts on a fantasy sports and betting website, involving account values exceeding $125,000. Stokes was ordered to pay $125,965.53 in forfeiture and $1,327,061 in restitution.

narrative

Kamerin Stokes, a 23-year-old from Memphis, was sentenced to 30 months in prison for his role in a cyberattack targeting a fantasy sports and betting website. Using a credential stuffing attack, Stokes and others compromised approximately 60,000 accounts to steal funds and resell access through his online 'Shop.' After pleading guilty to conspiring to commit computer intrusion, Stokes audaciously reopened his business with the tagline 'fraud is fun' to cover his legal fees. This led to a pretrial release violation and subsequent rearrest. In addition to his prison term and three years of supervised release, Stokes must pay $125,965.53 in forfeiture and $1,327,061 in restitution. The case was prosecuted by the U.S. Attorney's Office for the Southern District of New York with assistance from the FBI.

Enriched metadata

Scheme
cyber-fraud (100%)
Court
Southern District of New York
Outcome
pleaded · 2024-04-25
Restitution
$1,327,061
Entity
KAMERIN STOKES
Classified cyber-fraud(confidence 100%). No EDGAR filing fingerprint (criminal/DOJ-side scheme). detection rule →
Parties
credential stuffing attackcriminal businesshis own shopJay Claytonkamerin stokeskamerin stokes sentenceduser accountsvictim accounts
Keywords
betting websitewebsiteaccountsbettingstokesvictim accountsnewfraudshopprisonlinkvictimprison hackinghacking bettinggovernment non-government

Extracted insights

Dollar amounts 3
  • $1.33M $1,327,061 $1M–$10M
  • $126K $125,965 $100K–$1M
  • $125K $125,000 $100K–$1M
Entities 8
  • person credential stuffing attack
  • person criminal business
  • person his own shop
  • person Jay Clayton
  • person kamerin stokes
  • person kamerin stokes sentenced
  • person user accounts
  • person victim accounts
Triples 12
  • Jay Clayton Announced Kamerin Stokes Sentenced
  • Kamerin Stokes Was Sentenced To 30 Months In Prison
  • Kamerin Stokes Hacked Fantasy Sports And Betting Website
  • Kamerin Stokes Sold Access To User Accounts
  • Kamerin Stokes Pled Guilty To One Count Of Conspiring To Commit Computer Intrusion
  • Kamerin Stokes Victimized Thousands Of Users
  • Kamerin Stokes Reopened Criminal Business
  • Several Individuals Launched Credential Stuffing Attack
  • Individuals Accessed 60,000 Accounts
  • Kamerin Stokes Controlled His Own Shop
  • Kamerin Stokes Obtained Victim Accounts
  • Victim Accounts Had Total Value Of Over $125,000
View original DOJ press releasejustice.gov
Extracted body text (4,918c)
Press Release Defendant Sentenced To Prison For Hacking Betting Website Thursday, April 16, 2026 Share FacebookLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. XLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. LinkedInLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. Email For Immediate Release U.S. Attorney's Office, Southern District of New York United States Attorney for the Southern District of New York, Jay Clayton, announced today that KAMERIN STOKES, a/k/a “TheMFNPlug,” was sentenced to 30 months in prison for his role in a scheme to hack user accounts on a fantasy sports and betting website (the “Betting Website”) and sell access to those accounts, resulting in losses of hundreds of thousands of dollars to the users. STOKES was sentenced today before U.S. District Judge Naomi Reice Buchwald. On April 25, 2024, STOKES pled guilty to one count of conspiring to commit computer intrusion.“Kamerin Stokes victimized thousands of users of an online betting website though a cyberattack,” said U.S. Attorney Jay Clayton. “After pleading guilty to federal crimes, Stokes audaciously reopened his criminal business, marketed using the tagline ‘fraud is fun,’ and said that he opened the new Shop in part because ‘gotta pay my attorneys,’ referring to his prosecution in this case. Fraud is not fun; fraud on the street or fraud online will not be tolerated. Today’s federal prison sentence is a direct message to any others who think online fraud is different.”According to the charging documents and other filings and statements made in court:On or about November 18, 2022, several individuals launched a “credential stuffing attack” on the Betting Website. During a credential stuffing attack, a cyber threat actor collects stolen credentials, or username and password pairs, obtained from other large-scale data breaches of other companies, which can be purchased on the dark web. The threat actor then systematically attempts to use those stolen credentials to obtain unauthorized access to accounts held by the same user with other companies and providers, in order to compromise accounts where the user has maintained the same password. Here, in connection with the attack on the Betting Website, there was a series of attempts to log into the Betting Website accounts using a large list of stolen credentials.Those individuals successfully accessed approximately 60,000 accounts at the Betting Website (the “Victim Accounts”) through the credential stuffing attack. In some instances, the individuals who unlawfully accessed the Victim Accounts were able to add a new payment method on the account, deposit $5 into that account through the new payment method to verify that method, and then withdraw all the existing funds in the Victim Account through the new payment method (i.e., to a newly added financial account belonging to the hacker), thus stealing the funds in the Victim Account.Access to the Victim Accounts was sold on various websites that traffic in stolen accounts, which are frequently referred to as “Shops.” STOKES controlled his own Shop, used the alias “TheMFNPlug,” and purchased Victim Accounts in bulk. STOKES obtained Victim Accounts from the Betting Website with a total listed account value of over $125,000 and then offered access to those accounts for sale on his Shop.After pleading guilty, STOKES reopened his Shop website, offering for sale access to stolen accounts of various retailers. STOKES advertised his reopened Shop using the tagline “fraud is fun,” and said that he had been running these types of shops for three years. He further said that he opened the new Shop in part because “gotta pay my attorneys,” referring to his prosecution in this case. After reopening his Shop website, STOKES was rearrested for violating the conditions of his pretrial release and remanded into federal custody.* * *In addition to the prison term, STOKES, 23, of Memphis, Tennessee, was sentenced to three years of supervised release and ordered to pay $125,965.53 in forfeiture and $1,327,061 in restitution.Mr. Clayton praised the outstanding work of the Federal Bureau of Investigation. The case is being prosecuted by the Office’s Complex Frauds and Cybercrime Unit. Assistant U.S. Attorneys Kevin Mead and Micah Fergenson are in charge of the prosecution. Contact Nicholas Biase, Shelby Wratchford(212) 637-2600 Updated April 16, 2026 Topics Cybercrime Financial Fraud Component USAO - New York, Southern Press Release Number: 26-102
OCR text (4,918c · html-text · 99% conf)
Press Release Defendant Sentenced To Prison For Hacking Betting Website Thursday, April 16, 2026 Share FacebookLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. XLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. LinkedInLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. Email For Immediate Release U.S. Attorney's Office, Southern District of New York United States Attorney for the Southern District of New York, Jay Clayton, announced today that KAMERIN STOKES, a/k/a “TheMFNPlug,” was sentenced to 30 months in prison for his role in a scheme to hack user accounts on a fantasy sports and betting website (the “Betting Website”) and sell access to those accounts, resulting in losses of hundreds of thousands of dollars to the users. STOKES was sentenced today before U.S. District Judge Naomi Reice Buchwald. On April 25, 2024, STOKES pled guilty to one count of conspiring to commit computer intrusion.“Kamerin Stokes victimized thousands of users of an online betting website though a cyberattack,” said U.S. Attorney Jay Clayton. “After pleading guilty to federal crimes, Stokes audaciously reopened his criminal business, marketed using the tagline ‘fraud is fun,’ and said that he opened the new Shop in part because ‘gotta pay my attorneys,’ referring to his prosecution in this case. Fraud is not fun; fraud on the street or fraud online will not be tolerated. Today’s federal prison sentence is a direct message to any others who think online fraud is different.”According to the charging documents and other filings and statements made in court:On or about November 18, 2022, several individuals launched a “credential stuffing attack” on the Betting Website. During a credential stuffing attack, a cyber threat actor collects stolen credentials, or username and password pairs, obtained from other large-scale data breaches of other companies, which can be purchased on the dark web. The threat actor then systematically attempts to use those stolen credentials to obtain unauthorized access to accounts held by the same user with other companies and providers, in order to compromise accounts where the user has maintained the same password. Here, in connection with the attack on the Betting Website, there was a series of attempts to log into the Betting Website accounts using a large list of stolen credentials.Those individuals successfully accessed approximately 60,000 accounts at the Betting Website (the “Victim Accounts”) through the credential stuffing attack. In some instances, the individuals who unlawfully accessed the Victim Accounts were able to add a new payment method on the account, deposit $5 into that account through the new payment method to verify that method, and then withdraw all the existing funds in the Victim Account through the new payment method (i.e., to a newly added financial account belonging to the hacker), thus stealing the funds in the Victim Account.Access to the Victim Accounts was sold on various websites that traffic in stolen accounts, which are frequently referred to as “Shops.” STOKES controlled his own Shop, used the alias “TheMFNPlug,” and purchased Victim Accounts in bulk. STOKES obtained Victim Accounts from the Betting Website with a total listed account value of over $125,000 and then offered access to those accounts for sale on his Shop.After pleading guilty, STOKES reopened his Shop website, offering for sale access to stolen accounts of various retailers. STOKES advertised his reopened Shop using the tagline “fraud is fun,” and said that he had been running these types of shops for three years. He further said that he opened the new Shop in part because “gotta pay my attorneys,” referring to his prosecution in this case. After reopening his Shop website, STOKES was rearrested for violating the conditions of his pretrial release and remanded into federal custody.* * *In addition to the prison term, STOKES, 23, of Memphis, Tennessee, was sentenced to three years of supervised release and ordered to pay $125,965.53 in forfeiture and $1,327,061 in restitution.Mr. Clayton praised the outstanding work of the Federal Bureau of Investigation. The case is being prosecuted by the Office’s Complex Frauds and Cybercrime Unit. Assistant U.S. Attorneys Kevin Mead and Micah Fergenson are in charge of the prosecution. Contact Nicholas Biase, Shelby Wratchford(212) 637-2600 Updated April 16, 2026 Topics Cybercrime Financial Fraud Component USAO - New York, Southern Press Release Number: 26-102