2023-05-18 DOJ SDNY press_release 120 KB 6,861 chars

Wisconsin Man Charged With Hacking Fantasy Sports And Betting Website

Caption
United States v. Assistant Director in Charge of New York Field Office of Fbi, et al.
summary

Joseph Garrison, an 18-year-old from Madison, Wisconsin, was charged with orchestrating a credential-stuffing attack that compromised 60,000 accounts on a fantasy sports and betting website, stealing $600,000 from 1,600 victims by draining funds through newly added payment methods, and now faces up to 32 years in prison including a mandatory two-year sentence for aggravated identity theft.

paragraph

Joseph Garrison, 18, of Madison, Wisconsin, was charged with six federal counts including wire fraud conspiracy, computer intrusion, and aggravated identity theft for hacking approximately 60,000 user accounts on a fantasy sports and betting website via a credential-stuffing attack. He and co-conspirators stole about $600,000 from 1,600 accounts by adding new payment methods, depositing $5 to verify them, and withdrawing all existing funds. Law enforcement recovered over 40 million stolen username-password pairs and 700 custom config files targeting dozens of corporate websites on his devices, along with incriminating messages in which he boasted about his hacking success and belief he would not be caught.

narrative

Joseph Garrison, an 18-year-old from Madison, Wisconsin, was charged in a six-count federal complaint for orchestrating a credential-stuffing attack on a fantasy sports and betting website, compromising approximately 60,000 user accounts by reusing stolen login credentials obtained from prior data breaches. Through this method, he and co-conspirators added new payment methods to victim accounts, deposited $5 to verify them, and then drained the full account balances, stealing approximately $600,000 from about 1,600 victims. Law enforcement executed a search of his home in February 2023 and found over 40 million username-password pairs and 700 targeted configuration files on his computer, indicating a pattern of large-scale cyber intrusions across dozens of corporate websites. His cellphone contained incriminating messages in which he admitted to being 'addicted' to seeing money in his account, boasted about his success, and expressed confidence that law enforcement would not catch him. Garrison faces charges of conspiracy to commit computer intrusions, unauthorized access to a protected computer, wire fraud conspiracy, wire fraud, and aggravated identity theft, carrying a maximum potential sentence of 32 years, including a mandatory two-year minimum for identity theft. He surrendered to authorities in New York and was presented before U.S. Magistrate Judge James L. Cott, with prosecution led by the Southern District of New York’s Complex Frauds and Cybercrime Unit. The case underscores the FBI’s priority of holding cyber threat actors accountable for economic crimes targeting private individuals.

Enriched metadata

Scheme
cyber-fraud (95%)
Court
Southern District of New York
Outcome
charged · 2023-05-18
Victim loss
$600,000
Victims
1,600
Classified cyber-fraud(confidence 95%). No EDGAR filing fingerprint (criminal/DOJ-side scheme). detection rule →
Parties
assistant director in charge of new york field office of fbidamian williamsjoseph garrisonlaw enforcementmichael j. driscoll
Keywords
betting websitegarrisoncredential stuffingwebsiteaccountsbettingvictim accountswhich carriessentence prisonnewstuffing attackscarries maximummaximum sentencecredentialstuffing

Extracted insights

Dollar amounts 1
  • $600K $600,000 $100K–$1M
Entities 5
  • agency assistant director in charge of new york field office of fbi
  • person damian williams
  • person joseph garrison
  • person law enforcement
  • person michael j. driscoll
Triples 11
  • Joseph Garrison charged with hacking fantasy sports and betting website
  • Joseph Garrison launched credential stuffing attack on Betting Website on November 18, 2022
  • Joseph Garrison accessed approximately 60,000 accounts at Betting Website
  • Joseph Garrison stole approximately $600,000 from approximately 1,600 Victim Accounts
  • Joseph Garrison sold access to hacked accounts with instructions on how to drain funds
  • Damian Williams is United States Attorney for Southern District of New York
  • Michael J. Driscoll is Assistant Director in Charge of New York Field Office of FBI
  • Joseph Garrison surrendered in New York, New York on May 18, 2023
  • Joseph Garrison presented before United States Magistrate Judge James L. Cott
  • Law enforcement executed search on Joseph Garrison's home in February 2023
  • Law enforcement located programs used for credential stuffing attacks at Garrison's home
View original DOJ press releasejustice.gov
Extracted body text (6,861c)
Press Release Wisconsin Man Charged With Hacking Fantasy Sports And Betting Website Thursday, May 18, 2023 Share FacebookLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. XLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. LinkedInLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. Email For Immediate Release U.S. Attorney's Office, Southern District of New York Defendant Sold Access to Hacked Accounts with Instructions on How to Drain the Accounts’ Funds Damian Williams, the United States Attorney for the Southern District of New York, and Michael J. Driscoll, the Assistant Director in Charge of the New York Field Office of the Federal Bureau of Investigation (“FBI”), announced the unsealing of a six-count criminal Complaint charging JOSEPH GARRISON in connection with a scheme to hack user accounts at a fantasy sports and betting website (the “Betting Website”) and sell access to those accounts in order to steal hundreds of thousands of dollars from them. GARRISON surrendered this morning in New York, New York, and will be presented this afternoon before United States Magistrate Judge James L. Cott. U.S. Attorney Damian Williams said: “As alleged, Garrison used a credential stuffing attack to hack into the accounts of tens of thousands of victims and steal hundreds of thousands of dollars. Today, thanks to the work of my Office and the FBI, Garrison learned that you shouldn’t bet on getting away with fraud.” FBI Assistant Director in Charge Michael J. Driscoll said: “As alleged, Garrison attained unauthorized access to victim accounts using a sophisticated cyber-breaching attack to steal hundreds of thousands of dollars. Cyber intrusions aiming to steal private individuals’ funds represent a serious risk to our economic security. Combatting cyberattacks and holding the responsible threat actors accountable in the criminal justice system remains a top priority for the FBI.” As alleged in the Complaint:[1] On or about November 18, 2022, GARRISON launched a “credential stuffing attack” on the Betting Website. During a credential stuffing attack, a cyber threat actor collects stolen credentials, or username and password pairs, obtained from other large-scale data breaches of other companies, which can be purchased on the dark web. The threat actor then systematically attempts to use those stolen credentials to obtain unauthorized access to accounts held by the same user with other companies and providers in order to compromise accounts where the user has maintained the same password. Here, in connection with the attack on the Betting Website, there was a series of attempts to log into the Betting Website accounts using a large list of stolen credentials. GARRISON and others successfully accessed approximately 60,000 accounts at the Betting Website (the “Victim Accounts”) through the credential stuffing attack. In some instances, the individuals who unlawfully accessed the Victim Accounts were able to add a new payment method on the account, deposit $5 into that account through the new payment method to verify that method, and then withdraw all the existing funds in the Victim Account through the new payment method (i.e., to a newly added financial account belonging to the hacker), thus stealing the funds in the Victim Account. Using this method, GARRISON and others stole approximately $600,000 from approximately 1,600 Victim Accounts. Law enforcement executed a search on GARRISON’s home in February 2023. In that search, they located programs typically used for credential stuffing attacks. Those programs require individualized “config” files for a target website to launch credential stuffing attacks, and law enforcement located approximately 700 such config files for dozens of different corporate websites on GARRISON’s computer. Law enforcement also located files containing nearly 40 million username and password pairs on GARRISON’s computer, which are also used in credential stuffing attacks. On GARRISON’s cellphone, law enforcement also located conversations between GARRISON and his co-conspirators, which included discussions about how to hack the Betting Website and how to profit from the hack of the Betting Website by extracting funds from the Victim Accounts directly or by selling access to the Victim Accounts. In one particular conversation, GARRISON discussed, in substance and in part, how successful he was at credential stuffing attacks, how much he enjoyed credential stuffing attacks, and how GARRISON believed that law enforcement would not catch or prosecute him. Specifically, GARRISON messaged the following, in substance and in part: “fraud is fun . . . im addicted to see money in my account . . . im like obsessed with bypassing shit.” * * * GARRISON, 18, of Madison, Wisconsin, is charged with conspiracy to commit computer intrusions, which carries a maximum sentence of five years in prison; unauthorized access to a protected computer to further intended fraud, which carries a maximum sentence of five years in prison; unauthorized access to a protected computer, which carries a maximum sentence of five years in prison; wire fraud conspiracy, which carries a maximum sentence of 20 years in prison; wire fraud, which carries a maximum sentence of 20 years in prison; and aggravated identity theft, which carries a mandatory minimum sentence of two years in prison. The minimum and maximum potential sentences are prescribed by Congress and are provided here for informational purposes only, as any sentencing of the defendant will be determined by a judge. Mr. Williams praised the outstanding work of the FBI. Mr. Williams also thanked the United States Attorney’s Office for the Western District of Wisconsin for their assistance in the investigation. The case is being prosecuted by the Office’s Complex Frauds and Cybercrime Unit. Assistant U.S. Attorneys Kevin Mead and Micah Fergenson are in charge of the prosecution. The charges contained in the Complaint are merely accusations, and the defendant is presumed innocent unless and until proven guilty. [1] As the introductory phrase signifies, the entirety of the text of the Complaint and the description of the Complaint set forth herein constitute only allegations, and every fact described should be treated as an allegation. Contact Nicholas Biase (212) 637-2600 Updated May 18, 2023 Topic Cybercrime Component USAO - New York, Southern Press Release Number: 23-185
OCR text (6,861c · html-text · 99% conf)
Press Release Wisconsin Man Charged With Hacking Fantasy Sports And Betting Website Thursday, May 18, 2023 Share FacebookLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. XLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. LinkedInLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. Email For Immediate Release U.S. Attorney's Office, Southern District of New York Defendant Sold Access to Hacked Accounts with Instructions on How to Drain the Accounts’ Funds Damian Williams, the United States Attorney for the Southern District of New York, and Michael J. Driscoll, the Assistant Director in Charge of the New York Field Office of the Federal Bureau of Investigation (“FBI”), announced the unsealing of a six-count criminal Complaint charging JOSEPH GARRISON in connection with a scheme to hack user accounts at a fantasy sports and betting website (the “Betting Website”) and sell access to those accounts in order to steal hundreds of thousands of dollars from them. GARRISON surrendered this morning in New York, New York, and will be presented this afternoon before United States Magistrate Judge James L. Cott. U.S. Attorney Damian Williams said: “As alleged, Garrison used a credential stuffing attack to hack into the accounts of tens of thousands of victims and steal hundreds of thousands of dollars. Today, thanks to the work of my Office and the FBI, Garrison learned that you shouldn’t bet on getting away with fraud.” FBI Assistant Director in Charge Michael J. Driscoll said: “As alleged, Garrison attained unauthorized access to victim accounts using a sophisticated cyber-breaching attack to steal hundreds of thousands of dollars. Cyber intrusions aiming to steal private individuals’ funds represent a serious risk to our economic security. Combatting cyberattacks and holding the responsible threat actors accountable in the criminal justice system remains a top priority for the FBI.” As alleged in the Complaint:[1] On or about November 18, 2022, GARRISON launched a “credential stuffing attack” on the Betting Website. During a credential stuffing attack, a cyber threat actor collects stolen credentials, or username and password pairs, obtained from other large-scale data breaches of other companies, which can be purchased on the dark web. The threat actor then systematically attempts to use those stolen credentials to obtain unauthorized access to accounts held by the same user with other companies and providers in order to compromise accounts where the user has maintained the same password. Here, in connection with the attack on the Betting Website, there was a series of attempts to log into the Betting Website accounts using a large list of stolen credentials. GARRISON and others successfully accessed approximately 60,000 accounts at the Betting Website (the “Victim Accounts”) through the credential stuffing attack. In some instances, the individuals who unlawfully accessed the Victim Accounts were able to add a new payment method on the account, deposit $5 into that account through the new payment method to verify that method, and then withdraw all the existing funds in the Victim Account through the new payment method (i.e., to a newly added financial account belonging to the hacker), thus stealing the funds in the Victim Account. Using this method, GARRISON and others stole approximately $600,000 from approximately 1,600 Victim Accounts. Law enforcement executed a search on GARRISON’s home in February 2023. In that search, they located programs typically used for credential stuffing attacks. Those programs require individualized “config” files for a target website to launch credential stuffing attacks, and law enforcement located approximately 700 such config files for dozens of different corporate websites on GARRISON’s computer. Law enforcement also located files containing nearly 40 million username and password pairs on GARRISON’s computer, which are also used in credential stuffing attacks. On GARRISON’s cellphone, law enforcement also located conversations between GARRISON and his co-conspirators, which included discussions about how to hack the Betting Website and how to profit from the hack of the Betting Website by extracting funds from the Victim Accounts directly or by selling access to the Victim Accounts. In one particular conversation, GARRISON discussed, in substance and in part, how successful he was at credential stuffing attacks, how much he enjoyed credential stuffing attacks, and how GARRISON believed that law enforcement would not catch or prosecute him. Specifically, GARRISON messaged the following, in substance and in part: “fraud is fun . . . im addicted to see money in my account . . . im like obsessed with bypassing shit.” * * * GARRISON, 18, of Madison, Wisconsin, is charged with conspiracy to commit computer intrusions, which carries a maximum sentence of five years in prison; unauthorized access to a protected computer to further intended fraud, which carries a maximum sentence of five years in prison; unauthorized access to a protected computer, which carries a maximum sentence of five years in prison; wire fraud conspiracy, which carries a maximum sentence of 20 years in prison; wire fraud, which carries a maximum sentence of 20 years in prison; and aggravated identity theft, which carries a mandatory minimum sentence of two years in prison. The minimum and maximum potential sentences are prescribed by Congress and are provided here for informational purposes only, as any sentencing of the defendant will be determined by a judge. Mr. Williams praised the outstanding work of the FBI. Mr. Williams also thanked the United States Attorney’s Office for the Western District of Wisconsin for their assistance in the investigation. The case is being prosecuted by the Office’s Complex Frauds and Cybercrime Unit. Assistant U.S. Attorneys Kevin Mead and Micah Fergenson are in charge of the prosecution. The charges contained in the Complaint are merely accusations, and the defendant is presumed innocent unless and until proven guilty. [1] As the introductory phrase signifies, the entirety of the text of the Complaint and the description of the Complaint set forth herein constitute only allegations, and every fact described should be treated as an allegation. Contact Nicholas Biase (212) 637-2600 Updated May 18, 2023 Topic Cybercrime Component USAO - New York, Southern Press Release Number: 23-185