Wisconsin Man Sentenced To Prison For Hacking Fantasy Sports And Betting Website
Joseph Garrison, a 19-year-old Wisconsin man, was sentenced to 18 months in prison for conspiring to commit computer intrusion in a scheme that hacked user accounts on a fantasy sports and betting website, resulting in losses of approximately $600,000 to 1,600 users.
Joseph Garrison, a 19-year-old from Madison, Wisconsin, was sentenced to 18 months in prison for conspiring to commit computer intrusion after orchestrating a credential stuffing attack on a fantasy sports and betting website. He and his co-conspirators used over 40 million stolen username-password pairs to compromise approximately 60,000 user accounts, stealing around $600,000 by draining funds or selling access to hacked accounts. Garrison was ordered to pay $1,327,061 in restitution and $175,019 in forfeiture, in addition to three years of supervised release.
Joseph Garrison, a 19-year-old from Madison, Wisconsin, was sentenced to 18 months in prison for conspiring to commit computer intrusion after orchestrating a credential stuffing attack on a fantasy sports and betting website. The scheme involved using over 40 million stolen username-password pairs, obtained from prior data breaches, to gain unauthorized access to approximately 60,000 user accounts. Garrison and his co-conspirators stole around $600,000 by draining funds via newly added payment methods or selling access to hacked accounts, affecting roughly 1,600 victims. Law enforcement found extensive evidence on his devices, including 700 targeted attack configuration files and incriminating messages in which he admitted to being “addicted” to fraud. Garrison pled guilty in November 2023 and was ordered to pay $1,327,061 in restitution and $175,019 in forfeiture, in addition to three years of supervised release. The case was prosecuted by the Southern District of New York’s Complex Frauds and Cybercrime Unit, with support from the FBI and NYPD. Garrison's actions not only breached personal security but also eroded trust in online platforms, highlighting the urgent need for vigilance and collective efforts in combatting cyber threats and safeguarding digital integrity.
Extracted insights
- $1.33M $1,327,061 $1M–$10M
- $600K $600,000 $100K–$1M
- $175K $175,019 $100K–$1M
- person damian williams
- person joseph garrison
- person law enforcement
- Joseph Garrison sentenced to 18 months in prison
- Joseph Garrison pled guilty to one count of conspiring to commit computer intrusion
- Joseph Garrison launched credential stuffing attack on Betting Website on November 18, 2022
- Joseph Garrison accessed approximately 60,000 accounts on Betting Website
- Joseph Garrison stole approximately $600,000 from approximately 1,600 Victim Accounts
- Joseph Garrison possessed approximately 700 config files for credential stuffing attacks
- Joseph Garrison possessed nearly 40 million username and password pairs
- Damian Williams announced sentencing of Joseph Garrison
- U.S. District Judge Lewis A. Kaplan sentenced Joseph Garrison
- Joseph Garrison pled guilty on November 15, 2023
- Law enforcement executed search on Joseph Garrison's home in February 2023
Press Release Wisconsin Man Sentenced To Prison For Hacking Fantasy Sports And Betting Website Wednesday, January 31, 2024 Share FacebookLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. XLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. LinkedInLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. Email For Immediate Release U.S. Attorney's Office, Southern District of New York Damian Williams, the United States Attorney for the Southern District of New York, announced today that JOSEPH GARRISON was sentenced to 18 months in prison for his role in a scheme to hack user accounts on a fantasy sports and betting website (the “Betting Website”) and sell access to those accounts, resulting in losses of hundreds of thousands of dollars to the users. GARRISON was sentenced today before U.S. District Judge Lewis A. Kaplan. On November 15, 2023, GARRISON pled guilty to one count of conspiring to commit computer intrusion. U.S. Attorney Damian Williams said: “Joseph Garrison and his co-conspirators orchestrated a bold credential stuffing attack – collecting stolen usernames and password pairs from other large-scale data breaches – by exploiting vulnerabilities to siphon approximately $600,000 from unsuspecting victims. Such attacks not only breach personal security but erode trust in online platforms. Today’s sentencing underscores the urgent need for vigilance and the critical importance of our collective efforts in combatting cyber threats and safeguarding digital integrity.” According to the charging documents and other filings and statements made in court: On or about November 18, 2022, GARRISON launched a “credential stuffing attack” on the Betting Website. During a credential stuffing attack, a cyber threat actor collects stolen credentials, or username and password pairs, obtained from other large-scale data breaches, which can be purchased on the dark web. The threat actor then systematically attempts to use those stolen credentials to obtain unauthorized access to accounts held by the same user with other companies and providers in order to compromise accounts where the user has maintained the same password. Here, in connection with the attack on the Betting Website, there was a series of attempts to log into the Betting Website accounts using a large list of stolen credentials. GARRISON and others successfully accessed approximately 60,000 accounts on the Betting Website (the “Victim Accounts”) through the credential stuffing attack. In some instances, the individuals who unlawfully accessed the Victim Accounts were able to add a new payment method on the account, deposit $5 into that account through the new payment method to verify that method, and then withdraw all the existing funds in the Victim Account through the new payment method (i.e., to a newly added financial account belonging to the hacker), thus stealing the funds in the Victim Accounts. Using this method, GARRISON and others stole approximately $600,000 from approximately 1,600 Victim Accounts on the Betting Website. Law enforcement executed a search on GARRISON’s home in February 2023. In that search, they located programs typically used for credential stuffing attacks. Those programs require individualized “config” files for a target website to launch credential stuffing attacks, and law enforcement located approximately 700 such config files for dozens of different corporate websites on GARRISON’s computer. Law enforcement also located files containing nearly 40 million username and password pairs on GARRISON’s computer, which are also used in credential stuffing attacks. On GARRISON’s cellphone, law enforcement also located conversations between GARRISON and his co-conspirators, including discussions about how to hack the Betting Website and how to profit from the hack of the Betting Website by extracting funds from the Victim Accounts directly or by selling access to the Victim Accounts. In one particular conversation, GARRISON discussed, in substance and in part, how successful he was at credential stuffing attacks, how much he enjoyed credential stuffing attacks, and how GARRISON believed that law enforcement would not catch or prosecute him. Specifically, GARRISON messaged the following, in substance and in part: “fraud is fun . . . im addicted to see money in my account . . . im like obsessed with bypassing shit.” * * * In addition to the prison term, GARRISON, 19, of Madison, Wisconsin, was sentenced to 3 years of supervised release and ordered to pay $175,019.11 in forfeiture and $1,327,061 in restitution. Mr. Williams praised the outstanding work of the Federal Bureau of Investigation. Mr. Williams also thanked the New York City Police Department for its assistance in the investigation. The case is being prosecuted by the Office’s Complex Frauds and Cybercrime Unit. Assistant U.S. Attorneys Kevin Mead and Micah Fergenson are in charge of the prosecution. Contact Nicholas Biase, Lauren Scarff (212) 637-2600 Updated January 31, 2024 Topic Cybercrime Component USAO - New York, Southern Press Release Number: 24-038
Press Release Wisconsin Man Sentenced To Prison For Hacking Fantasy Sports And Betting Website Wednesday, January 31, 2024 Share FacebookLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. XLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. LinkedInLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. Email For Immediate Release U.S. Attorney's Office, Southern District of New York Damian Williams, the United States Attorney for the Southern District of New York, announced today that JOSEPH GARRISON was sentenced to 18 months in prison for his role in a scheme to hack user accounts on a fantasy sports and betting website (the “Betting Website”) and sell access to those accounts, resulting in losses of hundreds of thousands of dollars to the users. GARRISON was sentenced today before U.S. District Judge Lewis A. Kaplan. On November 15, 2023, GARRISON pled guilty to one count of conspiring to commit computer intrusion. U.S. Attorney Damian Williams said: “Joseph Garrison and his co-conspirators orchestrated a bold credential stuffing attack – collecting stolen usernames and password pairs from other large-scale data breaches – by exploiting vulnerabilities to siphon approximately $600,000 from unsuspecting victims. Such attacks not only breach personal security but erode trust in online platforms. Today’s sentencing underscores the urgent need for vigilance and the critical importance of our collective efforts in combatting cyber threats and safeguarding digital integrity.” According to the charging documents and other filings and statements made in court: On or about November 18, 2022, GARRISON launched a “credential stuffing attack” on the Betting Website. During a credential stuffing attack, a cyber threat actor collects stolen credentials, or username and password pairs, obtained from other large-scale data breaches, which can be purchased on the dark web. The threat actor then systematically attempts to use those stolen credentials to obtain unauthorized access to accounts held by the same user with other companies and providers in order to compromise accounts where the user has maintained the same password. Here, in connection with the attack on the Betting Website, there was a series of attempts to log into the Betting Website accounts using a large list of stolen credentials. GARRISON and others successfully accessed approximately 60,000 accounts on the Betting Website (the “Victim Accounts”) through the credential stuffing attack. In some instances, the individuals who unlawfully accessed the Victim Accounts were able to add a new payment method on the account, deposit $5 into that account through the new payment method to verify that method, and then withdraw all the existing funds in the Victim Account through the new payment method (i.e., to a newly added financial account belonging to the hacker), thus stealing the funds in the Victim Accounts. Using this method, GARRISON and others stole approximately $600,000 from approximately 1,600 Victim Accounts on the Betting Website. Law enforcement executed a search on GARRISON’s home in February 2023. In that search, they located programs typically used for credential stuffing attacks. Those programs require individualized “config” files for a target website to launch credential stuffing attacks, and law enforcement located approximately 700 such config files for dozens of different corporate websites on GARRISON’s computer. Law enforcement also located files containing nearly 40 million username and password pairs on GARRISON’s computer, which are also used in credential stuffing attacks. On GARRISON’s cellphone, law enforcement also located conversations between GARRISON and his co-conspirators, including discussions about how to hack the Betting Website and how to profit from the hack of the Betting Website by extracting funds from the Victim Accounts directly or by selling access to the Victim Accounts. In one particular conversation, GARRISON discussed, in substance and in part, how successful he was at credential stuffing attacks, how much he enjoyed credential stuffing attacks, and how GARRISON believed that law enforcement would not catch or prosecute him. Specifically, GARRISON messaged the following, in substance and in part: “fraud is fun . . . im addicted to see money in my account . . . im like obsessed with bypassing shit.” * * * In addition to the prison term, GARRISON, 19, of Madison, Wisconsin, was sentenced to 3 years of supervised release and ordered to pay $175,019.11 in forfeiture and $1,327,061 in restitution. Mr. Williams praised the outstanding work of the Federal Bureau of Investigation. Mr. Williams also thanked the New York City Police Department for its assistance in the investigation. The case is being prosecuted by the Office’s Complex Frauds and Cybercrime Unit. Assistant U.S. Attorneys Kevin Mead and Micah Fergenson are in charge of the prosecution. Contact Nicholas Biase, Lauren Scarff (212) 637-2600 Updated January 31, 2024 Topic Cybercrime Component USAO - New York, Southern Press Release Number: 24-038