The DraftSmarts User Database Quietly Appeared on the Dark Web in 2017
HEROIC analysts recieved intelligence on the DraftSmarts database through routine dark web monitoring in early 2017. The breach, dated January 4, 2017, affected 2,372 user accounts from draftsmarts.com, a sports fantasy drafting platform. Passwords in the database were protected with bcrypt hashing, which makes direct cracking difficult. The structured format of the exposed database indicates a deliberate extraction from the site's backend, and the data has since been seen in aggregated breach compilations traded across underground forums.
Why Fantasy Sports Account Data Attracts Attackers
Sports and fantasy gaming platforms collect more than just email addresses. They often store user preferences, connected social accounts, and payment-adjacent information. Even when passwords are well-protected, the email addresses tied to fantasy sports accounts can be used to target users on platforms where they may have used the same credentials. Attackers use these lists to run automated login attempts across banking apps, streaming services, and social media accounts, a method known as credential stuffing that is partcularly effective when users recycle passwords across sites.
What Was Exposed in the DraftSmarts Breach
- User account records (2,372 total)
- Email addresses
- Password hashes (bcrypt format)
- Account profile and registration data
Why This Matters for DraftSmarts Users
The risk from this breach is not immediate but it is real. Users who had accounts on DraftSmarts in 2017 and reused their password on other platforms face ongoing risk of account takeover. Even if the bcrypt hashes are not cracked, the email addresses in this database feed into large aggregated lists that power phishing campaigns, spam, and identity theft schemes. Financial fraud becomes easier when attackers can combine an email address from one breach with a password from another, a technique made possible by the scale of data available on underground markets.
How a Database Breach Works
A database breach occurs when an attacker gains unauthorized access to the server-side storage used by a website or application. This typically happens through known software vulnerabilities, misconfigured database settings, or stolen admin credentials. Once inside, the attacker exports the database file, which can contain thousands or millions of user records including emails, usernames, and hashed passwords. The exported data is then shared or sold on dark web forums, where it gets merged into larger datasets and resold repeatedly over time.
Check If Your Data Was Exposed
HEROIC provides a free breach scanner that searches across more than 400 billion records to determine whether your personal information has appeared in this breach or any other known incident. If you had an account on DraftSmarts or any sports fantasy platform, it takes just a moment to run a scan at HEROIC and see what information of yours may be circulating in criminal databases right now.
Breach Breakdown
2,372 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds