[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f4ixak1befrsh":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":31,"seoTitle":16,"seoTitleEn":32,"seoDescription":16,"seoDescriptionEn":33,"logoUrl":34,"isVerified":4,"isSensitive":4,"isSpamList":35,"isMalware":35,"company":36},"68e3266eda11adda4882539d","super-draft","SuperDraft Data Breach","superdraft","superdraft.io","2024-10-27T00:00:00.000Z","2025-01-12T05:43:05.000Z","2025-01-15T22:31:36.000Z","2026-07-18T23:58:48.437Z","Third party breach","",[],300187,"known",null,"unknown","High",[24,25,26,27,28,29,30],"Dates of birth","Email addresses","Geographic locations","Latitude and longitude pairs","Passwords","Purchases","Usernames","\u003Cp>The SuperDraft data breach is a security incident recorded in October 2024, affecting approximately 300,000 accounts. In the incident related to the fantasy sports platform, customer records, location fields, purchase information, and password hash values were exposed. This content has been prepared so that users can understand the scope of the incident, the exposed fields, the risk level, and the steps they need to take on a single page.\u003C\u002Fp>\u003Cp>The context of fantasy sports and betting-like rewarded games; when combined with location, purchase, and account access information, creates a high risk. The statement only includes verifiable data classes; different services with the same name, additional claims whose technical details are unclear, or information whose scope is unproven are not presented as a data field. This approach makes the real risk visible without misleading the user.\u003C\u002Fp>\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\u003Cp>The types of data listed in this incident are: birth dates, email addresses, geographic locations, latitude-longitude pairs, passwords, purchase information, and usernames. Latitude-longitude and purchase information can affect not only the user's account but also the context of their physical location and transaction history. When these fields are used together, they can lead to outcomes such as account takeover, social engineering, fraud, physical targeting, or privacy violations.\u003C\u002Fp>\u003Cp>It is understood that passwords are associated with bcrypt hash values; a strong hashing method reduces the risk, but the risk remains if there is password reuse. In records containing passwords, using the same or similar passwords on other services is one of the most critical risks. In records without passwords, fields such as device, location, phone, address, education, job application, or financial context can make targeted messages more convincing.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The record covers approximately 300,000 customer accounts associated with the domain superdraft.io. The incident is classified as a verified record. In the scope assessment, the number of accounts, domain, industry, country, and data classes were checked separately. The data fields shown to the user were limited to the fields actually listed within the record.\u003C\u002Fp>\u003Cp>The latitude-longitude field that was missing in the previous record has been added to the data classes. This boundary is especially important for similar brand names, records covering multiple services, or sensitive sectors. The record has not been merged with another event, has not been expanded in a way that would create duplicate records, and the company context has been clarified as much as possible.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>SuperDraft customers who use the same username on sports or gaming accounts and users with location information are at risk. The primary risk for these individuals is that leaked data can be matched with common information used on other accounts. When the same email address, phone number, username, device ID, or password is repeated, attackers may try these details on different services.\u003C\u002Fp>\u003Cp>The fantasy sports context can be exploited with fake reward, payment, redemption, or account verification messages. For corporate users, work email and task information stand out, while for individual users, address, date of birth, purchase, location, or membership context is highlighted. In areas such as education, telecommunications, finance, travel, politics, job applications, and VPNs, the context itself can also increase targeting risk.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Affected users should change their passwords, check their payment and purchase history, and examine whether there are any unknown sessions in their accounts. If the password or password-like field is listed, users should make changes on all accounts where they use the same password, use a unique password, and enable multi-factor authentication where possible. Operating on only a single platform may not be sufficient.\u003C\u002Fp>\u003Cp>If there are fields such as phone, address, date of birth, device ID, official ID, job application, or reward balance, users should check account recovery information, registered sessions, email forwarding, and suspicious messages. For institutions, processes should be updated against employee alerts, fake invoices, and account verification attempts.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>In sports and prize game accounts, location and payment data should be restricted if unnecessary, and account security should be regularly checked. In the long term, a password manager, unique passwords, multi-factor authentication, closing old accounts, deleting unnecessary profile fields, and data minimization form the basic security line. Since permanent personal data cannot be recovered, defense relies on strengthening account behavior.\u003C\u002Fp>\u003Cp>On the company and institutional side, post-incident inventory, access permissions, storage of old data, notification processes, and the use of third-party platforms should be reconsidered. On the user side, avoiding the repetition of the same identity information across different services and the habit of verifying suspicious communications through a secondary channel provide lasting protection.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>If the user matches this record, they should check all sports, gaming, and payment accounts where the same email-password pair is used. If a match is seen, the user should first read which data fields are listed, then prioritize the steps according to these fields. If there is a password, password change should be prioritized; if there is an official ID, ID monitoring; if there is location or device information, device security; if there is education or job application information, institutional account checks should be prioritized.\u003C\u002Fp>\u003Cp>Final assessment: This record has been classified as sensitive because it combines password, date of birth, purchase, and location fields. The user should compare this record with their account history; they should individually check the services where they use the same email, phone number, username, or password. Unexpected call, message, email, or account recovery notification should be considered higher risk after the incident.\u003C\u002Fp>","SuperDraft Data Breach (300.2 Thousand Reported Records)","SuperDraft Data Breach. 300.2 Thousand reported records were reported. Reported data: Dates of birth, Email addresses, Geographic locations. Review the scope…","\u002Fuploads\u002Flogo\u002Fsuperdraft_io.webp",false,{"name":37,"sector":38,"country":39,"website":10,"websiteArchiveUrl":16,"websiteStatus":16,"websiteCheckedAt":20},"SuperDraft","Fantasy Sports \u002F Daily Fantasy Sports","United States"]