Roku suffered another data breach, this time affecting 576,000 accounts

Roku has disclosed a second data breach in as many months. While it was looking into a previous incident in which 15,000 accounts were affected, the company learned that another 576,000 accounts had been compromised.

In both incidents, Roku believes that the attackers used a method called credential stuffing. "It is likely that login credentials used in these attacks were taken from another source, like another online account, where the affected users may have used the same credentials," the company says.

Roku added that, in fewer than 400 cases, attackers used victims' Roku accounts to buy streaming subscriptions and Roku devices using stored payment methods. However, the hackers did not gain access to full credit card numbers or other payment information.

The company has reset the passwords for all affected accounts and informed users who have been impacted. The company is also turning on two-factor authentication for its more than 80 million active accounts. The next time you log in, you'll get a verification email. You'll need to click a link in the email before you can access your account. Meanwhile, Roku says it's refunding or reversing charges in the cases where the hackers bought subscriptions or hardware.

While the impact of this latest breach doesn't seem too disastrous, it's a good reminder that you should have a strong, unique password for every single one of your accounts. A password manager makes it much easier to have robust login credentials, as you'll only need to remember one main password or log in using biometric data.

This article originally appeared on Engadget at https://www.engadget.com/roku-suffered-another-data-breach-this-time-affecting-576000-accounts-170442223.html?src=rss https://www.engadget.com/roku-suffered-another-data-breach-this-time-affecting-576000-accounts-170442223.html?src=rss
Created 2mo | Apr 12, 2024, 6:30:24 PM


Login to add comment

Other posts in this group

The ASUS ROG Ally X improves on the original in all the right ways

ASUS was the first major PC maker to try its hand at making a gaming handheld. And despite a few issues like a wonky microSD card reader, the

Jun 2, 2024, 9:30:46 AM | Engadget
You can now watch Godzilla Minus One at home on Netflix

Godzilla Minus One is now available to stream on Netflix, and the black-and-white version will soon follow. The streaming service announced the surprise release today, coinciding with the

Jun 1, 2024, 10:10:17 PM | Engadget
Netflix’s animated Tomb Raider series now has a release date

Tomb Raider: The Legend of Lara Croft is coming to Netflix on October 10. Netflix announced the release date today along with a new trailer, which finally gives us a slightly more in-depth

Jun 1, 2024, 10:10:16 PM | Engadget
Starliner’s first crewed flight gets scrubbed just before launch

The first crewed launch of Boeing’s Starliner capsule has once again been called off, this time after an automatic hold was issued by the ground launch sequencer less than four minutes before lifto

Jun 1, 2024, 5:40:09 PM | Engadget
This tool unlocks Windows' AI-powered Recall feature for unsupported PCs

During its Copilot AI and Surface event in May, Microsoft unveiled

Jun 1, 2024, 1:10:17 PM | Engadget
Meta says the future of Facebook is young adults (again)

When you think of the 20-year-old social network that is Facebook, its popularity among “young adults” is

May 31, 2024, 9:10:12 PM | Engadget
Engadget Podcast: MoviePass founder Stacy Spikes on the MovieCrash documentary

This week, Devindra and Engadget's Nathan Ingraham discuss the new Max documentary "MoviePass, MovieCrash" and reminisce about the early days of that wild startup. It was a huge mess in the end, bu

May 31, 2024, 6:50:23 PM | Engadget