Current:Home > InvestRoku says 576,000 streaming accounts compromised in recent security breach -AssetTrainer
Roku says 576,000 streaming accounts compromised in recent security breach
View
Date:2025-04-14 06:04:20
Just weeks after a security hack exposed more than 15,000 Roku accounts, the company said Friday that a second security breach impacted more than 576,000 accounts.
In a statement on its website, the company said it found no evidence that it was the source of the account credentials used in either of the attacks or that Roku's systems were compromised. Instead, the company said, login credentials used in the hacks were likely stolen from another source for which the affected users may have used the same username and password. This type of cyberattack is known as "credential stuffing."
Roku said in fewer than 400 cases, the "malicious actors logged in and made unauthorized purchases of streaming service subscriptions and Roku hardware producing using the payment store in these accounts, but they did not gain access to any sensitive information, including full credit card numbers or other full payment information."
The company said it reset the passwords for all affected accounts and notified those customers directly about the incident. It is refunding or reversing charges in the accounts that purchases made by unauthorized actors.
In addition, the company also enabled two-factor authentication for all Roku accounts, even those that have not been impacted by either security incident They said account holders should be aware that the next time they log into the Roku account online, a verification link will be sent to the associated email.
"While the overall number of affected accounts represents a small fraction of Roku's more than 80 (million) active accounts, we are implementing a number of controls and countermeasures to detect and deter future credential stuffing incidents," the company said.
Roku encouraged users to create a "strong, unique password" for their account and also advised them to "remain vigilant," being alert to any "suspicious communications appearing to come from Roku, such as requests to update your payment details, share your username or password, or click on suspicious links."
"We sincerely regret that these incidents occurred and any disruption they may have caused," the company said. "Your account security is a top priority, and we are committed to protecting your Roku account."
This is the second Roku breach in recent months. In March, Roku said hackers accessed more than 15,000 user accounts.
- In:
- Technology
- Cyberattack
Lucia Suarez Sang is an associate managing editor at cbsnews.com. Previously, Lucia was the director of digital content at FOX61 News in Connecticut and has previously written for outlets including FoxNews.com, Fox News Latino and the Rutland Herald.
TwitterveryGood! (6468)
Related
- Selena Gomez's "Weird Uncles" Steve Martin and Martin Short React to Her Engagement
- What is CrowdStrike, the cybersecurity company behind the global Microsoft outages?
- Nevada judge who ran for state treasurer pleads not guilty to federal fraud charges
- To test the Lotus Emira V-6, we first battled British build quality
- Which apps offer encrypted messaging? How to switch and what to know after feds’ warning
- Churchill Downs lifts suspension of trainer Bob Baffert following Medina Spirit’s failed drug test
- Indianapolis anti-violence activist is fatally shot in vehicle
- In a California gold rush town, some Black families are fighting for land taken from their ancestors
- Rolling Loud 2024: Lineup, how to stream the world's largest hip hop music festival
- U.S. journalist Evan Gershkovich's trial resumes in Russia on spying charges roundly denounced as sham
Ranking
- The Best Stocking Stuffers Under $25
- Country Singer Rory Feek Marries Daughter's Teacher 8 Years After Death of Wife Joey
- CrowdStrike CEO George Kurtz Apologizes Amid Massive Tech Outage
- CrowdStrike CEO George Kurtz Apologizes Amid Massive Tech Outage
- Behind on your annual reading goal? Books under 200 pages to read before 2024 ends
- Paris Olympics see 'limited' impact on some IT services after global tech outage
- Twisters' Daisy Edgar Jones Ended Up in Ambulance After Smoking Weed
- RHOBH's Kyle Richards Seemingly Reacts to Mauricio Umansky Kissing New Woman
Recommendation
Backstage at New York's Jingle Ball with Jimmy Fallon, 'Queer Eye' and Meghan Trainor
Christina Hall's HGTV Show Moving Forward Without Josh Hall Amid Breakup
Adidas Apologizes for Bella Hadid Ad Campaign Referencing 1972 Munich Olympics
Cardi B slams Joe Budden for comments on unreleased album
What do we know about the mysterious drones reported flying over New Jersey?
Political divisions stall proposed gun policies in Pennsylvania, where assassin took aim at Trump
Drone strike by Yemen’s Houthi rebels kills 1 person and wounds at least 10 in Tel Aviv
Nevada judge who ran for state treasurer pleads not guilty to federal fraud charges