Current:Home > InvestRoku says 576,000 streaming accounts compromised in recent security breach -MarketStream
Roku says 576,000 streaming accounts compromised in recent security breach
View
Date:2025-04-24 21:45:59
Just weeks after a security hack exposed more than 15,000 Roku accounts, the company said Friday that a second security breach impacted more than 576,000 accounts.
In a statement on its website, the company said it found no evidence that it was the source of the account credentials used in either of the attacks or that Roku's systems were compromised. Instead, the company said, login credentials used in the hacks were likely stolen from another source for which the affected users may have used the same username and password. This type of cyberattack is known as "credential stuffing."
Roku said in fewer than 400 cases, the "malicious actors logged in and made unauthorized purchases of streaming service subscriptions and Roku hardware producing using the payment store in these accounts, but they did not gain access to any sensitive information, including full credit card numbers or other full payment information."
The company said it reset the passwords for all affected accounts and notified those customers directly about the incident. It is refunding or reversing charges in the accounts that purchases made by unauthorized actors.
In addition, the company also enabled two-factor authentication for all Roku accounts, even those that have not been impacted by either security incident They said account holders should be aware that the next time they log into the Roku account online, a verification link will be sent to the associated email.
"While the overall number of affected accounts represents a small fraction of Roku's more than 80 (million) active accounts, we are implementing a number of controls and countermeasures to detect and deter future credential stuffing incidents," the company said.
Roku encouraged users to create a "strong, unique password" for their account and also advised them to "remain vigilant," being alert to any "suspicious communications appearing to come from Roku, such as requests to update your payment details, share your username or password, or click on suspicious links."
"We sincerely regret that these incidents occurred and any disruption they may have caused," the company said. "Your account security is a top priority, and we are committed to protecting your Roku account."
This is the second Roku breach in recent months. In March, Roku said hackers accessed more than 15,000 user accounts.
- In:
- Technology
- Cyberattack
Lucia Suarez Sang is an associate managing editor at cbsnews.com. Previously, Lucia was the director of digital content at FOX61 News in Connecticut and has previously written for outlets including FoxNews.com, Fox News Latino and the Rutland Herald.
TwitterveryGood! (8)
Related
- Rylee Arnold Shares a Long
- TikTok, Snap, X and Meta CEOs grilled at tense Senate hearing on social media and kids
- Massachusetts turns recreational plex into shelter for homeless families, including migrants
- Pennsylvania automatic voter registration boosts sign-ups, but not a political party, data shows
- Whoopi Goldberg is delightfully vile as Miss Hannigan in ‘Annie’ stage return
- Michigan shooter's mom told police 'he's going to have to suffer' after school slayings
- Duchess Meghan, Prince Harry share emotional message after Senate hearing on online safety
- West Virginia construction firm to buy bankrupt college campus
- Federal hiring is about to get the Trump treatment
- Pearl Jam throws a listening party for their new album that Eddie Vedder calls ‘our best work’
Ranking
- Who are the most valuable sports franchises? Forbes releases new list of top 50 teams
- Duchess Meghan, Prince Harry share emotional message after Senate hearing on online safety
- Biden to celebrate his UAW endorsement in Detroit, where Arab American anger is boiling over Gaza
- Pennsylvania automatic voter registration boosts sign-ups, but not a political party, data shows
- The FBI should have done more to collect intelligence before the Capitol riot, watchdog finds
- Pearl Jam throws a listening party for their new album that Eddie Vedder calls ‘our best work’
- Russian court extends detention of Russian-US journalist
- You’ll Love Jessica Biel’s Birthday Tribute to Justin Timberlake—This We Promise You
Recommendation
New data highlights 'achievement gap' for students in the US
Mark Zuckerberg accused of having blood on his hands in fiery Senate hearing on internet child safety
Disney's free speech lawsuit against Gov. Ron DeSantis dismissed but second lawsuit still pending
From Zendaya to Simone Biles, 14 quotes from young icons to kick off Black History Month
Why Sean "Diddy" Combs Is Being Given a Laptop in Jail Amid Witness Intimidation Fears
Federal Reserve holds its interest rate steady. Here's what that means.
Inside Donald Trump’s curious relationship with Fox News — and what it means for other candidates
Meta CEO Mark Zuckerberg apologizes to parents of victims of online exploitation in heated Senate hearing