Current:Home > NewsRoku says 576,000 streaming accounts compromised in recent security breach -AssetVision
Roku says 576,000 streaming accounts compromised in recent security breach
View
Date:2025-04-16 03:22:52
Just weeks after a security hack exposed more than 15,000 Roku accounts, the company said Friday that a second security breach impacted more than 576,000 accounts.
In a statement on its website, the company said it found no evidence that it was the source of the account credentials used in either of the attacks or that Roku's systems were compromised. Instead, the company said, login credentials used in the hacks were likely stolen from another source for which the affected users may have used the same username and password. This type of cyberattack is known as "credential stuffing."
Roku said in fewer than 400 cases, the "malicious actors logged in and made unauthorized purchases of streaming service subscriptions and Roku hardware producing using the payment store in these accounts, but they did not gain access to any sensitive information, including full credit card numbers or other full payment information."
The company said it reset the passwords for all affected accounts and notified those customers directly about the incident. It is refunding or reversing charges in the accounts that purchases made by unauthorized actors.
In addition, the company also enabled two-factor authentication for all Roku accounts, even those that have not been impacted by either security incident They said account holders should be aware that the next time they log into the Roku account online, a verification link will be sent to the associated email.
"While the overall number of affected accounts represents a small fraction of Roku's more than 80 (million) active accounts, we are implementing a number of controls and countermeasures to detect and deter future credential stuffing incidents," the company said.
Roku encouraged users to create a "strong, unique password" for their account and also advised them to "remain vigilant," being alert to any "suspicious communications appearing to come from Roku, such as requests to update your payment details, share your username or password, or click on suspicious links."
"We sincerely regret that these incidents occurred and any disruption they may have caused," the company said. "Your account security is a top priority, and we are committed to protecting your Roku account."
This is the second Roku breach in recent months. In March, Roku said hackers accessed more than 15,000 user accounts.
- In:
- Technology
- Cyberattack
Lucia Suarez Sang is an associate managing editor at cbsnews.com. Previously, Lucia was the director of digital content at FOX61 News in Connecticut and has previously written for outlets including FoxNews.com, Fox News Latino and the Rutland Herald.
TwitterveryGood! (6447)
Related
- IRS recovers $4.7 billion in back taxes and braces for cuts with Trump and GOP in power
- Sports Illustrated Resorts are coming to the US, starting in Tuscaloosa, Alabama
- Tuberville tries to force a vote on single military nomination as he continues blockade
- Syrian President Bashar Assad arrives in China on first visit since the beginning of war in Syria
- 2025 'Doomsday Clock': This is how close we are to self
- Pilot killed when crop-dusting plane crashes in North Dakota cornfield, officials say
- Japan’s troubled Toshiba to delist after takeover by Japanese consortium succeeds
- Malaria is on the ropes in Bangladesh. But the parasite is punching back
- Federal Spending Freeze Could Have Widespread Impact on Environment, Emergency Management
- Japanese crown prince begins Vietnam visit, marking 50 years of diplomatic relations
Ranking
- Highlights from Trump’s interview with Time magazine
- She has Medicare and Medicaid. So why should it take 18 months to get a wheelchair?
- 'Sex Education' Season 4: Cast, release date, how to watch final episodes of Netflix show
- What Ariana Grande Is Asking for in Dalton Gomez Divorce
- Macy's says employee who allegedly hid $150 million in expenses had no major 'impact'
- Why the power of a US attorney has become a flashpoint in the Hunter Biden case
- White supremacist pleads guilty to threatening jurors, witnesses in Pittsburgh synagogue shooting trial
- Google sued for negligence after man drove off collapsed bridge while following map directions
Recommendation
Off the Grid: Sally breaks down USA TODAY's daily crossword puzzle, Hi Hi!
A helicopter, a fairy godmother, kindness: Inside Broadway actor's wild race from JFK to Aladdin stage
Democrats want federal voting rights bill ahead of 2024 elections
What Biden's support for UAW strike says about 2024 election: 5 Things podcast
Jamie Foxx gets stitches after a glass is thrown at him during dinner in Beverly Hills
DJ Khaled Reveals How Playing Golf Has Helped Him Lose Weight
Russell Brand faces sexual assault claim dating to 2003, London police say
Attorney General Merrick Garland says no one has told him to indict Trump