Roku Reports Cyber Breach Of Over Half A Million Accounts

Compromised data was used to make unauthorized purchases in fewer than 400 cases

clock • 3 min read
Roku Reports Cyber Breach Of Over Half A Million Accounts

Roku, a leading streaming service provider, has warned 576,000 of its users that their accounts have been compromised in a cyber breach discovered during an ongoing investigation into a previous intrusion from March.

Rather than directly compromising Roku's network through a security flaw, the hackers employed a "credential-stuffing" attack, the company said.

This technique involves hackers using previously leaked usernames and passwords to gain unauthorized access to user accounts, particularly when users use the same credentials across multiple platforms.

Roku said there is no evidence indicating it was the source of the account credentials used in these attacks, and that neither of Roku's systems were compromised in either incident.

Despite the scale of the breach, the company assured its users that the hackers did not manage to access any sensitive data such as full credit card numbers or other payment details. However, the company did acknowledge that in fewer than 400 cases, the compromised data was used to make unauthorized purchases of hardware products and streaming service subscriptions.

The purchases were made using the payment methods stored in the affected accounts.

In response to the breach, Roku says it has taken steps to address the situation. The company has committed to refunding or reversing charges for the accounts where unauthorized purchases were made as a result of the attack.

As a precautionary measure, the company has reset the passwords for the affected accounts and is rolling out two-factor authentication across all user accounts to enhance security measures.

According to BleepingComputer, threat actors are employing credential stuffing technique using tools like Open Bullet 2 or SilverBullet to breach Roku accounts. These hacked accounts are subsequently sold for as little as $0.50 in illegal online marketplaces.

The sellers also provide instructions on how to use the stolen accounts for unauthorized purchases.

Roku, which boasts more than 80 million active accounts, has advised its users to create unique and strong passwords for their accounts and to enable two-factor authentication as an additional layer of security.

Cybersecurity experts have often warned against the dangers of using the same credentials across different platforms, emphasizing the importance of using unique passwords for each online account to minimize the risk of unauthorized access.

Roku provides a variety of streaming devices, home automation kits, sound bars, and various other products powered by its specialized operating system, allowing users to access services such as Netflix, Amazon Prime Video, and Hulu.

To generate revenue, Roku permits customers to buy streaming subscriptions directly via their Roku account, consolidating all their streaming services into one account. Upon adding a subscription, Roku securely stores customers' credit card details in their online accounts to simplify future purchases.

Last month, Roku disclosed another data breach impacting more than 15,000 customers, amid reports that compromised accounts were being sold for as little as $0.50 each.

At that time, Roku said it had secured the affected accounts and initiated a password reset as soon as the breach was detected.

This article originally appeared on our sister site Computing.

You may also like
Access Point: Weekly News Roundup For IT Executives – May 17, 2024

Column

Access Point is a weekly roundup of major tech news for IT executives on the go. This edition covers May 13-May 17.

clock 05-17-2024 • 2 min read
Microsoft May Patch Tuesday Fixes Two Actively Exploited Zero Days

Software

An expert called one of the vulnerabilities a "vital security threat"

clock 05-15-2024 • 3 min read
4 Announcements From Google I/O 2024 That Midmarket IT Leaders Should Know

Software

Yes, much of the keynote was focused on AI -- but with some cool features

clock 05-14-2024 • 2 min read

More on Security

Countries With The Highest Cyber Threat Risk And Ones With The Lowest: Report

Countries With The Highest Cyber Threat Risk And Ones With The Lowest: Report

Samara Lynn
clock 05-16-2024 • 4 min read
CISOs Call To Ditch The 'Stigma Of Blame' In Cybersecurity

CISOs Call To Ditch The 'Stigma Of Blame' In Cybersecurity

Ditching ‘Humans are the weakest link’

Tom Allen
clock 05-13-2024 • 2 min read
LockBit Leader Unmasked

LockBit Leader Unmasked

Named as Russian national Dmitry Khoroshev

clock 05-08-2024 • 3 min read