Roku disclosed credential stuffing attack affecting 15,363 accounts
- Organization
- Roku
- Exploit
- Credential Compromise
- Industry
- Streaming Media
Roku notified the attorneys general of Maine and California on March 8, 2024 that 15,363 customer accounts had been accessed without authorization, and began mailing notices to the affected users.
The company said the attackers used login credentials stolen in unrelated breaches of other online services and replayed them against Roku accounts, a technique known as credential stuffing. Roku detected the activity between January 4 and February 21, 2024, and determined that unauthorized access had occurred between December 28, 2023 and February 21, 2024. In many cases the intruders changed the account login details, locking the legitimate owners out.
In a limited number of accounts, the attackers used stored payment methods to purchase streaming subscriptions and Roku hardware. Roku said the intruders were not able to reach Social Security numbers, full payment card numbers or dates of birth. Coverage at the time noted that Roku did not then offer two factor authentication, and that access to hijacked accounts was being advertised on criminal markets for roughly 50 cents each.
Roku said it secured the affected accounts, forced password resets, investigated account activity, cancelled fraudulent subscriptions and refunded unauthorized charges. In April 2024 the company disclosed a second and larger credential stuffing incident affecting about 576,000 accounts, which it found while notifying victims of the first, and subsequently made two factor authentication mandatory for all users.
Sources
- Fox Business, Roku says over 15,000 accounts may have been accessed by bad actors in data breach incident
- Bitdefender HotforSecurity, Hackers target Roku: 15,000 accounts compromised in data breach
- Paubox, Roku: More than 15,000 accounts breached
- TechCrunch, Roku says 576,000 user accounts hacked after second security incident