Roku sign on building

iStock.com/Michael Vi

Roku Hit by Cyberattack: Over Half a Million Accounts Breached

April 12, 2024

On Friday, Roku disclosed that approximately 576,000 user accounts were compromised in a recent cyberattack, marking the second security breach this year.

According to a blog post by Roku, hackers managed to infiltrate user accounts by utilizing stolen login credentials. The breach came to light during account monitoring after a cyberattack that impacted 15,000 accounts earlier in the year.

The method employed by the hackers is known as credential stuffing, where they exploit leaked login and password information from one data breach across multiple accounts. This underscores the importance of using unique passwords for each online account, as suggested by experts.

Roku clarified that the compromised credentials were likely obtained from a separate data breach on another platform, absolving Roku’s systems of any direct compromise.

While the hackers managed to access fewer than 400 accounts to make purchases on streaming services and Roku products, Roku assured users that sensitive financial information remained secure. The company is in the process of reversing charges and refunding affected accounts.

As a precautionary measure, Roku has automatically reset user passwords and plans to reach out to affected users directly.

In response to the security breach, Roku announced the implementation of two-factor authentication across all accounts. This additional security step will require users to confirm logins on a secondary device.

“We sincerely regret that these incidents occurred and any disruption they may have caused. Your account security is a top priority, and we are committed to protecting your Roku account,” the company said. However, the announcement has had a negative impact on Roku’s stock, with a nearly 3% decline since the breach was disclosed.

For users keen on enhancing their account security, Roku advised creating unique passwords comprising a mix of letters, symbols, and numbers. Additionally, users should remain vigilant against internet scams, phishing emails, and suspicious requests for login or financial information.

Roku users are encouraged to periodically review account activity for any unauthorized purchases or subscriptions.

Recent News