Roku Says 576,000 Streaming Accounts Compromised in Security Breach
Company resets passwords of affected users, implements two-factor authentication for all accounts following two hacking incidents

Following a hack that exposed more than 15,000 Roku accounts last month, the company said Friday it discovered a second security incident that affected 576,000 additional user accounts.
Roku said it reset the passwords for all affected accounts and are notifying those customers directly about the latest incident. According to the company, in fewer than 400 cases, “malicious actors” made unauthorized purchases of streaming service subscriptions and/or Roku hardware products using the payment method stored in these accounts. Roku said it refunding or reversing charges for accounts that were compromised and used to make illicit purchases.
Related Stories
VIP+How YouTube and Netflix Copied Each Other’s Homework

Emmys Producers Explain Why Jeremy Allen White Was Bleeped, Playing Off John Oliver During His Dog Tribute, That Awkward Johnnie Walker Ad and More
In addition, Roku said, it has enabled two-factor authentication (2FA) for all Roku accounts, even for those that were not been affected by the recent incidents. As a result, the next time users attempt to log in to their Roku account online, a verification link will be sent to the email address associated with the account; Roku users will then need to click the link in the email before they can access the account.
Popular on Variety
Roku said the hackers did not gain access to any sensitive personal information, including full credit card numbers or other payment information.
Roku said it found no evidence that it was the source of the account credentials used in either of the attacks or that Roku’s systems were compromised in either incident. According to the company, it’s likely that login credentials used in the hacks were stolen from another source (i.e. other online accounts) for which the affected users may have used the same username and password — a cyberattack known as “credential stuffing.”
“While the overall number of affected accounts represents a small fraction of Roku’s more than 80 million active accounts, we are implementing a number of controls and countermeasures to detect and deter future credential stuffing incidents,” the company said.
Roku encouraged users to create a “strong, unique password” for their account (using a mix of at least eight characters, including numbers, symbols and lowercase and uppercase letters). It also advised customers to “remain vigilant,” being alert to any “suspicious communications appearing to come from Roku, such as requests to update your payment details, share your username or password, or click on suspicious links.” The company also directed users to an article on its customer-support site, “How to keep your Roku account secure.”
“[W]e sincerely regret that these incidents occurred and any disruption they may have caused,” the company said. “Your account security is a top priority, and we are committed to protecting your Roku account.”
VIP+ Analysis: Did Sony Hack Teach Us Nothing on Cyberattacks?
Read More About:
Jump to CommentsMore from Variety

China Box Office: ‘Stand By Me’ Wins Muddled-up Mid-Autumn Holiday Weekend

New Live Music Data Suggests Cautious Optimism

China Box Office: Thai Comedy ‘How to Make Millions Before Grandma Dies’ Climbs to Third, as ‘Alien: Romulus’ Reaches $100 Million Milestone

China Box Office: ‘Stand by Me’ Retains Top Spot as ‘The Wild Robot’ Cranks Up Third Place

Netflix vs. YouTube: The Post-Streaming Wars Era’s Archrivalry

All ‘Harry Potter’ Movies to Get Theatrical Re-Releases in China (EXCLUSIVE)
Most Popular
Luke Bryan Reacts to Beyoncé’s CMA Awards Snub: ‘If You’re Gonna Make Country Albums, Come Into Our World and Be Country With…

Donald Glover Cancels 2024 Childish Gambino Tour Dates After Hospitalization: ‘I Have Surgery Scheduled and Need Time Out to Heal’

‘Joker 2’ Ending: Was That a ‘Dark Knight’ Connection? Explaining What’s Next for Joaquin Phoenix’s Joker

‘Love Is Blind' Creator Reveals Why They Didn’t Follow Leo and Brittany After Pods, if They'll Be at Reunion (EXCLUSIVE)

Coldplay’s Chris Martin Says Playing With Michael J. Fox at Glastonbury Was ‘So Trippy’: ‘Like Being 7 and Being in Heaven…

Rosie O'Donnell on Becoming a 'Big Sister' to the Menendez Brothers, Believes They Could Be Released From Prison in the ‘Next 30 Days’

Why Critically Panned ‘Joker 2’ Could Still Be in the Awards Race for Lady Gaga and Joaquin Phoenix

‘That ’90s Show’ Canceled After Two Seasons on Netflix, Kurtwood Smith Says: ‘We Will Shop the Show’

Charli XCX Reveals Features for ‘Brat’ Remix Album Include Ariana Grande, Julian Casablancas, Tinashe and More

Indian King of Comedy Kapil Sharma, Star of Busan Film ‘Zwigato,’ Takes On Global Streaming With Hit Netflix Show (EXCLUSIVE)

Must Read
- Film
COVER | Sebastian Stan Tells All: Becoming Donald Trump and Starring in 2024’s Most Controversial Movie
By Andrew Wallenstein 2 weeks
- TV
Menendez Family Slams Netflix’s ‘Monsters’ as ‘Grotesque’ and ‘Riddled With Mistruths’: ‘The Character Assassination of Erik and Lyke Is Repulsive…

- TV
‘Yellowstone’ Season 5 Part 2 to Air on CBS After Paramount Network Debut

- TV
50 Cent Sets Diddy Abuse Allegations Docuseries at Netflix: ‘It’s a Complex Narrative Spanning Decades’ (EXCLUSIVE)

- Shopping
‘Deadpool & Wolverine’ Sets Digital and Blu-ray/DVD Release Dates

Sign Up for Variety Newsletters
By providing your information, you agree to our Terms of Use and our Privacy Policy.We use vendors that may also process your information to help provide our services. // This site is protected by reCAPTCHA Enterprise and the Google Privacy Policy and Terms of Service apply.Variety Confidential
ncG1vNJzZmiukae2psDYZ5qopV9nfXOAjp2goKGklrlwusSwqmiqn6DCbrTAnKJmq5WYwrO107Jkm6qVlrCpeZRwbWloYGLAtb7EmqSippdirqSvzq6lratdZn90gZhvb3JsaWQ%3D