Header image

Roku Detects 600,000 Impacted in Credential Stuffing Attacks

Unauthorised actors accessed about 600,000 user accounts using credential stuffing attacks.


Streaming service Roku has reported that unauthorised actors accessed about 600,000 user accounts using credential stuffing attacks.

Using stolen usernames and passwords from one platform, and attempting to log in to accounts on other platforms, two incidents were identified - one impacting around 15,000 user accounts, and another of 576,000.

Roku concluded that there was no data security compromise within its systems, that Roku was not the source of the account credentials used in these attacks, and in fewer than 400 cases, malicious actors logged in and made unauthorised purchases of streaming service subscriptions and Roku hardware products using the payment method stored in these accounts.

However Roku’s monitoring determined that attackers did not gain access to any sensitive information, including full credit card numbers or other full payment information.

Roku said it has more than 80M active accounts, so those impacted “represents a small fraction” of its user base.

“We sincerely regret that these incidents occurred and any disruption they may have caused,” its statement read. “Your account security is a top priority, and we are committed to protecting your Roku account.” 


Dan Raywood Senior Editor SC Media UK

Dan Raywood is a seasoned B2B journalist with over 20 years of experience, specializing in cybersecurity for the past 15 years. He has extensively covered topics from Advanced Persistent Threats and nation-state hackers to major data breaches and regulatory changes. Outside work, Dan enjoys supporting Tottenham Hotspur, managing mischievous cats, and sampling craft beers.

Dan Raywood Senior Editor SC Media UK

Dan Raywood is a seasoned B2B journalist with over 20 years of experience, specializing in cybersecurity for the past 15 years. He has extensively covered topics from Advanced Persistent Threats and nation-state hackers to major data breaches and regulatory changes. Outside work, Dan enjoys supporting Tottenham Hotspur, managing mischievous cats, and sampling craft beers.

Upcoming Events

08
Aug
Webinar

How to Automate the Lifecycle of Joiners, Movers, and Leavers With No-Code Solutions

Streamlining the lifecycle of joiners, movers, and leavers using no-code automation

The process of onboarding new employees and quickly removing departing staff profiles can be both time-consuming and labour-intensive.
In this live webinar, we will look at how to streamline these processes to save time and resources, and providing a smooth experience for both admins and employees.

Key takeaways:
  • Understanding the importance of securing the joiners, movers and leavers process
  • Exploring successful attacks that occurred due to errors in managing these transitions
  • Discover which advanced controls can be utilized
image image image