Roku has been hit by cyber hackers who gained access to 15,363 accounts and took usernames and passwords that customers also used on other websites, the TV streaming platform recently disclosed.
The breach, reported on March 8, occurred between December 28, 2023 and February 21, according to a disclosure notice with the Maine Attorney General's Office.
Roku said it has already reset the account passwords of those affected by the cyber attack, but encourages users to also take the following steps:
What to do
- Review the subscriptions and the devices linked to your account, which you can view on your account dashboard.
- Always use a strong, unique password for each of your online accounts. For more information, visit Roku's how to create a strong and secure password for your account site.
- Regularly review statements from your account and obtain your credit report from one or more of the national credit reporting companies. You can obtain a free copy of your credit report online at www.annualcreditreport.com or by calling toll-free 1-877-322-8228.
Hackers tried to buy subscriptions
The breach is the latest in a long line of cyber attacks on businesses and follows a massive breach at 23andMe last December. The breach at the genetic testing company also involved hacks of accounts in which customers used the same passwords and usernames from other websites.
Experts warn customers to change their passwords often and don't use the same ones across accounts.
In a March 8 letter sent to users, Roku said that it observed suspicious activity "indicating that certain individual Roku accounts may have been accessed by unauthorized actors.”
After an investigation, Roku found that unauthorized actors likely obtained the usernames and passwords of subscribers from third-party sources, such as data breaches of other services that those subscribers use, and then used those same logins and passwords to gain access to Roku accounts.
“After gaining access, they then changed the Roku login information for the affected individual Roku accounts and, in a limited number of cases, attempted to purchase streaming subscriptions,” Roku said. “However, access to the affected Roku accounts did not provide the unauthorized actors with access to social security numbers, full payment account numbers, dates of birth, or other similar sensitive personal information requiring notification.”
To reset your Roku account, go to my.roku.com and use the “forgot password?” option on the sign-in page.
Roku users with any questions about the incident are encouraged to contact Roku at 1-816-272-8106 or by email at account-help@roku.com.
For more information regarding warning signs of identity theft, how to report identity theft and how to protect yourself, visit USA.gov’s Identity Theft webpage.