X

Roku Discloses Data Breach Incident Affecting 576,000 Users

Here's what to know about the newly announced security breach.

Meara Isenberg Writer
Meara covers streaming service news for CNET. She recently graduated from the University of Texas at Austin, where she wrote for her college newspaper, The Daily Texan, as well as for state and local magazines. When she's not writing, she likes to dote over her cat, sip black coffee and try out new horror movies.
Meara Isenberg
2 min read
image-from-ios
Eli Blumenthal/CNET

More Roku customers have been affected by a second data breach at the company, Roku said Friday. The streaming brand disclosed a breach affecting 576,000 user accounts, which follows another recently unearthed incident involving 15,000 accounts.

In response to the new breach, Roku has enabled two-factor authentication for all Roku accounts, according to a blog post. The company said it's notifying affected users and has already reset their passwords. 

Roku said with both breaches, login credentials used in the attacks likely came from outside sources, such as a web account where a user employed the same credentials. The company said "there is no indication" its systems were compromised.

A small number of customers were affected by unauthorized transactions, however. "In less than 400 cases," Roku said, "malicious actors logged in and made unauthorized purchases of streaming service subscriptions and Roku hardware products using the payment method stored in these accounts, but they did not gain access to any sensitive information, including full credit card numbers or other full payment information." The company is reversing or refunding the unauthorized charges.

Roku has more than 80 million active accounts and provides streaming media players, smart TVs and a streaming platform that lets customers access apps such as Netflix and Disney Plus. As part of the new two-factor authentication, users must click a verification link sent to their email the next time they try to log in to their Roku account. The company is urging users to use strong, unique passwords and to look out for suspicious communications that claim to be from Roku. (Here's more on how to keep your passwords safe and secure.)