
The Disney+ streaming service has only been available for a few days, but it has already attracted attention, and this is not only due to its programs and the great response from the audience. As we reported a few days ago, some hackers breached users' Disney+ accounts and are now selling the credentials on underground hacking forums .
The company said yesterday that no evidence of a system breach was found and that the accounts exposed belong to a very small number of Disney+ users
The Disney+ service managed to reach 10 million subscribers from the first day of launch.
Hackers took advantage of the service's popularity and targeted users . According to researchers, user credentials are being sold on hacking forums for between $3 and $11. Meanwhile, a subscription costs $7 per month or $70 per year.
Disney claims the breach was caused by specific users not taking security. Many users use the same password across multiple services. This means that a breach of one account allows hackers to gain access to other user accounts. Disney believes that is what happened in this case.
However, it is easy to avoid such situations by using unique and strong passwords. This is the advice given by all security experts, as well as Troy Hunt, an Australian researcher who has created the site “Have I Been Pwned?”This site notifies people when their data has been compromised.
However, Hunt said that Disney, for its part, could implement some better security measures.

“The Disney situation appears to be another case of a credential stuffing attack, where hackers exploit password reuse combined with inadequate defensesput in place by the service provider,” Hunt said.
Paul Rohmeyer, a professor at Stevens Institute of Technology in Hoboken, New Jersey, said he was surprised that streaming services did not implement effective security measures, such as multi-factor authentication.
With this method, when users try to log in to account from a new device, they receive a code via text or email , which they must use to gain access. This means that if a hacker has stolen a user's credentials, they cannot continue the process because they do not have this code.
The researcher believes that services may be hesitant to implement stricter security measures because they fear they will be seen as "more intrusive" than competitors.
However, security is more important and should be a concern for all services. Disney+ has not implemented multi-factor authentication, which requires a unique code every time a new device.
Of course, the greatest responsibility lies with the users themselves who do not adequately protect their accounts and use the same passwords. However, the services must also take security measures to limit the chances of a breach.
