Roku warns that 576,000 accounts were compromised in new credential stuffing attacks , about a month after announcing a similar incident (fewer accounts were compromised at the time).

According to the company, the attackers used login credentials stolen from other online platforms to compromise active Roku accounts . Unfortunately, many users still use the same passwords across different accounts. In credential stuffing attacks, like the one that targeted Roku, attackers leverage automated tools to attempt millions of logins using a list of username/password pairs that have been leaked online from past breaches. The technique is particularly effective when users reuse the same login information across multiple platforms.
See also: PetSmart: Warns customers about credential stuffing attack
“ After completing our investigation into the first incident, we continued to [..] closely monitor account activity and identified a second incident, which impacted approximately 576,000 additional accounts ,” Roku said on Friday
The company stressed that it has found no evidence to prove that the company itself was compromised to carry out these credential stuffing attacks.
“In fewer than 400 cases, malicious actors logged in and made unauthorized purchases of streaming service subscriptions and Roku hardware productsusing the payment method stored on those accounts. However, they did not gain access to sensitive information, including full credit card numbers or other payment information.”“.
As BleepingComputer reported last month, threat are hacking Roku accounts and selling them on illegal marketplaces. The sellers are also providing information on how to use the stolen accounts to make fraudulent purchases, such as Roku streaming boxes, sound bars, light strips, etc.
See also: Jason's Deli: Customer data breach via credential stuffing

Password reset and 2FA
Following the discovery of new credential stuffing attacks that affected 576,000 accounts, Roku has reset passwords for all affected users.
The company will also refund and reverse charges for accounts used by the attackers to pay Roku products and streaming subscriptions.
Additionally, Roku has added support for two-factor authentication (2FA) and has enabled it by default for all customer accounts.
Users are also urged to choose strong and unique passwords . for their accounts. A strong password includes letters, numbers, and symbols
See also: PayPal: Accounts compromised through credential stuffing attack
To prevent similar credential stuffing attacks, Roku recommends using different passwords for different servicesso that all accounts cannot be accessed if one password is leaked.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Users are urged to notify Roku customer support if they receive strange requests to share credentials , update payment information, or click on suspicious links.
Finally, it is important to regularly check account activity.
Source: www.bleepingcomputer.com
