Plex Forums Hacked – Private Messages Exposed
Registered users of the Plex Forums have received an email from the company informing them of the breach in which personal dataassociated with their accounts has been exposed.
The official message instructs users to change their passwords, even if they have stored them in encrypted form (hashed and salted) and therefore there is a small chance that the text can be recovered.

Change your password on Plex
"Unfortunately, we were notified this afternoon that the server hosting our forums and blogs has been compromised. The investigation is ongoing, and as far as we know the attacker only gained access to these parts of our systems," their message reads.
Customers who made payments were assured that their card information was safe and not exposed because this type of data is not stored on Plex servers.
Forum users were most affected, with their IP addresses, private messages and email addresses exposed. A company representative said the investigation is ongoing, but the vulnerability exploited was likely PHP/IPB.
Finally, they advise all users to always choose strong passwords, never share them in any way with third parties, and of course not use the same password on different pages/accounts.
The hacker is demanding a ransom
A Reddit post, allegedly by the attacker, claimed that Plex had until tomorrow to pay him 9.5 bitcoins (currently $2,427/ €2,190) or user data would be leaked into the public domain. If the ransom was not paid by July 3, the attacker said the reward would increase to 14.5 bitcoins (currently $3,705/ €3,340).
Finally, he stated that it does not matter who pays the ransom, and even the users themselves have the option of paying in exchange for the removal of their data from the leaked database
