Jump to content

Roku 2024 credential-stuffing data breaches

From Consumer Rights Wiki

In 2024, Roku disclosed two credential stuffing data breaches that exposed 15,363 and then more than 576,000 customer accounts to takeover.[1][2] Attackers changed the login details on hijacked accounts and used the stored payment methods to make fraudulent purchases, and the accounts were resold on stolen-account marketplaces for as little as 50 cents each.[1] The first incident was disclosed in early March 2024 and the second on April 12, 2024.[1][2] Roku said fewer than 400 accounts saw unauthorized purchases and that full credit-card numbers were not exposed, and it enabled two-factor authentication for all accounts after the second incident.[2]

The breaches

[edit | edit source]

The breaches were the result of credential stuffing, a technique in which attackers try username and password pairs stolen from unrelated third-party breaches against a target site.[1][2] Roku's accounts store customers' credit-card information so it can be reused for future purchases, and at the time of the first breach Roku did not offer two-factor authentication.[1]

First disclosure (March 2024)

[edit | edit source]

In a breach notice filed with the offices of the Maine and California Attorneys General, Roku said its security team detected the intrusion between January 4 and February 21, 2024, and determined that unauthorized actors had accessed accounts between December 28, 2023, and February 21, 2024; the Maine filing put the number affected at 15,363 customers.[3]

Once an account was taken over, the attackers could change its password, email address, and shipping address, which locked out the legitimate owner and let the attackers use stored credit-card information to make purchases without the owner receiving order-confirmation emails.[1] BleepingComputer reported that hijacked Roku accounts were sold on stolen-account marketplaces for as little as 50 cents each, and that buyers used the stored cards to purchase cameras, remotes, soundbars, and streaming boxes.[1]

Second disclosure (April 2024)

[edit | edit source]

On April 12, 2024, Roku disclosed a second, larger breach affecting more than 576,000 accounts, again through credential stuffing.[2][4] Roku said that across the two incidents there were fewer than 400 cases in which attackers made unauthorized purchases of streaming subscriptions and Roku hardware, and that the attackers did not gain access to full credit-card numbers or other full payment information.[2]

Roku's response

[edit | edit source]

Roku said it secured the affected accounts, forced a password reset, and moved to cancel fraudulent subscriptions and refund affected account holders.[1] After the second incident, Roku enabled two-factor authentication for all accounts, including those not affected by either breach.[2][4]

Timing relative to the forced-arbitration terms change

[edit | edit source]

The breaches overlapped with Roku's rollout of updated Dispute Resolution Terms, which took effect on February 20, 2024, and began appearing on devices as an accept-only notice in early March 2024.[5] On March 11, 2024, BleepingComputer reported that a source told it the new terms were in part related to the ongoing credential-stuffing attacks and financial fraud; after the article was published, Roku disputed this and stated that the new terms were not related to the hacked accounts.[1] Writing about the terms change, Gizmodo's Lucas Ropek said that, for companies, the benefit of forced arbitration is that they can avoid class-action lawsuits.[6]

See also

[edit | edit source]

References

[edit | edit source]
  1. 1.0 1.1 1.2 1.3 1.4 1.5 1.6 1.7 1.8 Toulas, Bill (2024-03-11). "Over 15,000 hacked Roku accounts sold for 50¢ each to buy hardware". BleepingComputer. Retrieved 2026-08-24.
  2. 2.0 2.1 2.2 2.3 2.4 2.5 2.6 Suarez Sang, Lucia (2024-04-12). "Roku says 576,000 streaming accounts compromised in recent security breach". CBS News. Archived from the original on 2024-04-13. Retrieved 2026-08-24.
  3. Hope, Alicia (2024-03-22). "Roku Data Breach: Over 15,000 Affected and Stored Credit Cards Used for Unauthorized Purchases". CPO Magazine. Retrieved 2026-08-24.
  4. 4.0 4.1 Paganini, Pierluigi (2024-04-12). "Roku disclosed a new security breach impacting 576,000 accounts". Security Affairs. Retrieved 2026-08-24.
  5. Coldewey, Devin (2024-03-05). "Roku disables TVs and streaming devices until users consent to new terms". TechCrunch. Retrieved 2026-08-24.
  6. Ropek, Lucas (2024-03-06). "Roku Will Bork Your TV Unless You Promise Not to Sue". Gizmodo. Retrieved 2026-08-24.