Credential theft

Roku credential stuffing attack (576,000 accounts)

πŸ“… 2024-03-01 🏒 Roku streaming platform
Primary Source β†—

Incident Details

Second Roku credential stuffing incident of 2024 (first: ~15,000 accounts in March). Attackers used username/password pairs from prior unrelated breaches to authenticate against Roku accounts. 576,000 accounts compromised. In fewer than 400 cases, attackers used stored payment methods to purchase streaming subscriptions and Roku hardware. Full credit card numbers not accessible. Roku enabled mandatory two-factor authentication for all 80 million user accounts in response. Roku stated its systems were not breached β€” credentials came from third-party data.

Technical Details

Initial Attack Vector
CWE-307: Improper Restriction of Excessive Authentication Attempts (credential stuffing using credentials stolen from third-party breaches)
Vendor / Product
Roku streaming platform

Timeline

  1. 2024-03-01 Breach occurred
  2. 2024-04-12 Publicly disclosed
  3. 2024-04-12 Customers notified