Credential theft
Roku credential stuffing attack (576,000 accounts)
Primary Source βIncident Details
Second Roku credential stuffing incident of 2024 (first: ~15,000 accounts in March). Attackers used username/password pairs from prior unrelated breaches to authenticate against Roku accounts. 576,000 accounts compromised. In fewer than 400 cases, attackers used stored payment methods to purchase streaming subscriptions and Roku hardware. Full credit card numbers not accessible. Roku enabled mandatory two-factor authentication for all 80 million user accounts in response. Roku stated its systems were not breached β credentials came from third-party data.
Technical Details
- Initial Attack Vector
- CWE-307: Improper Restriction of Excessive Authentication Attempts (credential stuffing using credentials stolen from third-party breaches)
- Vendor / Product
- Roku streaming platform
Timeline
- 2024-03-01 Breach occurred
- 2024-04-12 Publicly disclosed
- 2024-04-12 Customers notified