logo

Roku Mandates 2FA for Customers After Credential-Stuffing Compromise

ID: 53a5fa47-c613-59b0-addc-0afb30a58e98

STIX ID: report--53a5fa47-c613-59b0-addc-0afb30a58e98

Feed Name: Dark Reading

Threat Score
55/100

Date Published: 2024-04-15

Date Updated: 2026-04-21

Author: Dark Reading Staff

...
...

Roku experienced two credential-stuffing incidents that affected approximately 591,000 accounts; attackers used compromised logins to make purchases on about 400 accounts. Roku has reset passwords for affected users, mandated two-factor authentication for all accounts, reimbursed victims for unauthorized charges, and reported that full credit card numbers and highly sensitive personal data were not exposed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.