Roku warns 576,000 accounts hacked in new credential stuffing attacks
ID: aaad637f-5b0f-5082-a397-eb421ec4be39
STIX ID: report--aaad637f-5b0f-5082-a397-eb421ec4be39
Feed Name: Bleeping Computer
Roku disclosed two waves of credential stuffing account takeover attacks—one impacting ~15,000 accounts and a subsequent incident affecting approximately 576,000 accounts—where attackers leveraged credential lists and automated cracking tools (OpenBullet 2/SilverBullet) to log into accounts, sell them on illicit marketplaces (as low as $0.50), and in under 400 cases make fraudulent purchases using stored payment methods; Roku reset affected passwords, enabled 2FA by default, and is refunding unauthorized charges.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
