logo

Roku forcing 2-factor authentication after 2 breaches of 600K accounts

ID: d0683b96-725c-5c9d-b172-572c5e0ca91b

STIX ID: report--d0683b96-725c-5c9d-b172-572c5e0ca91b

Feed Name: Ars Technica Security

Threat Score
50/100

Date Published: 2024-04-19

Date Updated: 2026-04-19

Author: Kevin Purdy

...
...

Roku disclosed two credential-stuffing incidents that collectively impacted about 591,000 customer accounts (approximately 15,000 in an initial incident and 576,000 discovered subsequently). Attackers accessed stored payment methods and made under 400 unauthorized purchases; Roku says full card numbers were not exposed and will require two-factor authentication to prevent future account takeovers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.