2024 Credential stuffing — 576k accounts
Data compromised
Account credentials; unauthorized purchases in some cases
Technical writeup
Roku disclosed two incidents: 576,000 accounts compromised in April plus 15,000 in March. Attackers used credential stuffing with credentials from other breaches. In fewer than 400 cases, attackers made unauthorized purchases. Roku reset passwords and implemented mandatory 2FA.
Root cause
Credential stuffing; password reuse from other breaches.