
Roku, the popular streaming service, has disclosed a significant data breach affecting over half a million user accounts. This marks the platform’s second breach of the year, raising concerns about cybersecurity for its users.
According to a company blog post, hackers gained unauthorized access to Roku accounts using stolen login credentials. While attempting to exploit the breach, the perpetrators targeted less than 400 accounts to make purchases of subscription services. Fortunately, Roku reassured users that sensitive financial information was not compromised during the incident.
The recent breach follows an earlier security incident reported by Roku, where approximately 15,000 accounts were compromised due to a tactic known as "credential stuffing." This technique involves hackers using login information obtained from other sources unrelated to Roku, to gain unauthorized access to accounts.
Roku emphasized that there is no evidence to suggest that its systems were directly compromised in either breach. Instead, it appears that the login credentials used by hackers were obtained from other online accounts where users may have reused the same credentials.
In response to the breaches, Roku has pledged to reverse unauthorized charges and refund all affected accounts. Additionally, the company advises users to take proactive steps to secure their accounts by changing their passwords. Roku has provided a guide to help users create strong and secure passwords to mitigate the risk of future breaches.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543