Skip to content

Roku

Disclosed Mar 8, 20242 years ago576,000 affectedConfirmed

Official notice

Credential stuffing compromises about 15,000 Roku accounts

Roku notified users in March 2024 that attackers used username and password pairs stolen from other services to access Roku accounts between late December 2023 and February 2024. TechCrunch reported about 15,000 accounts were affected in this first incident.

What is known

People affected576,000 (as reported by the organization)
DisclosedMar 8, 2024
DiscoveredDec 28, 2023
HappenedDec 28, 2023
AttackCredential stuffing
Data exposedEmails, Credentials and tokens, Payment cards
SectorMedia · US
StatusConfirmed

Sources

Source
California Attorney General breach notice: Rokuoag.ca.gov · Official notice
California AG breach notice: Roku, Inc.oag.ca.gov · Regulator
Roku says 576,000 user accounts hacked after second security incidenttechcrunch.com · News

Notices filed

WhereFiledPeople
California AGresidents of CAMar 8, 2024
ResearchtotalMar 8, 2024
ResearchtotalApr 12, 2024576,000
History of this record
  • 2026-09-25 · discovered: empty to 2023-12-28 · seed source
  • 2026-09-25 · summary: Roku said about 576,000 user accounts were accessed through credential stuffing, discovered while it was notifying victims of an earlier incident. Fewer than 400 accounts saw fraudulent purchases, which Roku refunded, and it then rolled out to Roku notified users in March 2024 that attackers used username and password pairs stolen from other services to access Roku accounts between late December 2023 and February 2024. TechCrunch reported about 15,000 accounts were affected in th · seed source
  • 2026-09-25 · title: Second credential stuffing attack hits 576,000 Roku accounts to Credential stuffing compromises about 15,000 Roku accounts · seed source
  • 2026-09-25 · sector: tech to media · seed source
  • 2026-09-25 · attack: unknown to credential-stuffing · seed source
  • 2026-09-25 · data_types: [] to ["emails","credentials","payment-card"] · seed source
  • 2026-09-25 · records_basis: empty to organization · seed source
  • 2026-09-25 · records: empty to 576000 · seed source
  • 2026-09-25 · summary: empty to Roku said about 576,000 user accounts were accessed through credential stuffing, discovered while it was notifying victims of an earlier incident. Fewer than 400 accounts saw fraudulent purchases, which Roku refunded, and it then rolled out · seed source
  • 2026-09-25 · title: empty to Second credential stuffing attack hits 576,000 Roku accounts · seed source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about Roku

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.