Roku
Disclosed Mar 8, 20242 years ago576,000 affectedConfirmed
Credential stuffing compromises about 15,000 Roku accounts
Roku notified users in March 2024 that attackers used username and password pairs stolen from other services to access Roku accounts between late December 2023 and February 2024. TechCrunch reported about 15,000 accounts were affected in this first incident.
What is known
| People affected | 576,000 (as reported by the organization) |
|---|---|
| Disclosed | Mar 8, 2024 |
| Discovered | Dec 28, 2023 |
| Happened | Dec 28, 2023 |
| Attack | Credential stuffing |
| Data exposed | Emails, Credentials and tokens, Payment cards |
| Sector | Media · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| California Attorney General breach notice: Rokuoag.ca.gov · Official notice | Official notice |
| California AG breach notice: Roku, Inc.oag.ca.gov · Regulator | Regulator |
| Roku says 576,000 user accounts hacked after second security incidenttechcrunch.com · News | News |
Notices filed
| Where | Filed | People |
|---|---|---|
| California AGresidents of CA | Mar 8, 2024 | |
| Researchtotal | Mar 8, 2024 | |
| Researchtotal | Apr 12, 2024 | 576,000 |
History of this record
- 2026-09-25 · discovered: empty to 2023-12-28 · seed source
- 2026-09-25 · summary: Roku said about 576,000 user accounts were accessed through credential stuffing, discovered while it was notifying victims of an earlier incident. Fewer than 400 accounts saw fraudulent purchases, which Roku refunded, and it then rolled out to Roku notified users in March 2024 that attackers used username and password pairs stolen from other services to access Roku accounts between late December 2023 and February 2024. TechCrunch reported about 15,000 accounts were affected in th · seed source
- 2026-09-25 · title: Second credential stuffing attack hits 576,000 Roku accounts to Credential stuffing compromises about 15,000 Roku accounts · seed source
- 2026-09-25 · sector: tech to media · seed source
- 2026-09-25 · attack: unknown to credential-stuffing · seed source
- 2026-09-25 · data_types: [] to ["emails","credentials","payment-card"] · seed source
- 2026-09-25 · records_basis: empty to organization · seed source
- 2026-09-25 · records: empty to 576000 · seed source
- 2026-09-25 · summary: empty to Roku said about 576,000 user accounts were accessed through credential stuffing, discovered while it was notifying victims of an earlier incident. Fewer than 400 accounts saw fraudulent purchases, which Roku refunded, and it then rolled out · seed source
- 2026-09-25 · title: empty to Second credential stuffing attack hits 576,000 Roku accounts · seed source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.