Thousands of Roku accounts hacked including credit cards — what you need to know

A hand holds a Roku remote in front of a TV with the Roku home screen.
(Image credit: Shutterstock)

Roku has suffered a massive data breach, with as many as 15,363 customers affected and their data stolen, including credit card information, passwords, and usernames. 

Roku announced the breach in a public memo sent to customers dated March 8th, citing various information on what happened and what the company is doing to combat the issue. 

According to BleepingComputer, the purported hackers who not only stole the data but used it to buy into streaming platforms and other products also sold off stolen Roku accounts for just $0.50 per individual user. 

Roku stuffing attack 

Threat actors involved in the Roku data breach targeted Roku.com itself using so-called SilverBullet or Open Bullet 2 cracking tools. These allow hackers access into locked accounts by way of credential stuffing on Roku’s website, thereby allowing them to change the passwords and collect all of the valuable information associated with the account, including credit cards, emails, shipping addresses, and more. 

Once in control of an account, threat actors can use the stolen information fraudulently — in this case buying up streaming subscriptions and other hardware via Roku’s Shopify integration. 

According to BleepingComputer's sources, the threat actors that targeted Roku were actively engaging in the mass breach for several months utilizing imported custom configuration files, or simply custom configs, and a variation of proxy servers to bypass captchas and other protective resources. 

Account holders affected by the data breach are requested by Roku to visit “my.roku.com” and to reset their password using the “Forgot password?” tool.

Several of these stolen Roku accounts were discovered on a variety of account marketplaces for as low as $0.50. At the time of writing, as many as 440 accounts have been sold, with details on how fraudulent buyers can utilize the provided information for nefarious purposes, most notably to buy light strips, remotes, soundbars, cameras, and more using stolen credit cards.

Account holders affected by the data breach are requested by Roku to visit “my.roku.com” and to reset their password using the “Forgot password?” tool. Once you have accessed your account, ensure that all of your information, including connected devices and active subscriptions, are in order via the Roku dashboard.

Roku’s data breach statement

Roku has addressed the issue in a memo to its customers sent out on Friday of last week. The company details how “unauthorized actors were able to obtain login information from third-party sources” and that said threat actors were then able to alter “Roku logins for the affected individual Roku accounts.” 

Although Roku has stated that it secured all impacted accounts and has enforced a password reset wherever possible following the incident, without any two factor authentication on even the best Roku devices and services, it’s quite a conundrum to face for its customers. 

It’s best to ensure that all of your passwords across services are altered following the breach and to contact your banks to keep your credit cards secure. It’s a bit more complicated for stolen address information, but you’ll be sleeping soundly given threat actors won’t be able to access your other accounts and credit cards. 

Roku’s data breach comes on the heels of a rather problematic user agreement change, which disallowed users access to their TVs until accepting the new policy. The breach is in no way connected to these changes, but highlights many problems currently under the Roku banner — despite the firm’s OS being hailed as the number one selling TV OS in the US

More from Tom's Guide

Ryan Epps
Staff Writer

Ryan Epps is a Staff Writer under the TV/AV section at Tom's Guide focusing on TVs and projectors. When not researching PHOLEDs and writing about the next major innovation in the projector space, he's consuming random anime from the 90's, playing Dark Souls 3 again, or reading yet another Haruki Murakami novel. 

Read more
A picture showing different credit cards stacked on top of each other on a table
5 million Americans just had their credit card details leaked online — what to do now
An open lock depicting a data breach
12 million hit in Zacks Investment data breach — how to protect yourself now
Discord on a phone and a laptop
Almost 1 million Discord users just had their account details exposed in new RestoreCord data breach — what to do now
Green skull on smartphone screen.
Over 1 million Android devices infected with password-stealing, pre-installed botnet malware — how to stay safe
An Android bot next to an Android TV remote
Millions of Android TVs hijacked in massive botnet — how to see if yours is at risk
An open lock depicting a data breach
Massive healthcare data breach just exposed the personal info of 1 million Americans — what to do now
Latest in TVs
A Samsung TV box on the floor of a Walmart. It is strapped shut and ready to be moved.
Here's why you should never throw out the box that came with your TV
Samsung Display Bezel-less tile concept at MWC 2025
Bezel-less tile OLED TVs could be the future of large-screen displays
Photos of the LG C5 OLED taken in 2025 at an LG event.
The LG C5 OLED isn't the upgrade I was hoping it'd be — here's why
Google TV Streamer in front of TV
3 reasons to still buy a streaming device in 2025 — yes, even with smart TVs
LG TV with webOS on screen on wall
7 smart TV tips and tricks you need to do right now to get better performance
The Philips Roku TV OLED made in partnership with Skyworth
New Roku OLED TV just announced — and it's hundreds less than the LG C4 OLED
Latest in News
A render of the iPhone 17 Pro Max
iPhone 17 Pro Max — this new rumor could push people towards iPhone 17 Air
Isabela Merced as Dina and Bella Ramsey as Ellie in The Last of Us Season 2
New 'The Last of Us' season 2 trailer shows off my favorite moment from 'Part II'
apple watch 4
Apple Watch escapes U.S. import ban after court victory in patent case
samsung galaxy s25 edge mockups at galaxy unpacked 2025
iPhone 17 Air and Samsung Galaxy S25 Edge could get yet another ultra-thin rival
NYTimes Connections
NYT Connections today hints and answers — Sunday, March 9 (#637)
Prime Gaming's selection of free games for March 2025
Amazon Prime is giving away these 20 games in March — get Fallout, Saints Row 3, and more free games now
  • Atamas
    Roku supposedly sent out a memo on March 8th? To whom?? I certainly received no such memo! I contacted a friend, & neither did he. Roku has my email, as I receive lots of promotional crap from them.
    Reply