Boxee Unboxed: Data Breach Hits Online TV Service

More than 158,000 sets of account details from the user forums of Internet-TV software maker Boxee are currently circulating online after a data breach sometime last month.

The leaked data consists of 158,128 individual user accounts, including about 172,000 email addresses, plus user names and cryptographically scrambled passwords, researchers told the tech blog Ars Technica.  Worse, the leaked data also includes the IP addresses and birthdates of users, as well as message archives and past password changes.

MORE: How to Protect Yourself From Data Breaches

Boxee makes computer software designed to put Internet content on living-room TVs. Before the company was bought by Samsung in 2013, it partnered with D-Link to make a set-top box, called a Boxee Box, that came with several apps, including Netflix, Vudu, YouTube and Pandora, and could also be used to watch over-the-air programming and record shows to a cloud-storage service.

The Boxee user forums seem to have been dormant since early August of last year, shortly after the Samsung purchase was announced.

It's not clear when the Boxee breach took place or who is responsible, but the stolen data became widely available last week, Australia-based security researcher Scott A. McIntyre told Ars Technica.

A blog posting by Risk Based Security of Richmond, Va., said the Boxee data first showed up on a Tor-protected website around March 10. Password-management service LastPass last week alerted users whose email addresses appeared in the leaked Boxee data.

The stolen data appears to only contain Boxee forum accounts, not regular Boxee service accounts. As of midday Wednesday, neither Boxee nor Samsung had issued a statement.

Think you might be affected by the Boxee breach? You can use the "Have I Been Pwned?" online tool to check if your email address is included. "Have I Been Pwned?" searches through data aggregated from several major data breaches, and the 800-megabtye Boxee file has already been added.

If your email address turns up, immediately change your Boxee password. If you use that same password anywhere else online, change it there as well.

The leaked passwords are cryptographically scrambled, but that doesn't necessarily mean users are safe. Last fall, Adobe's enormous 150 million-account data breach was made worse by the fact that every password was encrypted using the same key, and simple passwords such as "password" were easier to unscramble than a newspaper word puzzle.

Risk Based Security said someone had apparently found account data in the Boxee leak pertaining to well-known security reporter Brian Krebs. The Risk Based Security blog offers a screenshot of Krebs' partially obfuscated personal information posted to Boxee's forums, but we could find no such posting in the forums.

According to "Have I Been Pwned?" and McIntyre, Krebs' email address is not in the leaked data.

Email jscharr@techmedianetwork.com or follow her @JillScharr and Google+.  Follow us @TomsGuide, on Facebook and on Google+.

TOPICS

Jill Scharr is a creative writer and narrative designer in the videogame industry. She's currently Project Lead Writer at the games studio Harebrained Schemes, and has also worked at Bungie. Prior to that she worked as a Staff Writer for Tom's Guide, covering video games, online security, 3D printing and tech innovation among many subjects. 

Latest in Online Security
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
MacBook Pro 2023
New Mac attack is tricking users into thinking their computer is locked — how to stay safe
Hacker using a stolen social security card
Your Social Security number is a literal gold mine for scammers and identity thieves — here’s how to keep it safe
An open lock depicting a data breach
Half a million teachers hit in major data breach with SSNs, financial data and more exposed — what to do now
Green skull on smartphone screen.
Malicious Android apps with 60 million installs bombarding phones with ads and phishing attacks — how to stay safe
Malware
Dangerous new password-stealing trojan automatically reinstalls itself on infected PCs
Latest in News
Rendered images of rumored foldable iPhone.
Foldable iPhone report just revealed key details — here's what we know
Nintendo Switch 2
Nintendo Switch 2 rumored specs — here’s what we know so far
iPhone 17 Pro render
iPhone 17 Pro — 7 biggest rumored upgrades
CAD renderings of the Google Pixel 10 Pro XL
Pixel 10 leak could be good news for all Android phones
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
Lewis Hamilton of Great Britain and Scuderia Ferrari looks on during Sprint Qualifying ahead of the F1 Grand Prix of China at Shanghai International Circuit in Shanghai, China, on March 21, 2025. (Photo by Song Haiyuan/Paddocker/NurPhoto via Getty Images)
How to watch Chinese Grand Prix 2025 online – stream F1 without cable, qualifying highlights
  • Bean007
    Even though the forums have been dead for awhile I'm not surprised that the company hasn't responded since they stop caring about the Boxee Box.
    Reply