ROKU, INC.
bd_58e489ed0f5d0b52 · schema v1 · pii pii-v1
Full breach record for ROKU, INC. →Roku, Inc. notified the California Attorney General of unauthorized access to certain individual Roku accounts. The incident occurred between December 28, 2023, and February 21, 2024. Unauthorized actors used login credentials (email addresses and passwords) obtained from third-party data breaches to access Roku accounts. They changed login information and, in limited cases, attempted to purchase streaming subscriptions. Roku secured affected accounts by forcing password resets, investigated charges, and refunded unauthorized subscriptions. No SSNs or full payment account numbers were accessed.
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_49c6d0ded27361a1Maine State AGfiled 2024-03-08Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-582208
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 8, 2024
- Raw hash
- 35d806336e087dd038f3a9df02929c7c31666271c87f1876ea49535dd0cbf764
Reporting entity
- Name
- ROKU, INC.norm: roku
Victim entity
- Name
- ROKU, INC.norm: roku
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- CREDENTIALSIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.