ROKU, INC.
bd_58e489ed0f5d0b52 · schema v1 · pii pii-v1
Full breach record for ROKU, INC. →2 incidents on fileRoku, Inc. notified the California Attorney General of unauthorized access to certain individual Roku accounts. The incident occurred between December 28, 2023, and February 21, 2024. Unauthorized actors used login credentials (email addresses and passwords) obtained from third-party data breaches to access Roku accounts. They changed login information and, in limited cases, attempted to purchase streaming subscriptions. Roku secured affected accounts by forcing password resets, investigated charges, and refunded unauthorized subscriptions. No SSNs or full payment account numbers were accessed.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 28, 2023
Begins
Mar 8, 2024
Filed
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- Maine State AGbd_49c6d0ded27361a12024-03-08Verified
- Indiana State AGbd_7d1c041465f60e1d2023-12-28 · +71dCandidate
Filing propagation · 3 filings · 3 states
View merged incident ↗Pattern: first filing Dec 28 (IN), last Mar 8 (CA) — a 71-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.