ROKU, INC.
ent_019e63e312987514e7fbd08c137bf9ca
Disclosures
3
State AG · 3 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
15,363
as filed · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- ROKU, INC.
- Normalized
- roku— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300KR6ITU0YIR1T71
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (3)newest first
- 🦞Maine State AGas victim2024-03-08
Roku Inc. experienced a data breach affecting 15,363 individuals, including 76 Maine residents. The breach occurred from December 28, 2023, to February 21, 2024, and was discovered between January 4, 2024, and February 21, 2024. The incident involved unauthorized individuals using account credentials, believed to be obtained from third-party sources, to access customer accounts. Consumers were notified in writing on March 8, 2024. Identity theft protection services were not offered.
- 🐻California State AGas victim2024-03-08
Roku, Inc. notified the California Attorney General of unauthorized access to certain individual Roku accounts. The incident occurred between December 28, 2023, and February 21, 2024. Unauthorized actors used login credentials (email addresses and passwords) obtained from third-party data breaches to access Roku accounts. They changed login information and, in limited cases, attempted to purchase streaming subscriptions. Roku secured affected accounts by forcing password resets, investigated charges, and refunded unauthorized subscriptions. No SSNs or full payment account numbers were accessed.
- 🏎️Indiana State AGas victim2023-12-28
Roku Inc reported a data breach to the Indiana Attorney General. 273 Indiana residents were affected. 15,363 individuals affected in total.