Ссылка
click to show
click to show
Plex Hacked
Summary
Plex - the personal media library application and service - has reported that a third party has gained unauthorised access to their system and accessed customer data, including email addresses, usernames and hashed passwords.
Plex is recommending users change their passwords and sign out of all devices.
Quotes
Quote
Plex has experienced a data breach in which an unauthorized third party accessed emails, usernames, securely hashed passwords, and authentication data.
The platform recommends users change their password immediately and sign out of any active sessions or devices.
Quote
What happened
An unauthorized third party accessed a limited subset of customer data from one of our databases. While we quickly contained the incident, information that was accessed included emails, usernames, securely hashed passwords and authentication data.
Any account passwords that may have been accessed were securely hashed, in accordance with best practices, meaning they cannot be read by a third party. Out of an abundance of caution, we recommend you take some additional steps to secure your account (see details below). Rest assured that we do not store credit card data on our servers, so this information was not compromised in this incident.
What you should do:
Quote
If you use a password to sign into Plex: We kindly request that you reset your Plex account password immediately by visiting https://plex.tv/reset. When doing so, there’s a checkbox to “Sign out connected devices after password change,” which we recommend you enable. This will sign you out of all your devices (including any Plex Media Server you own) for your security, and you will then need to sign back in with your new password.
If you use SSO to sign into Plex: We kindly request that you log out of all active sessions by visiting https://plex.tv/security and clicking the button that says ”Sign out of all devices”. This will sign you out of all your devices (including any Plex Media Server you own) for your security, and you will then need to sign back in as normal.
My thoughts
Even though the passwords were hashed, you should consider those passwords pwned and change your password anywhere else you may have used the same password - and for best practice you should not reuse the same password for multiple services. Use unique passwords for each website/service.
If people could like, stop hacking websites and stealing all our data, that would be great.
Sources
https://forums.plex.tv/t/important-notice-of-security-incident/930523
https://www.androidauthority.com/plex-data-breach-3595999/