Roku steps up security with mandatory 2FA for customers

April 23, 2024
1 min read

TLDR:

  • Roku has made 2FA mandatory for all users after two credential stuffing attacks affecting over 500,000 accounts.
  • The attacks did not reveal financial information, but hackers were able to make purchases on the platform.

Roku has responded to two waves of credential stuffing attacks in 2024 by making two-factor authentication (2FA) mandatory for all users. The attacks compromised over 500,000 accounts, with the more recent breach affecting 576,000 accounts. While the hackers did not access financial information, they were able to make purchases on the platform using payment methods stored in the compromised accounts. As a security measure, Roku has reset passwords for breached accounts and is requiring all users to set up email 2FA for continued account access. Despite the security changes, some experts believe that email 2FA may not provide adequate protection against sophisticated cyber threats. Roku’s response to the attacks has garnered mixed reactions from customers, who are already expressing discontent over recent changes to the company’s terms of service.

The incident highlights the importance of robust security measures in the face of evolving cyber threats. Ted Miracco, CEO of Approov, emphasized the need for advanced defenses like app attestation and token-based access controls to counter sophisticated attacks targeting APIs. While Roku’s move towards mandatory 2FA is a positive step, there is a call for the company to enhance its security infrastructure to address modern cybersecurity challenges effectively.

Latest from Blog

EU push for unified incident report rules

TLDR: The Federation of European Risk Management Associations (FERMA) is urging the EU to harmonize cyber incident reporting requirements ahead of new legislation. Upcoming legislation such as the NIS2 Directive, DORA, and