Plex, the app for watching TV shows and movies, suffers a massive hack: How to protect your account

The streaming platform Plex has been hacked . The app is warning users to reset their passwords after suffering a data breach, in which a group of cybercriminals managed to steal customer authentication data.
In a notice seen by BleepingComputer , Plex reports that the information stolen from the database includes names, securely hashed passwords, email addresses, and authentication data. Furthermore, this unauthorized access affects a "limited subset of data," and while the platform reveals it has "contained" the breach, it confirms that cybercriminals obtained the aforementioned subscriber information.
However, Plex clarifies that no payment card information was disclosed , as it is not stored on the server. And, for now, the streaming platform indicates that it has addressed the method used to "breach its server," although it has not shared technical details about the attack.
On the other hand, BleepingComputer notes that "the passwords for the accessed accounts have been securely encrypted according to best practices, meaning they cannot be read by third parties." Furthermore, Plex has not shared what hashing algorithm the cybercriminals used , increasing the possibility that attackers could attempt to crack the passwords.
Therefore, Plex recommends that users, out of an "extreme caution," reset their credentials at the following link ( https://plex.tv/reset ) and also enable the option to "Sign out of connected devices after changing password." This will reset the credentials and close all connections using the same passwords, however, users will be required to log back in on any devices that use those credentials.
Additionally, Plex recommends users enable two-factor authentication for added protection, while reminding BleepingComputer that it will never ask users for their passwords or bank card details via email.
How to change your password on PlexUsers must click this link to change their password. For increased security, Plex recommends that users use a credential that contains uppercase and lowercase letters, numbers, and special characters , and that it not be used on any other service. It also advises users never to include their name, date of birth, or similar.
It also recommends enabling two-factor authentication to add an extra layer of security from account settings, while also warning users to log out of connected devices to avoid potential security issues.
Sign up for our newsletter and get the latest technology news straight to your inbox.
20minutos