In an advisory posted on its website and emails sent to users, Plex admitted that “an unauthorized third party accessed a limited subset of customer data from one of our databases.” The data involved includes email addresses, usernames, authentication details, and securely hashed passwords.
While the company is downplaying the scale of the attack, the fact that this is a repeat event has left many users concerned. Plex insists that no credit card or payment data was compromised, as the company does not store such information on its servers.
What Plex Users Should Do
Plex is asking all customers to secure their accounts right away:
• For users who log in with a password: Reset your Plex account password at plex.tv/reset and check the option to “Sign out connected devices.” This will sign you out everywhere, including Plex Media Server, and you’ll need to log back in with your new password.
• For users who log in with SSO: Log out of all active sessions by visiting plex.tv/security and clicking “Sign out of all devices.” You’ll then need to sign back in as normal.
Plex says it has already identified and blocked the method used in the attack, and further security measures are being put in place. However, no details have been shared about who was behind the breach or how many accounts were affected.
A Pattern of Breaches
For long-time Plex users, this incident feels all too familiar. In 2022, the platform faced a similar breach, with customers being asked to reset passwords. Two breaches in such a short span are likely to raise questions about Plex’s security practices and its ability to protect sensitive data.
For now, Plex is asking users to take precautions and stay alert. But for many customers, trust in the platform’s security may already be shaken.
Tags:
Cyber News