Roku Mandates 2FA for Customers After Credential-Stuffing Compromise

April 15, 2024 at 04:19PM Roku is enforcing mandatory two-factor authentication for all users following two incidents where customer accounts were compromised. Approximately 591,000 customers were affected, with 400 having their accounts used for unauthorized purchases. The breach did not expose sensitive financial or personal information, and Roku has reset passwords for the affected accounts. … Read more

Roku makes 2FA mandatory for all after nearly 600K accounts pwned

April 15, 2024 at 11:40AM Roku is requiring 2FA for all accounts after attackers accessed around 591,000 customer accounts through credential stuffing attacks. Users affected by the compromise have been reimbursed, and no sensitive information was accessed. Roku emphasized the need for unique passwords and vigilant monitoring of suspicious activity. All users are encouraged to … Read more

Like Seat Belts and Airbags, 2FA Must Be Mandatory ASAP

February 16, 2024 at 10:08AM The hack of genetic testing company 23andMe exposed 6.9 million people’s genetic data due to faulty security measures. The breach underlines the necessity for mandatory two-factor authentication (2FA) in SaaS applications to bolster security and protect against potential misuse and targeting. Implementing 2FA is crucial for safeguarding genetic and personal … Read more