Skip to main content

Plex resets users’ passwords after forum hack, attacker demanding ransom in Bitcoin

exploit
Image used with permission by copyright holder
Plex is one of our favorite media servers, and it’s certainly one of the most popular media streaming apps out there. This popularity is likely exactly what made it the target of a hacker who compromised the service’s user forums on Wednesday.

Plex confirmed the intrusion in a blog post yesterday. “The attacker was able to gain access to some personal information, such as IP addresses, forum private messages, email addresses, and encrypted (hashed and salted) passwords for our forum users,” the post reads.

Recommended Videos

As a security measure, Plex has reset the passwords of all forum accounts. Since Plex uses single sign-on (SSO), this means that any Plex.tv accounts linked with forum accounts have be reset as well.

Please enable Javascript to view this content

Fortunately, no financial data was compromised. “We have no reason to believe that any other parts of our system were compromised, and we never store credit card or other payment data on our systems,” the post reads.

Just because no financial data was revealed in the hack, that doesn’t mean that the hacker isn’t looking for money. The hacker, who goes by the name of “savaka” posted a message to the hacked forum claiming that users’ details would be released unless a ransom of 9.5 Bitcoin (roughly $2,400) was paid by today.

“This ransom is still active and on the 3rd: if no BTC payment is made, the ransom wll go up by 5 BTC,” the message read. “Eventually if no BTC payment is made, the data will be released via multiple torrent networks and there will be no more Plex.tv.”

Plex has no intention of paying the ransom, so while the password reset should be enough to keep your Plex account safe, you will want to make sure that if you use the same login info for any other sites, you change your password on those sites as well.

The password reset is causing some problems for users of third-party apps. If you’re running into trouble after the password reset, Plex has the answers to some common questions in the blog post announcing the breach.

Kris Wouk
Former Digital Trends Contributor
Kris Wouk is a tech writer, gadget reviewer, blogger, and whatever it's called when someone makes videos for the web. In his…
I’m a Steam Deck apologist. Here’s why I’ve been using the ROG Ally instead
Elden Ring running on the Asus ROG Ally X.

Since its launch, I'm a bit of a Steam Deck apologist. It doesn't need the advocacy, as the Steam Deck is easily the best handheld gaming PC you can buy, but even in the face of competition from the ROG Ally, Lenovo Legion Go, and MSI Claw, I still use my Steam Deck for gaming on the go. A couple of apps have been slowly changing that story, however.

I like playing on my Steam Deck OLED due to the convenience. SteamOS isn't perfect, no, but it allows me to pick up and play my games quickly, which I value more than the higher performance available on Windows handhelds. A couple of key tweaks to the Windows experience can unlock that pick-up-and-play experience, and ever since configuring the ROG Ally X properly, I've been gravitating toward it more and more for my handheld gaming.
A proper sleep

Read more
Surfshark vs. Windscribe: Which unlimited device VPN is best?
Surfshark and Windscribe prices appear in a split-screen on a PC monitor.

You use more than one device, so it makes sense to use a VPN to protect privacy on all your computers, laptops, tablets, and phones. If you’re like me, that’s a lot of devices, making Surfshark and Windscribe top candidates.

While the best VPNs offer solid cybersecurity with excellent speed, some limit the number of simultaneous connections. That means you might need to disconnect your phone before using the VPN on your laptop. That can be frustrating if you've left your phone upstairs or in another room to charge, so I compared both Surfshark and Windscribe to see which is the better solution.
Specs

Read more
The 10 announcements that made 2024 a landmark year for AI
ChatGPT and Siri integration on iPhone.

We've officially passed the second anniversary of the start of the AI boom, and things haven't slowed down. Just the opposite. Generative AI is ramping up at a pace that feels nearly overwhelming, expanding into new platforms, mediums, and even devices at a relentless pace.

Here are the 10 announcements that made 2024 a monumental year in the world of AI.
OpenAI releases GPT-4o

Read more