Data Breaches

Plex Urges Password Resets Following Data Breach

Hackers accessed emails, usernames, password hashes, and authentication data stored in a Plex database.

Hackers accessed emails, usernames, password hashes, and authentication data stored in a Plex database.

Popular streaming platform Plex on Monday issued an urgent warning that user information has been compromised in a data breach.

“An unauthorized third party accessed a limited subset of customer data from one of our databases. While we quickly contained the incident, information that was accessed included emails, usernames, securely hashed passwords, and authentication data,” Plex said.

The streaming platform says the impact from the incident is believed to be limited, and the hackers should not be able to crack the hashed passwords, but urged users to take immediate action to secure their accounts.

“If you use a password to sign into Plex: We kindly request that you reset your Plex account password immediately by visiting https://plex.tv/reset. When doing so, there’s a checkbox to ‘Sign out connected devices after password change’, which we recommend you enable,” Plex said.

By checking the box, users will be automatically signed out of all their devices, including the Plex Media Server, and will need to sign back in using the new password. While this might seem like an inconvenience, it ensures that the attackers are signed out of any potentially compromised accounts.

Users relying on Single Sign-On to access their accounts should log out of all active sessions and also check the box for signing out of all devices.

Advertisement. Scroll to continue reading.

Plex also notes that it has blocked the attackers’ access to its systems and that it has launched internal reviews to improve security.

The company also encourages users to be wary of potential phishing attacks, including unsolicited communication from Plex impersonators.

“We remind you that no one at Plex will ever reach out to you over email to ask for a password or credit card number for payments,” the streaming platform notes.

What Plex did not say was who was behind the attack and how many users were potentially affected. SecurityWeek has emailed Plex for a statement on the matter and will update this article if the company responds.

Plex suffered a similar data breach back in 2022. 

Related: Rationalizing the Stack: The Case for Security Vendor Consolidation

Related: Through the Lens of Music: What Cybersecurity Can Learn From Joni Mitchell

Related: Meshed Cybersecurity Platforms Enable Complex Business Environments

Related: PromptLock Only PoC, but AI-Powered Ransomware Is Real

Related Content

Artificial Intelligence

Spanish regulators say an AI agent chained together a successful login, vulnerability discovery, and access to personal data in a potential milestone for autonomous...

Data Breaches

In June 2026, hackers accessed files containing patients’ names, contact information, diagnosis details, and health insurance information.

Data Breaches

A hacker claims to have stolen 7.5 million customer records after breaching the company’s systems.

Data Breaches

Hackers exploited a vulnerability in a VPN product to steal the personal information of roughly 240,000 people.

Data Breaches

The company unintentionally disclosed users’ information to a third party impersonating a government agency.

Data Breaches

Stolen credentials were used in a multi-month campaign to access subscriber personal data and billing records.

Data Breaches

Hackers compromised the Brevo marketing platform and used that access to send phishing emails to users of Trezor, BitBox, and CoinTracking.

Data Breaches

A misconfigured test server containing engineering material, including internal configurations, was accessed by threat actors.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version