Plex's forums hacked, user data being held ransom

Streaming service Plex's forums have been hacked, and the hacker is holding the data ransom in exchange for Bitcoin. Plex has announced that the hacker was able to gain access to IP addresses, email addresses, hashed and salted passwords as well as private message. Payment information is not stored on Plex's servers, so that information is still secure.

The streaming service refused to pay the ransom, and has reset the passwords of all affected users. Plex uses a SSO (single sign-on) authentication, so if the hacker were to reverse-engineer the hashed passwords, he or she would be able to gain access to a user's account as well.

The hacker posted about his exploits on Reddit:

I gave them until the 3rd of this month to send 9.5 BTC, or I would release all this data. This ransom is still active and on the 3rd: if no BTC payment is made, the ransom wll go up by 5 BTC. Eventually if no BTC payment is made, the data will be released via multiple torrent networks and there will be no more plex.tvYou can also pay me to remove your data from the content that's going to be released - If you send an e-mail without BTC ready to send, I will add your data to a special list.

Plex confirmed the hack on its official blog, stating that it was looking into the issue:

At approximately 1pm PDT yesterday (July 1st) we learned that the server which hosts our forums and blog was compromised. The attacker was able to gain access to some personal information, such as IP addresses, forum private messages, email addresses, and encrypted (hashed and salted) passwords for our forum users. As a precaution, we reset the passwords of all users with linked forum accounts and reached out via email with further instructions for those affected. At this time, our forums remain offline while we complete our investigation. All other systems are online and operational.

If you're a Plex user, we suggest you go ahead and change your password. Be sure to create a strong password that is unique to the service so that it doesn't compromise your account security on other websites. We'll update the article once we have more information.

Source: Reddit, Plex (opens in new tab)

  Just wondering, but why would anyone care if someone stole their forum logins? Maybe if they used the same logins elsewhere, but other than that?
  They are claiming to have more data. Plex says all they could get are the hashed passwords, but the (censored for the kids) says they have more. That's what they're claiming to have for "ransom".
  I suppose this is a tiny bit of a good thing in the fact that they have it in their head that Plex is a big enough company that they can be hacked and ransomed, hopefully they will learn from this and tighten up their security, I'm a Plex user myself, but I'm not worried about this, just change my password, luckily they don't store account details on their servers, I hope they catch this guy, get a job as a hacker or something, go work for NSA, don't steal customers data and ransom it!!!!
  • They have forum account details on their servers.
  • If you had the ability to read English and understand sentences you would know he was talking about bank account details.
  I would switch to using plex but the two things I require are vob support and metadata support for mymovies, neither of which are possible at this time. So it's really only the best, like most things, depending on your situation.
  Yeah - I started our hone media collecting with WHS and WMC. All the movies ripped to server in folder format (only previews, PUOs, etc, removed). Plex still, to this day, refuses to support disc images, whether ISO or folder format (which would be an easy conversion back to ISO). I've thus stayed off this now derailed train. :P
  Why would you close the mailbox? Unless you used the same password for both...
  Why keep it open? I have my own domain name, so I use hundreds of unique email addresses that I give out to people e.g. for Plex it would be; for the Hilton hotel it would be; for Windows Central it's that way I know who is spamming me or sold my email to be spammed. I can also block/delete an email address in an instant and know that it will only affect one website or company. Speaking of spam, my Windows Central email IS getting spammed - which means they've either sold the list to someone, or they've had their list compromised. There is no other explanation as I ONLY use it to login here.
  I've done the same, and have also used different names in my profile info. It truly is amazing how many companies share your information with "business partners" without proper notice. Also stunning, those that do give notice say to allow 6 weeks to add your name to their do not share list.
  I do the same thing. Funny thing is that if you use Google Apps (I still have a free one that supports way more than 10 accounts), you can do it with aliasas or even + signs. This way, you close an alias and not a full mailbox. Also, with Google Apps (and Gmail too), you can do the + sign trick ( The "+alias" can be tagged and filtered on.
  I do the same thing everywhere, as far as passwords and email addresses is concerned. Nice to have your own domain names. I have several domains. Except I usually use 22 to 24 character passwords. Longer on websites that allow it. I don't have to do the typing for it anyway, so I generally make the password as long as the site will accept for the maximum characters, and randomly shorten it so that the lengh of the password also cannot be guessed. There will be no compromises of my data. Even with hashes and salts, it will take them more years than they have left to live to extract the data, and I change all my passwords everywhere I log in on a regular basis, reminded kindly by KeePass to do so. Even if they could do it quickly, I have a small handful of sites that have my financial data of any sort, and those are all changed twice per week. Paranoid much? Yep. Proud of it, too. Never been compromised. And being able to recycle email addresses to keep out spammers is a great thing to be able to do. :)  
  • So if this only affects the forums, I guess only people who go to the forums are affected and it doesn't interfere with the other plex services.
  • Assuming Plex staff was honest about what was taken
  • If they weren't they'll find themselves in very hot water with the law as they're obliged to inform people of the extent of the compromise. Posted via the Windows Central App for Android
  • I'd doubt they'd do that but they aren't most transparent bunch.
  The lesson here is to make sure you don't use shared accounts and passwords across any sites.
  This is why I hate people. Get a fucking life you hacking bastards. I don't use plex, but this does nothing but hurt all those that use it.
  Well, actually, it reminds the lazy owners of these services to enforce proper security standards.
  If people wouldn't do this then "proper" security standards wouldn't be necessary
  The best way to look at it, you wouldn't leave your all the external doors in your house and your physical mail box wide open 24/7. So this is no different, it's only as secure as you make it.
  On the flip side though, no matter what locks you have, hardened frames, glass, security cameras - if someone wants in they will find a way. The point is, why do it in the first place, the excuse of "well, you didn't protect it enough" doesn't really wash! If someone gets in your locked house and takes your possesions, would it then be your fault for not providing adequate security?
