Plex issues warning to all users: Reset your password NOW as it confirms security breach

Plex, a media streaming platform, just confirmed that hackers accessed a database containing your email address, username and encrypted password
|SORA/ GB NEWS
All products and promotions are independently selected by our experts. To help us provide free impartial advice, we will earn an affiliate commission if you buy something. Click here to learn more
Hackers accessed a database containing email addresses, usernames and passwords
- Plex, the media streaming platform, just confirmed a data breach
- Email addresses, usernames and passwords have been compromised
- The company is urging you to reset your password ASAP
- Security experts advise on other ways you can protect yourself
Don't Miss
Most Read
Plex, the immensely popular media streaming platform, says you must change your password immediately. The company just confirmed that hackers managed to access a database packed with email addresses, usernames, and encrypted passwords.
If you rely on the same password and email address combination for multiple accounts — then you should change everything as quickly as possible to block criminals from accessing other services.
The streaming service confirmed they detected the breach earlier today (September 9) and quickly contained it. They have also already closed the security threat that allowed unauthorised access and are conducting thorough reviews of their systems to strengthen defences against future attacks.
However, Plex can't reverse what's been taken by the hackers, so they're urging you to take swift action to secure your account
Although your Plex password was securely encrypted, making it unreadable to attackers, the company is taking extra precautions in the rare instance it's able to be uncovered. Plex has also assured users that payment card details remain safe as they don't store this information on their servers.
To reset your password, navigate to Plex's website and enter your email address so the company can send reset instructions
|PLEX PRESS OFFICE
To reset your password, follow these steps:
- Visit plex.tv/reset to change your password
- Tick the box labelled "Sign out connected devices after password change" to log out all your devices, including any Plex Media Server you own
- Change your password
- Sign in to your devices with the new password
If you sign in using Google or Apple, go to plex.tv/security and select "Sign out of all devices" instead. You'll need to re-authenticate on all your devices afterwards, too.
Plex says it's conducting comprehensive security reviews to prevent future incidents, but urges you to reset your password out of precaution
|PLEX PRESS OFFICE
This isn't the first time users have been urged to reset their Plex password. The platform experienced an almost identical security incident in August 2022, when hackers accessed the same type of user information - emails, usernames and encrypted passwords.
The similarity between these breaches has raised concerns about whether Plex is being repeatedly targeted or if there are deeper security issues. Users on forums have expressed frustration about having to reclaim their media servers and re-authenticate devices like Roku players after password resets.
The company says it's conducting comprehensive security reviews to prevent future incidents. However, the pattern of repeated breaches suggests ongoing vulnerabilities that hackers continue to exploit.
Experts recommend taking additional precautions
Darren Guccione, CEO and Co-Founder of Keeper Security, said: "This incident is a timely reminder of the continued importance of enacting strong password hygiene practices. Even with a hashed format, weak or reused credentials are still vulnerable to exploitation via automated tools and credential-stuffing attacks.
"Whether or not an individual is affected by a breach, it’s always advisable to regularly reset passwords. Avoid names, dates and dictionary words. Passwords should be long - a minimum of 16 characters is recommended - and completely randomised, ideally generated and stored using a password manager. And never reuse passwords. If one account is breached, reusing credentials elsewhere puts your entire digital identity at risk."
Get 52% off NordPass password manager
NordPass is a secure password manager that works across your favourite devices, including iPhone and Android, Windows and Mac, and more. It'll evaluate your password strength, autofill login details, and warn about data breaches on the Dark Web that impact you. It's a one-stop-shop to fight back against hackers from the team behind the award-winning NordVPN
NordPass
$2.57
$1.09
Switch to 1Password for free
The award-winning 1Password is designed to generate and store unguessable passwords, passkeys, credit card numbers, national insurance numbers, and much more. Its built-in WatchTower feature evaluates password strength and warns about data breaches that impact you. 1Password is currently free to test for 14 days with no obligation to subscribe
1Password
Plex also strongly recommends enabling two-factor authentication for extra protection. The company warns that they'll never ask for passwords or payment details via email - any such requests are phishing attempts you should ignore.
This adds an extra layer of security to your account by requiring more than just your password to log in. After you enter your password, you’ll also need to provide a second verification code, usually generated by an authenticator app (like Google Authenticator, Authy, or 1Password) or sent via text message.
Karolis Arbaciauskas, head of product at NordPass said, “For those using [single-sign on] (SSO) to log in, it would be best to log out of all active sessions. That can be done here, by clicking the button ‘Sign out of all devices.’ For step-by-step instructions on how to reset your password, visit this link.
“Remember to also inform your family and friends about this change. After a password reset, users will need to log in again on all their devices using the new credentials. A password manager can be helpful for securely generating and sharing these new credentials."
LATEST DEVELOPMENTS
- Microsoft is pulling the plug on one of its Outlook email apps
- BBC is building new Roku rival with 'radically simple' design
- Best VPN deals
- New WhatsApp feature will REWRITE your text messages
If you're not familiar with Plex, it's a media server and streaming platform, founded in 2009 and based in Los Gatos, California. It lets you organise, stream, and access your personal collection of movies, TV shows, music, and photos across devices. In addition to personal media, Plex also offers free, ad-supported movies, TV, live TV, and podcasts, making it a one-stop hub for both personal and online entertainment.
More From GB News