NATIONAL NEWS

Disney Plus Blames Past Hacks For User Accounts Sold Online

Nov 20, 2019, 4:22 PM

Disney+ has arrived to try and reshape the streaming landscape. (CNN Business' Frank Pallotta)

(CNN Business' Frank Pallotta)

(AP) — Disney said Disney Plus account passwords being sold in underground hacking forums are coming from previous breaches at other companies, predating last week’s launch of its streaming service.

The company reiterated Wednesday that it found no evidence of a security breach and that account problems are limited to “a very small percentage of users” of Disney Plus.

Disney and other traditional media companies are trying to capture the subscription revenue now going to Netflix and other streaming giants. Helped by promotions, including a free year for some Verizon customers, Disney Plus attracted 10 million subscribers on its first day.

The news site ZDNet found stolen account usernames and passwords selling for $3 on underground hacking forums. Disney’s streaming service costs $7 a month or $70 a year.

Despite warnings by security experts, users often reuse passwords at multiple services, meaning a breach at one opens the door for a hacker to gain access to the others.

Users can easily avoid this by using strong passwords that are unique for each service, said Troy Hunt, an Australian security researcher whose “Have I Been Pwned?” website alerts people when their identity information is stolen.

But Hunt said Disney should implement better security measures.

“The Disney situation appears to be yet another credential stuffing attack where hackers exploit a combination of customers reusing passwords and the service provider not providing sufficient defenses to stop it,” Hunt said in an email.

Paul Rohmeyer, a professor at the Stevens Institute of Technology in Hoboken, New Jersey, said he’s surprised that streaming services haven’t yet implemented better security such as multi-factor authentication.

With multi-factor authentication, users must enter a code sent as a text message or email when logging in from a new device. The code helps ensure that people using stolen passwords or guessing them can’t use a service without also having access to the legitimate user’s phone or email account.

Rohmeyer said services may be hesitant to implement tougher security because they don’t want to be seen as more inconvenient than competitors.

Multi-factor authentication is an option for many non-streaming services, including Google, Facebook and Apple, but the extra security must be turned on. Disney Plus does require codes sent by email when changing account passwords, but it doesn’t use them for logging in from new devices.

Multi-factor authentication is harder to implement for services that are shared in households, as multiple users would need access to the same phone or email account. While Disney Plus, Netflix and Hulu let family members create their own profiles, with separate watch lists and preferences, they all share the same username and password. Apple TV Plus gets around this by having each family member sign in with a separate Apple ID.

KSL 5 TV Live

National News

...

Associated Press

Cicadas are so noisy in a South Carolina county that residents are calling the police

Emerging cicadas are so loud in one South Carolina county that residents are calling the sheriff's office asking why they can hear sirens or a loud roar.

1 hour ago

FILE - Former film producer Harvey Weinstein appears in court at the Clara Shortridge Foltz Crimina...

MIchael Sisak

New York appeals court overturns Harvey Weinstein’s 2020 rape conviction from landmark #MeToo trial

New York’s highest court has overturned Harvey Weinstein’s 2020 rape conviction.

7 hours ago

Rudy Giuliani, the former personal lawyer for former U.S. President Donald Trump, speaks to the pre...

Jacques Billeaud, Jonathan J. Cooper and Josh Kelety

Arizona indicts 18 in election interference case, including Giuliani and Meadows

An Arizona grand jury has indicted former President Donald Trump’s chief of staff Mark Meadows, lawyer Rudy Giuliani and 16 others in an election interference case related to the 2020 presidential vote.

8 hours ago

FILE - Travis Scott performs at the Astroworld Music Festival in Houston, Nov. 5, 2021. A Texas gra...

Juan A. Lozano, Associated Press

Judge declines to dismiss lawsuits filed against rapper Travis Scott over concert that killed 10

A judge has declined to dismiss hundreds of lawsuits filed against rap star Travis Scott over his role in the deadly 2021 Astroworld festival in which 10 people were killed in a crowd surge.

8 hours ago

Speaker of the U.S. House of Representatives Mike Johnson (R-LA) attends a news conference at Colum...

Haley Talbot, Lauren Fox and Clare Foran, CNN

Johnson calls on Columbia University president to resign during tense news conference

House Speaker Mike Johnson called on Columbia University’s president to resign Wednesday during a tense news conference.

21 hours ago

A Ford sign is shown at a dealership in Springfield, Pa., Tuesday, April 26, 2022. Ford is recallin...

Chris Isidore, CNN

Ford just reported a massive loss on every electric vehicle it sold

Ford’s electric vehicle unit reported that losses soared in the first quarter to $1.3 billion, or $132,000 for each of the 10,000 vehicles it sold in the first three months of the year, helping to drag down earnings for the company overall.

22 hours ago

Sponsored Articles

Women hold card for scanning key card to access Photocopier Security system concept...

Les Olson

Why Printer Security Should Be Top of Mind for Your Business

Connected printers have vulnerable endpoints that are an easy target for cyber thieves. Protect your business with these tips.

Modern chandelier hanging from a white slanted ceiling with windows in the backgruond...

Lighting Design

Light Up Your Home With These Top Lighting Trends for 2024

Check out the latest lighting design trends for 2024 and tips on how you can incorporate them into your home.

Technician woman fixing hardware of desktop computer. Close up....

PC Laptops

Tips for Hassle-Free Computer Repairs

Experiencing a glitch in your computer can be frustrating, but with these tips you can have your computer repaired without the stress.

Close up of finger on keyboard button with number 11 logo...

PC Laptops

7 Reasons Why You Should Upgrade Your Laptop to Windows 11

Explore the benefits of upgrading to Windows 11 for a smoother, more secure, and feature-packed computing experience.

Stylish room interior with beautiful Christmas tree and decorative fireplace...

Lighting Design

Create a Festive Home with Our Easy-to-Follow Holiday Prep Guide

Get ready for festive celebrations! Discover expert tips to prepare your home for the holidays, creating a warm and welcoming atmosphere for unforgettable moments.

Battery low message on mobile device screen. Internet and technology concept...

PC Laptops

9 Tips to Get More Power Out of Your Laptop Battery

Get more power out of your laptop battery and help it last longer by implementing some of these tips from our guide.

Disney Plus Blames Past Hacks For User Accounts Sold Online