NATIONAL NEWS

Disney Plus Blames Past Hacks For User Accounts Sold Online

Nov 20, 2019, 4:22 PM

Disney+ has arrived to try and reshape the streaming landscape. (CNN Business' Frank Pallotta)

(CNN Business' Frank Pallotta)

(AP) — Disney said Disney Plus account passwords being sold in underground hacking forums are coming from previous breaches at other companies, predating last week’s launch of its streaming service.

The company reiterated Wednesday that it found no evidence of a security breach and that account problems are limited to “a very small percentage of users” of Disney Plus.

Disney and other traditional media companies are trying to capture the subscription revenue now going to Netflix and other streaming giants. Helped by promotions, including a free year for some Verizon customers, Disney Plus attracted 10 million subscribers on its first day.

The news site ZDNet found stolen account usernames and passwords selling for $3 on underground hacking forums. Disney’s streaming service costs $7 a month or $70 a year.

Despite warnings by security experts, users often reuse passwords at multiple services, meaning a breach at one opens the door for a hacker to gain access to the others.

Users can easily avoid this by using strong passwords that are unique for each service, said Troy Hunt, an Australian security researcher whose “Have I Been Pwned?” website alerts people when their identity information is stolen.

But Hunt said Disney should implement better security measures.

“The Disney situation appears to be yet another credential stuffing attack where hackers exploit a combination of customers reusing passwords and the service provider not providing sufficient defenses to stop it,” Hunt said in an email.

Paul Rohmeyer, a professor at the Stevens Institute of Technology in Hoboken, New Jersey, said he’s surprised that streaming services haven’t yet implemented better security such as multi-factor authentication.

With multi-factor authentication, users must enter a code sent as a text message or email when logging in from a new device. The code helps ensure that people using stolen passwords or guessing them can’t use a service without also having access to the legitimate user’s phone or email account.

Rohmeyer said services may be hesitant to implement tougher security because they don’t want to be seen as more inconvenient than competitors.

Multi-factor authentication is an option for many non-streaming services, including Google, Facebook and Apple, but the extra security must be turned on. Disney Plus does require codes sent by email when changing account passwords, but it doesn’t use them for logging in from new devices.

Multi-factor authentication is harder to implement for services that are shared in households, as multiple users would need access to the same phone or email account. While Disney Plus, Netflix and Hulu let family members create their own profiles, with separate watch lists and preferences, they all share the same username and password. Apple TV Plus gets around this by having each family member sign in with a separate Apple ID.

KSL 5 TV Live

National News

FILE - The logo for Boeing appears on a screen above a trading post on the floor of the New York St...

Alex Veiga, The Associated Press

Boeing locks out its private firefighters around Seattle over pay dispute

Boeing has locked out its private force of firefighters who protect its aircraft-manufacturing plants in the Seattle area and brought in replacements after the latest round of negotiations with the firefighters' union failed to deliver an agreement on wages.

10 hours ago

An illustration depicts the far side of the moon, with Earth behind it. (NASA via CNN Newsource)...

Ashley Strickland, CNN

New mission could shed light on the secrets of the moon’s ‘hidden side’

Over the past few years, competing countries have turned the moon into a hotspot for activity not witnessed since the Apollo 17 astronauts departed from the lunar surface in 1972.

14 hours ago

Shug the zebra appears to be in good health after almost six days on the loose, according to local ...

Paradise Afshar, CNN

Escaped zebra captured after nearly a week on the lam

A zebra’s almost week-long Washingtonian adventure came to an end on Friday, when the animal was recaptured after escaping from a trailer on the highway, according to local authorities.

17 hours ago

An SUV is stranded in a ditch along a stretch of street flooding during a severe storm Thursday in ...

Mary Gilbert, CNN Meteorologist and Joe Sutton, CNN

Evacuations ordered, homes damaged in Texas as rivers surge to Hurricane Harvey levels. And more rain is on the way

Flooding is intensifying in Texas, where more rain is expected over the weekend in the wake of strong storms and downpours that swept away vehicles, damaged homes and triggered evacuations.

19 hours ago

ROHNERT PARK, CALIFORNIA - APRIL 17: In an aerial view, a sign is posted on the exterior of a Red L...

Nathaniel Meyersohn, CNN

What went wrong at Red Lobster

All you can eat shrimp, might be the downfall of the seafood restaurant chain that is considering bankruptcy.

2 days ago

The loose zebra that's in King County in Washington....

Gene Johnson, Associated Press

Zebra remains on the loose in Washington state as officials close trailheads

A zebra that escaped from a trailer east of Seattle last weekend remained on the lam Friday.

2 days ago

Sponsored Articles

Side view at diverse group of children sitting in row at school classroom and using laptops...

PC Laptops

5 Internet Safety Tips for Kids

Read these tips about internet safety for kids so that your children can use this tool for learning and discovery in positive ways.

Women hold card for scanning key card to access Photocopier Security system concept...

Les Olson

Why Printer Security Should Be Top of Mind for Your Business

Connected printers have vulnerable endpoints that are an easy target for cyber thieves. Protect your business with these tips.

Modern chandelier hanging from a white slanted ceiling with windows in the backgruond...

Lighting Design

Light Up Your Home With These Top Lighting Trends for 2024

Check out the latest lighting design trends for 2024 and tips on how you can incorporate them into your home.

Technician woman fixing hardware of desktop computer. Close up....

PC Laptops

Tips for Hassle-Free Computer Repairs

Experiencing a glitch in your computer can be frustrating, but with these tips you can have your computer repaired without the stress.

Close up of finger on keyboard button with number 11 logo...

PC Laptops

7 Reasons Why You Should Upgrade Your Laptop to Windows 11

Explore the benefits of upgrading to Windows 11 for a smoother, more secure, and feature-packed computing experience.

Stylish room interior with beautiful Christmas tree and decorative fireplace...

Lighting Design

Create a Festive Home with Our Easy-to-Follow Holiday Prep Guide

Get ready for festive celebrations! Discover expert tips to prepare your home for the holidays, creating a warm and welcoming atmosphere for unforgettable moments.

Disney Plus Blames Past Hacks For User Accounts Sold Online