Thousands of Disney+ accounts hijacked

Hackers exploited the video streaming service just hours after it launched

Hackers began hijacking thousands of Disney+ user accounts just hours after the service launched, to resell on hacking forums. 

ZDNet investigation discovered many of the hacked accounts are available for free on hacking forums, or are being sold for $3 to $11 (though a legitimate subscription is only $7). 

Advertisement - Article continues below

After its launch in the US, Canada, and the Netherlands on November 12, Disney+ attracted 10 million customers in the first 24 hours. The traffic impeded video streaming speeds, and many users were unable to access their favorite movies and shows.

Amidst the flood of technical complaints, other users began reporting a total loss of access to their accounts. The reports, posted to social networks like Twitter and Reddit, described online attacks in which hackers logged users out of their accounts on every device and changed the account's email and password to lock the previous owner out.

In some cases, reported anonymously to ZDNet, users reused passwords for their Disney+ accounts, meaning hackers could have gained access by using email and password combinations leaked at other sites. Others, however, used unique passwords, suggesting credentials may have been obtained through keylogging, a program that records a computer user's keystrokes, or info-stealing malware.

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

Thousands of hijacked Disney+ accounts are now up for sale, but some are being offered to the hacker community for free using the streaming service's account sharing function.

Other streaming services have been exploited in the same way; Amazon Prime, Hulu, and Netflix accounts are still being bought and sold on hacking forums all the time.

One way Disney+ could beef up security for their users would be to use a multi-factor authentication process to log in. This would prevent attacks relying on password credentials. Users should also create unique passwords for their accounts, but that won't protect them from malware.

Disney did not respond to IT Pro's request for details on the streaming service's current security measures at the time of publication.

Featured Resources

Navigating the new normal: A fast guide to remote working

A smooth transition will support operations for years to come

Download now

Putting a spotlight on cyber security

An examination of the current cyber security landscape

Download now

The economics of infrastructure scalability

Find the most cost-effective and least risky way to scale

Download now

IT operations overload hinders digital transformation

Clearing the path towards a modernised system of agreement

Download now
Advertisement

Recommended

Visit/antivirus/28144/best-antivirus
antivirus

Best antivirus for Windows 10

30 Jun 2020
Visit/security/ethical-hacking/356252/poorly-secured-banking-apps-lead-to-cyber-threats
ethical hacking

Mobile banking apps are exposing user data to attackers

26 Jun 2020
Visit/security/malware/356231/most-malware-came-through-https-connections-in-q1-2020
malware

Most malware came through HTTPS connections in Q1 2020

25 Jun 2020
Visit/security/phishing/356211/phishing-attacks-target-unsuspecting-wells-fargo-customers
phishing

Phishing attacks target unsuspecting Wells Fargo customers

24 Jun 2020

Most Popular

Visit/laptops/29190/how-to-find-ram-speed-size-and-type
Laptops

How to find RAM speed, size and type

24 Jun 2020
Visit/policy-legislation/data-protection/356344/eu-institutions-warned-against-purchasing-any-further
data protection

EU institutions told to avoid Microsoft software after licence spat

3 Jul 2020
Visit/security/vulnerability/356295/microsoft-patches-high-risk-flaws-that-can-be-exploited-with-a
vulnerability

Microsoft releases urgent patch for high-risk Windows 10 flaws

1 Jul 2020