Data breach
Plex
- Records
- 123,041
- Breach date
- 2 July 2015Estimated
- Added
- 25 March 2025
What was exposed
2 types of data · 3 more reported · 1 puts you at serious risk
- Email addresses123,041
- Passwords123,034
- IP addressesReported, not counted
- Private messagesReported, not counted
- UsernamesReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
In July 2015, Plex, the media streaming and server software company, disclosed that attackers had compromised the server hosting its forums and blog. According to a security notice the company posted on its own blog, the attacker accessed personal information belonging to forum users, including email addresses, IP addresses, forum private messages, and passwords stored as salted hashes. Our investigation team's records for this breach contain 123,041 records, including 123,041 email addresses and 123,034 passwords. Because many forum accounts were linked to plex.tv accounts, Plex reset the passwords of all users with linked forum accounts and blocked access until those users completed a reset. The company said it never stores credit card or other payment data on its systems.
Breach Timeline
July 1, 2015: At approximately 1pm PDT, Plex learned that the server hosting its forums and blog had been compromised, according to the company's security notice. The forums were taken offline while the company investigated.
July 2, 2015: TechCrunch reported on the breach, noting that account and payment information were not affected, but linked forum and plex.tv accounts were.
July 6, 2015: Plex updated its notice, stating that forensic specialists had identified the source of the compromise. Attackers had entered by exploiting bugs in the forum software, some of which were not well understood or publicly patched. The investigation found no other compromised systems.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses and passwords.
Plex's security notice listed additional information exposed in the attack: IP addresses, forum private messages, and usernames. The notice stated that forum passwords were encrypted, hashed, and salted.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Exposed email addresses and password hashes can be risky even years later. If attackers crack the hashed passwords, they may try those email and password combinations on other websites, a tactic known as credential stuffing. People who reused the same password on other accounts face the greatest danger, because a single cracked password can unlock email, shopping, or banking accounts elsewhere.
Private forum messages and IP addresses add further exposure. Private messages can contain personal details useful for phishing, and IP addresses reveal approximate locations and internet providers at the time of the breach. Phishing emails that reference a person's forum activity or appear to come from Plex can seem more convincing when the sender holds real account details.
What Is Plex Doing in Response?
Plex responded quickly after learning of the intrusion. It took the forums offline while it investigated, reset the plex.tv passwords of every user with a linked forum account, and emailed affected users with instructions. The company also stated that it had no reason to believe any other part of its system was compromised and that its other systems remained online and operational. Its July 6 update said a forensic investigation found the attackers had exploited vulnerabilities in the forum software and had not reached other systems.
What Should You Do If You Were Affected?
If you had a Plex forum account in 2015, take these steps:
Change your Plex password if you have not done so since the breach, and change it anywhere else you reused the same password.
Use a unique, strong password for Plex, ideally with a password manager.
Turn on two-factor authentication for Plex and for any important accounts that offer it.
Watch for phishing emails that mention Plex, your forum activity, or password resets, and avoid clicking links in unexpected messages.
Check whether your email address appears in this or other breaches using a reputable breach search service.
