Plex has confirmed it recently experienced a “security incident.” Although the impact of the incident is understood to be limited, Plex is still asking users to reset their password to ensure their accounts remain secure.
According to Plex, an unauthorized third party managed to access one of Plex’s databases. This also resulted in the third party gaining access to what Plex says is “a limited subset of customer data.”
The accessed data is understood to have included emails, usernames, securely hashed passwords and authentication data.
Data that was not accessed during the breach was credit card information, which Plex says is not stored on its servers.
While Plex says the impact of the incident is limited, it is still recommending that all users reset their password by visiting https://plex.tv/reset.
As part of the password reset procedure, Plex also recommends enabling the “Sign out connected devices after password change” option.
The company also recommends those using SSO to sign into Plex to log out of all active sessions by visiting https://plex.tv/security and clicking ”Sign out of all devices”.
Following either of these recommendations will automatically sign the user out of Plex on all their devices, and require them to sign back in again with their new password.
For those interested in taking additional action to further protect their Plex account, the company recommends enabling two-factor authentication, if it is not already enabled.



Start the conversation