Disney Plus blames past hacks for user accounts sold online

Nov 20, 2019, 3:51 PM | Updated: 4:04 pm

FILE - Wednesday, Nov. 13, 2019 file photo, a Disney logo forms part of a menu for the Disney Plus ...

FILE - Wednesday, Nov. 13, 2019 file photo, a Disney logo forms part of a menu for the Disney Plus movie and entertainment streaming service. Disney Plus says it doesn’t have a security breach, but some users of the new streaming service have been shut out after hackers tried to break into their accounts. (AP Photo/Steven Senne, File)

(AP Photo/Steven Senne, File)

Disney said Disney Plus account passwords being sold in underground hacking forums are coming from previous breaches at other companies, predating last week’s launch of its streaming service.

The company reiterated Wednesday that it found no evidence of a security breach, and that account problems are limited to “a very small percentage of users” of Disney Plus.

Disney and other traditional media companies are trying to capture the subscription revenue now going to Netflix and other streaming giants. Helped by promotions, including a free year for some Verizon customers, Disney Plus attracted 10 million subscribers on its first day.

The news site ZDNet found stolen account usernames and passwords selling for $3 on underground hacking forums. Disney’s streaming service costs $7 a month or $70 a year.

Despite warnings by security experts, users often reuse passwords at multiple services, meaning a breach at one opens the door for a hacker to gain access to the others.

Users can easily avoid this by using strong passwords that are unique for each service, said Troy Hunt, an Australian security researcher whose “Have I Been Pwned?” website alerts people when their identity information is stolen.

But Hunt said Disney should implement better security measures.

“The Disney situation appears to be yet another credential stuffing attack where hackers exploit a combination of customers reusing passwords and the service provider not providing sufficient defenses to stop it,” Hunt said in an email.

Paul Rohmeyer, a professor at the Stevens Institute of Technology in Hoboken, New Jersey, said he’s surprised that streaming services haven’t yet implemented better security such as multi-factor authentication.

With multi-factor authentication, users must enter a code sent as a text message or email when logging in from a new device.

The code helps ensure that people using stolen passwords or guessing them can’t use a service without also having access to the legitimate user’s phone or email account.

Rohmeyer said services may be hesitant to implement tougher security because they don’t want to be seen as more inconvenient than competitors.

Multi-factor authentication is an option for many non-streaming services, including Google, Facebook and Apple, but the extra security must be turned on. Disney Plus does require codes sent by email when changing account passwords, but it doesn’t use them for logging in from new devices.

Multi-factor authentication is harder to implement for services that are shared in households, as multiple users would need access to the same phone or email account. While Disney Plus, Netflix and Hulu let family members create their own profiles, with separate watch lists and preferences, they all share the same username and password. Apple TV Plus gets around this by having each family member sign in with a separate Apple ID.

We want to hear from you.

Have a story idea or tip? Send it to the KSL NewsRadio team here.

Two horses on the loose bolt through the streets of London near Aldwych, on Wednesday April 24, 202...

Pan Pylas, Associated Press

Rush hour chaos in London as 5 military horses run amok after getting spooked during exercise

LONDON (AP) — Five military horses spooked by noise from a building site bolted during routine exercises on Wednesday near Buckingham Palace, threw off four riders and caused chaos as they galloped loose through central London streets and collided with vehicles during the busy morning rush hour. The commotion erupted when the horses from the […]

4 hours ago

House Speaker Mike Johnson talks to the press after the House passed four foreign aid bills at the ...

Haley Talbot, Lauren Fox and Clare Foran, CNN

Johnson calls on Columbia University president to resign during tense news conference

House Speaker Mike Johnson called on Columbia University’s president to resign Wednesday during a tense news conference.

5 hours ago

Agriculture officials said the fire most likely started after a piece of equipment malfunctioned at...

Emma Keddington and Simone Seikaly

Equipment malfunction suspected after fire at Utah egg farm

A 21,000 square foot barn at Oakdell Egg Farms quickly caught fire when a power washer caught fire.

6 hours ago

FILE: An arson investigation is underway after several suspicious fires in Salt Lake City on Tuesda...

Britt Johnson

Salt Lake City Fire conduct arson investigation Tuesday morning

An arson investigation is underway after several suspicious fires in Salt Lake City on Tuesday.

7 hours ago

Wine bottles are pictured at a state liquor store in Salt Lake City on Friday, Oct. 23, 2020....

Jeff Caplan

Jeff Caplan’s Minute of News: How people get drunk WITHOUT drinking

Try explaining this condition to a cop.

8 hours ago

Ahead of the NHL to Utah party on Wednesday, Utahns crowded the plaza of the Delta Center and waite...

Simone Seikaly, Eric Cabrera, Emma Keddington, Adam Small

Utahns showing up for the NHL in Utah

Ahead of the NHL to Utah party, Utahns crowded the plaza of the Delta Center and waited in long lines for the party to start.

9 hours ago

Sponsored Articles

a doctor putting her hand on the chest of her patient...

Intermountain Health

Intermountain nurse-midwives launch new gynecology access clinic

An access clinic launched by Intermountain nurse-midwives provides women with comprehensive gynecology care.

Young couple hugging while a realtor in a suit hands them keys in a new home...

Utah Association of Realtors

Buying a home this spring? Avoid these 5 costly pitfalls

By avoiding these pitfalls when buying a home this spring, you can ensure your investment will be long-lasting and secure.

a person dressed up as a nordic viking in a dragon boat resembling the bear lake monster...

Bear Lake Convention and Visitors Bureau

The Legend of the Bear Lake Monster

The Bear Lake monster has captivated people in the region for centuries, with tales that range from the believable to the bizarre.

...

Live Nation Concerts

All the artists coming to Utah First Credit Union Amphitheatre (formerly USANA Amp) this summer

Summer concerts are more than just entertainment; they’re a celebration of life, love, and connection.

Mother and cute toddler child in a little fancy wooden cottage, reading a book, drinking tea and en...

Visit Bear Lake

How to find the best winter lodging in Bear Lake, Utah

Winter lodging in Bear Lake can be more limited than in the summer, but with some careful planning you can easily book your next winter trip.

Happy family in winter clothing at the ski resort, winter time, watching at mountains in front of t...

Visit Bear Lake

Ski more for less: Affordable ski resorts near Bear Lake, Utah

Plan your perfect ski getaway in Bear Lake this winter, with pristine slopes, affordable tickets, and breathtaking scenery.

Disney Plus blames past hacks for user accounts sold online