Disney+ Blames Past Hacks for User Accounts Sold Online

Despite warnings by security experts, users often reuse passwords at multiple services.

Advertisement
By Associated Press | Updated: 21 November 2019 16:43 IST

Photo Credit: Robyn Beck/ AFP

Disney said Disney+ account passwords being sold in underground hacking forums are coming from previous breaches at other companies, predating last week's launch of its streaming service.

The company reiterated Wednesday that it found no evidence of a security breach and that account problems are limited to “a very small percentage of users” of Disney+.

Disney and other traditional media companies are trying to capture the subscription revenue now going to Netflix and other streaming giants. Helped by promotions, including a free year for some Verizon customers, Disney+ attracted 10 million subscribers on its first day.

Advertisement

The news site ZDNet found stolen account usernames and passwords selling for $3 (roughly Rs. 210) on underground hacking forums. Disney's streaming service costs $7 (roughly Rs. 500) a month or $70 (roughly Rs. 5,000) a year.

Advertisement

Despite warnings by security experts, users often reuse passwords at multiple services, meaning a breach at one opens the door for a hacker to gain access to the others.

Users can easily avoid this by using strong passwords that are unique for each service, said Troy Hunt, an Australian security researcher whose "Have I Been Pwned?" website alerts people when their identity information is stolen.

Advertisement

But Hunt said Disney should implement better security measures.

“The Disney situation appears to be yet another credential stuffing attack where hackers exploit a combination of customers reusing passwords and the service provider not providing sufficient defences to stop it,” Hunt said in an email.

Advertisement

Paul Rohmeyer, a professor at the Stevens Institute of Technology in Hoboken, New Jersey, said he's surprised that streaming services haven't yet implemented better security such as multi-factor authentication.

With multi-factor authentication, users must enter a code sent as a text message or email when logging in from a new device. The code helps ensure that people using stolen passwords or guessing them can't use a service without also having access to the legitimate user's phone or email account.

Rohmeyer said services may be hesitant to implement tougher security because they don't want to be seen as more inconvenient than competitors.

Multi-factor authentication is an option for many non-streaming services, including Google, Facebook, and Apple, but the extra security must be turned on. Disney+ does require codes sent by email when changing account passwords, but it doesn't use them for logging in from new devices.

Multi-factor authentication is harder to implement for services that are shared in households, as multiple users would need access to the same phone or email account. While Disney+, Netflix, and Hulu let family members create their own profiles, with separate watch lists and preferences, they all share the same username and password. Apple TV+ gets around this by having each family member sign in with a separate Apple ID.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Disney Plus
Advertisement

Related Stories

Popular Mobile Brands
  1. Top OTT Releases of the Week (Sept 1 - Sept 7): Know What to Watch
  2. Flipkart Big Billion Days Sale Date Revealed, Will Compete With Amazon Sale
  3. Oppo Reno 14 FS 5G Launches in Select Global Markets With These Features
  4. Samsung Galaxy S24 5G With Snapdragon 8 Gen 3 Chip to Launch in India Soon
  5. Moto Book 60 Pro With Up to Intel Core Ultra 7 CPU Launched in India
  6. Amazon Great Indian Festival 2025: Smartphone Deals Teased Ahead of Sale
  7. You Can Now Create Projects in ChatGPT Without Paying for a Subscription
  8. Huawei FreeBuds 7i Launched With ANC, Spatial Audio Support: See Price
  1. OnePlus 15 Confirmed to Feature DetailMax Camera Engine; Tipster Hints at Next-Gen BOE Oriental Display
  2. Moto Book 60 Pro Launched in India With Up to Intel Core Ultra 7 CPU, 14-Inch OLED Screen
  3. OpenAI to Challenge LinkedIn With New AI-Powered Jobs Platform in 2026
  4. Samsung Galaxy S24 5G With Snapdragon 8 Gen 3 Chip Confirmed to Launch in India, Will Go on Sale via Flipkart
  5. Huawei FreeBuds 7i Launched With ANC, Spatial Audio Support: Price, Specifications
  6. Bitcoin Holds Steady As Ethereum Gains From Strong ETF Demand
  7. Lava Bold N1 5G Launched in India With 90Hz HD+ Display and 13-Megapixel Rear Camera: Price, Specifications
  8. Hollow Knight: Silksong's Massive Launch Crashes Steam, PlayStation, Xbox and Nintendo Storefronts
  9. Amazon Great Indian Festival 2025: Deals on Samsung Galaxy S24 Ultra, iPhone 15, OnePlus 13s Teased Ahead of Sale
  10. Adobe Premiere App for iOS Introduced With Desktop-Like Controls, Generative AI Tools
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.