Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.
Plex gets hacked on Tuesday, they inform their users the next day, way to go Plex. Put's to shame many others who wait months before telling their customers they got hacked and their personal data is compromised.
 
Wish I'd never went with Plex years ago, the last data breach let my details slip onto the dark web and keeps me in spam emails on an older account for years, this one is on the same deleted account (so I thought)
 
No email from Plex to me about my account neither. I also can't get in to change my password. Does anyone know of a mitigation that can be done in the meantime? Would a simple powering off of my Plex device do any good? Or this is all on the Plex server infrastructure/account side and I am screwed unless/until I can get in to reset?
 
  • Like
Reactions: jjm3
No email from Plex to me about my account neither. I also can't get in to change my password. Does anyone know of a mitigation that can be done in the meantime? Would a simple powering off of my Plex device do any good? Or this is all on the Plex server infrastructure/account side and I am screwed unless/until I can get in to reset?
This is on their side. Are you unable to reset your password from their site?
 
If you are able to login, and you may not be able to now that you clicked that link, you can reset your password and enable MFA on your profile page.
Thank you, belvdr. I followed your advice and was able to reset my password from my Account page in Plex on my iMac. I did try to enable 2 Factor Authentication, but it requires "Use an authenticator application on your phone to get two-factor authentication codes when prompted." I don't have an 'authenticator app' on my phone and not sure what to do from there. Is there a recommended authenticator app that you know of? Thanks for your help :)
 
  • Like
Reactions: belvdr
Thank you, belvdr. I followed your advice and was able to reset my password from my Account page in Plex on my iMac. I did try to enable 2 Factor Authentication, but it requires "Use an authenticator application on your phone to get two-factor authentication codes when prompted." I don't have an 'authenticator app' on my phone and not sure what to do from there. Is there a recommended authenticator app that you know of? Thanks for your help :)
I use Google Authenticator.
 
  • Like
Reactions: jayling7
Well reset pw, enabled 2fa and broke my server. so be careful as you can fubar your self hosted server by enabling 2fa.
 
Thank you, belvdr. I followed your advice and was able to reset my password from my Account page in Plex on my iMac. I did try to enable 2 Factor Authentication, but it requires "Use an authenticator application on your phone to get two-factor authentication codes when prompted." I don't have an 'authenticator app' on my phone and not sure what to do from there. Is there a recommended authenticator app that you know of? Thanks for your help :)
I’ve been using Raivo and I think it’s great. It’s for iOS only.
 
  • Like
Reactions: jayling7
Plex gets hacked on Tuesday, they inform their users the next day, way to go Plex. Put's to shame many others who wait months before telling their customers they got hacked and their personal data is compromised.
I received an email about this at 12:41AM CST, so if they found out about this yesterday at what time? Lets say they found it around Noon.. That means 12 hours later they notified people about this. Not even next day, but hours later. SO much better than most others..
 
I actually tried to delete my account while I am at it (I never use it) but the delete account button seems to redirect me to the „reset forgotten password“ page instead with no way to actually delete it
 
Well reset pw, enabled 2fa and broke my server. so be careful as you can fubar your self hosted server by enabling 2fa.
Had something similar except I just changed password, no 2FA. When I logged into plex.tv, my account said my plex server was missing. I logged into my server and it said my server didn't belong to any account and asked me to claim it. I did, and it said I was not authorized. Sweating bullets, I just quit the Plex server and restarted it and all was fine.
 
  • Like
Reactions: mhnd
I'm still unable to create a new password when provided the link to do so. I keep getting a "The token is invalid, please request a new one" error, and it's not saving or updating to the new password I'm trying to create. BOOO.
 
Weird. Didn’t receive and email.

I didn't get anything either, if I didn't read this site I wouldn't have any idea about the site being hacked. I changed my password now anyway to a random one Apple has suggested.
 
I'm still unable to create a new password when provided the link to do so. I keep getting a "The token is invalid, please request a new one" error, and it's not saving or updating to the new password I'm trying to create. BOOO.
I think their systems will be a bit overwhelmed today. I am in the process of re-linking all my AppleTV boxes and the plex.tv/link site is a bit unstable also. Just need patience... :)
 
I actually tried to delete my account while I am at it (I never use it) but the delete account button seems to redirect me to the „reset forgotten password“ page instead with no way to actually delete it
Seems you have to reset your password first, and then go back and delete your account. That's what worked for me.
 
  • Like
Reactions: mhnd and belvdr
In case anyone runs their Plex server on a remote linux box and has trouble claiming via the web interface, this helped me get everything back to normal!

 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.