Account Hacked

Server Version#:N/A
Player Version#:N/A

I got an email yesterday about someone logging in to my account as me but in another state. This was not my login. I went to the access area and found some unknown device accessed my account. How can I find out what they were able to do. My main concern is access to my photos and if they were able to download it, etc.

Any help will be appreciated.

Unless you’re using something like Trakt to monitor activity, you won’t see anything that isn’t in your Plex Media Server.*.log files (settings - Server - Troubleshooting - Download Logs)

To ensure your account is resecured,

  1. Change the password (obviously)
  2. Forcibly sign out ALL devices. See below.

Changing the password invalidates the Plex token they are holding thereby resecuring the account provided the password is strong enough.

1 Like

Hi I’m a novice at looking at the logs. what should i be looking for to determine what they have seen? I am most worried about pictures I’ve backup from my phone.

What you’ll see is listed by media item number.
Converting that to actual path takes a bit of doing; specifically constructing the URL used.

IIRC, you can see the partial query in the log and also reconstruct the URL. It’s been a while since I reverse engineering the paths so would have to do some research

I’m assuming since the login reported the ip address, I should search for the ip address to see what type of media was touch?

Yes. that’s a good path to take.
It’ll help you sift through what is there and get right to the interactions

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.