Action required: Important notice of a potential data breach

For some additional information, passwords were hashed with bcrypt, salted and peppered.
While we’re still investigating, we’re requiring all users to reset their passwords. Everyone will get an email, but not all at once, we’re trying to stagger this to manage the load.

If we had invalidated everyone’s password at once, we’d have had tens of millions of people hitting our servers at once trying to set a new password, and honestly, we can’t handle everyone doing that at once.

We’d strongly suggest everyone also revoke their tokens by signing out all devices. While we’re still investigating the issue, there is a risk that authentication tokens may have been compromised. We’re being abundantly cautious here, because we want to do everything we can to preserve security for our users.

Password reset emails are taking a little longer than normal, due to the amount of traffic we’re getting. You can also go directly to https://app.plex.tv/desktop/#!/settings/account to reset your password.

Should you have any difficulty with claiming your server afterwards, please ensure you’ve followed all the steps here. If you’re still having difficulties, please post specifics about your setup (OS, server version, how you access it, etc.) so that we can help

9 Likes