Action required: Important notice of a potential data breach

After getting the email about their hacker and told to change password, I decided to delete my account instead since I have t used it in over 2 years. Guess what? I can’t.
“I tried to delete my account using the Link in red at the bottom of my account page. It leads to a page to reset my password instead. Which leads to sending me an email, which leads to creation of a new password.

Accident in the link on the page? Or intentional by the hackers?”

I was able to reset my password and claim my server (after going through the hassle of removing and re-adding it), but I am getting this error when trying to access it from https://app.plex.tv/

app.plex.tv is unable to connect to “fakeservername” securely

Its “Secure connections” setting may be set to disabled, or you may need to adjust some settings on your network. You can [learn more about secure connections here]

My secure settings are definitely not set to disabled. I am guessing this is an issue on Plex’ side since I haven’t changed any settings since resetting my login info.

1 Like

it’s real just google plex and click news all the articles come up, not sure why I haven’t received the reset password email after going to change it, i even tried to delete my account and no password has been sent WTF PLEX.

THANK YOU from me as well - again this was the only thing that worked on my QNAP Container Station

Plex put additional safety measures in place after the incident.

You need to change your password before deleting your account.

To change your password bypassing e-mails:

  1. Go to Account Settings, https://app.plex.tv/desktop/#!/settings/account.
  2. Scroll down to Password, choose Edit.
  3. Enter new password (twice), and current password.
  4. Check the box to sign out of connected devices.
  5. Save changes.

Note that changing your password places your server in an unclaimed state. You will need to re-claim it before streaming any media.

You should also be able to delete your account if desired.

1 Like

Restarting the Plex Server resolved this for me, it does take a couple of minutes to connect and then you need to do the ‘reclaim’ step too.

When I initially read the eMail from plex the line below jumped out at me …

Even though all account passwords that could have been accessed were hashed and secured in accordance with best practices, out of an abundance of caution we are requiring all Plex accounts to have their password reset.

If they indeed are requiring all plex accounts to reset their passwords then I do wonder why they just didn’t invalidate all on their side and force folks to create new ones ? I understand that would have likely caused havoc but its the only way this requirement could be enforced. As of now its a recommendation from plex and not a requirement.

Anyhow, I’ve subsequently chalked it up to inaccurate wording when the eMail was sent out, most likely in a rush.

1 Like

Same here !
I can’t get enough of this application and all its failures !

A question for Plex - was DOB in the data that was hacked ?

1 Like

Run PMS on Shield and so far I have managed after several attempts to get password reset through Plex Web, but Plex no longer sees Shield and my libraries. It’s running correctly on Shield itself and everything looks normal there, but the Roku app and Plex Web doesn’t see Shield as an option any longer. I re-link acct from Shield and no joy.
At first Plex saw the Shield but said he couldn’t connect so I removed it from Plex Web but now nothing appears except Your Media.

Thanks! This method also worked for me.

Same for me

Yes it is real

Well, I bit the bullet and decided to change my password. By accident, I didn’t select log me out of other devices. I’m not sure if that mattered. Anyway, I did not have to reclaim my server which is strange, although I don’t ever remember having to claim my server.

And I didn’t have to do anything to my Plex Docker container either. Documentation here said I needed to set PLEX_CLAIM to the value of the claim token. I never had that before.

But I’m back up.

You didn’t have to re-claim the server and log-in every single device because you never logged them out. I did the same thing. If you notice people streaming that you don’t know worry about it then. Until that happens it doesn’t matter as long as the password is at least changed.

The need to reclaim a server is directly linked to signing out all devices. The “all devices” includes any server linked to an account.

So, am I OK? And are my friends OK?

Honestly, I only use Plex on my desktop, laptop, TV, PS4, TV, and phone. Well, I guess that’s a lot. However, I went to each device and signed out and back in.

Help !

Based on your screenshot above it appears you need to claim your server after changing your password. See What if Your Plex Account Requires a Password Reset? | Plex Support and the section on how to claim your server (local/bundled web client).