Action required: Important notice of a potential data breach

What a ■■■■ show. I changed my password per Plex’s suggestion (despite having a two-factor authorization on my account), and now I’m locked out, both locally and on app.plex.tv. “You do not have access to this server.” Not being able to even access my own content locally is really making me realize that Plex’s setup is way too dependent on their (apparently unsecure) cloud. Or their mass email to everyone was not well thought out on the impact it would have in general. Not cool, Plex. Not cool.

Edit: What is most bullshit about this whole thing is I disabled all of the “free” Plex BS on my account, but when I try to access MY server, all I can see is the “free” Plex BS but NONE of my local media. What. The. ■■■■.

3 Likes

the 2fa emergency keys are also stolen?

What the heck. Tried changing my password. Got an error. Now I can’t see my server anymore…

Reset passwords and logged out as per the email, cannot re-claim the server using the container version of Plex

Too many people changing the password I guess what is causing all the issues.

If you have 2Fa enabled I assume you should be ok. The recovery keys are not stored or should not have been stored at Plex so unless they have your 2FA device you should be fine for the time being.

1 Like

-e PLEX_CLAIM=
Optionally you can obtain a claim token from Claim | Plex and input here. Keep in mind that the claim tokens expire within 4 minutes.

Just be patient when changing your password, my password changed was accepted after clicking the update button 4 times over the course of 5 minutes.

This doesn’t really help the charge of the server though, so just know the authentication server is busy at the moment right after the email highlighting a security issue was sent.

BE PATIENT.

You can activate 2FA reliably in the meantime it seems. So you should do that if it’s not done already.

you have reclaim your server. its like when you set up plex for the first time, but all the data base is still there , I used the original software config that came with my NAS to redo it

on the other hand, we are asked to disconnect all accounts during the change… we must deduce that the access tokens are also included?

So, is it rue now or is it fake?
I managed to reset my password successfully but now I’m missing my server. I can not connect to it anymore!

2 Likes

There’s no way for me to “reclaim” my server. Incognito/private windows still ask for my PIN. Its useless.

Same problem. After password reset, I can’t connect to the server even locally.
The server “PLEX” is unreachable. Make sure it’s running, double check your network, and try again.

2 Likes

As was mentioned above, you have to reclaim the server. The directions are at What if Your Plex Account Requires a Password Reset? | Plex Support

3 Likes

I have a question. Does the 2 factor authentication do the job here? Also why the hell have PLEX that old system with authentication app? It is pain in the ass if you lose the phone and that was the reason I delete all my 2 factor authenticator from all my account that doesnt support something like SMS or another email as alternative!

You have to log in to the local server address http://127.0.0.1:32400/ not app.plex.tv

1 Like

Changed my password . . . logged in, all my media is missing. @$%^&*
Plex team what the hell is going on?
image

3 Likes

Thanks for the comment, have done that previously with success, just not working now

People keep repeating this, but the point is even local logon isn’t working right now. Tried reclaiming myself and not getting anywhere

1 Like

Sue the ■■■■ out of these ■■■■■■■■ Im tired of this ■■■■ having my information floating out there due to poor security measures. Wheres the ■■■■■■■ accountability?!?

I’m not convinced you know how many breaches work against companies. Look up zero day.

1 Like

I am locally logged in and under the General/Settings section and cannot find my my server to reclaim it… I am on a Syno, running Plex off Package Center. What the heck…