I think someone is lurking in/has stolen my server/

I need help. I have 45 “friends” that i didn’t authorize. I can no longer share libraries. I can no longer “unmatch” or “fix match.”

I don’t have the ability to I have a playlist with movies i would NEVER DREAM of watching. I think someone quietly stole my server, while leaving me with PARTIAL control.

I tried to set up 2FA, but my password doesn’t work. I know my password, ffs. I know people will say log out and log back in, but, i’ve had a Lifetime Plex Pass for going on 12 years. Before that, i gave the $75 as a donation, every year. Does this sound familiar to anyone?

PLEASE help.

Please contact https://www.plex.tv/contact/?option=plex-pass-billing

This is honestly my 2nd greatest fear. The greatest would be an intruder deleting my libraries…. (Thank goodness for 140m (arbitrarily chosen) automated library backups!)

I hope for you this is not what happened. :four_leaf_clover::crossed_fingers:

PS during the beginning of Lockdown my server was hit by ransom wear and all my non apps were encrypted. It took weeks to get it back to - had to negotiate down from $5000 to $2000 then the user I purchased Bitcoin from took my money and I had to start again.

Now I have smarter backups that won’t backup encrypted files and and Windows directories are backed to to Synology and Synology directories are backed to to Windows (different machines and different volumes)

So I’ve been through the worst and don’t wish that or similar to happen to anyone else.

The first step would be don’t giving Plex write access to your libraries.

You’re right,I don’t use the “admin" profile anyway because my viewing history is on another user. - so I can’t delete watches shows (news).

I’m going to be desktop and disabling that now.

Thanks for the idea/reminder

Untitled

Task completed

Thanks again @pommesmatte

Thats a first step, but that’s just a Plex setting and any intruder with your plex admin credentials could change that setting.

I meant giving the system user running your Plex processes read-only access to your media libraries.

100% understand that.

I learned a lot from being hacked. I’m pretty sure I know how they got in, but not definitely, so I try and take any and every precaution.

I think that Plex, by not having an actual separate Admin user with separate authentication, was a huge oversight and one that should be revisited.

1 Like

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.