New unknown user accessed my server

Hi,

I just got a notification that a new user has accessed my server. I didn’t recognize the email. I checked my user list and this email was added with all of my libraries shared with them. I also noticed that media was being downloaded under my Plex username, but it wasn’t me.

I immediately deleted that random account from my server. I also changed my password. I do have 2-factor enabled. But it wasn’t like this person accessed my Plex account… just like they somehow added themselves to my server. Any thoughts on how this happened or what else I can do to prevent this? Should I change my router port?

Thanks.

Do you run Tautulli? If so, make sur you’ve enabled the security feature in there. We’ve seen malicious users gain access to an account through that.

Thanks for the reply! I do run Tautulli. How do I enable the security feature? Is is best to uninstall Tautulli? I don’t need it.

I believe the security feature is to just require signing in, but I’m not sure. It’s come up before so a search should reveal something.

Thank you for your help! I think this has to be it. Like a dum dum, I did indeed have my Tautulli port open and not password protected. I feel like an idiot. I set it up so long ago, not thinking twice about who could access it. Well, it’s uninstalled now and that port is closed. Thank you again!

I also run tautulli for the stats (love stats).

However, it is running only locally for my personal use and the port is not opened on the router to the Internet.

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.