Netflix
We've seen a steady rise in credential stuffing attacks targeting streaming services over the past year, but a recent discovery stood out. What initially appeared to be another collection of leaked email/password combinations quickly revealed itself to be far more granular, including specific viewing history data, device information, and even billing addresses. This level of detail suggests a more targeted compromise than typical stealer logs or scraped databases. The data had been circulating quietly on a private Telegram channel frequented by account resellers, but we noticed the asking price was significantly higher than usual – indicating a perception of higher value within that community.
### The Netflix Data Trove: 1.4 Million Accounts Exposed with Viewing History and Payment Data
A significant breach impacting **Netflix** has been identified, exposing approximately **1.4 million** user accounts. This breach goes beyond simple credential leaks, including detailed viewing history, device information, and partial payment details. The initial discovery occurred on **July 12, 2024**, when Darkwatch analysts detected unusual activity on a private **Telegram** channel known for trading compromised accounts. What caught our attention wasn't the volume of data, but the specificity: The dataset included not just email addresses and passwords, but also viewing preferences, device types used for streaming, and the first few digits of credit card numbers associated with the accounts. This level of detail is atypical for standard credential dumps and suggests a more sophisticated compromise. Given the sensitivity of the exposed data, and the potential for identity theft and financial fraud, this breach represents a significant risk for affected users and highlights the ongoing vulnerability of streaming platforms to sophisticated attacks. This incident also serves as a stark reminder of the value of user data to malicious actors, and the need for robust security measures to protect against data breaches.
* **Total records exposed:** 1,400,000
* **Types of data included:** Emails, usernames, passwords (likely hashed, but potentially cracked), viewing history, device information (IP addresses, device types), partial credit card numbers (first 6 digits), billing addresses.
* **Sensitive content types:** PII, financial data
* **Source structure:** JSON dump, likely originating from a compromised internal API or database.
* **Leak location:** Private Telegram channel (specific URL withheld for security reasons). Date of first appearance: July 12, 2024.
The breach has not yet been widely reported in mainstream media, but discussions on cybersecurity forums and social media platforms like **X (Twitter)** suggest growing awareness within the security community. One Telegram post claimed the files were "collected from devs testing an AI project" – a claim that remains unverified but highlights the potential for insider threats or supply chain compromises. Security researcher **Troy Hunt** has also acknowledged the breach on **X**, stating that he is "investigating reports of a large Netflix data dump" and urging users to enable two-factor authentication where available. This incident bears similarities to previous breaches targeting streaming services, as detailed in a **2023 report by Akamai** on credential stuffing attacks in the media and entertainment industry. The report highlights the increasing sophistication of these attacks, with attackers using automated tools and techniques to bypass traditional security measures.
Breach Breakdown
44 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds