• Contact Us
  • Login
Upgrade
Tech News Hero
Advertisement
  • Home
  • News
  • Gadgets
  • Social
  • Gaming
  • Mobile
  • PC
  • Internet
  • Security
  • Apps
No Result
View All Result
  • Home
  • News
  • Gadgets
  • Social
  • Gaming
  • Mobile
  • PC
  • Internet
  • Security
  • Apps
No Result
View All Result
Tech News Hero
No Result
View All Result
Home Security

Thousands of hacked Disney+ accounts are already for sale on hacking forums

by technewshero
November 16, 2019
in Security
0
Share on FacebookShare on Twitter
Disney+ login page

Hackers didn’t waste any time and have started hijacking Disney+ user accounts hours after the service launched.

Many of these accounts are now being offered for free on hacking forums, or available for sale for prices varying from $3 to $11, a ZDNet investigation has discovered.

A stream of user complaints

The Disney+ video streaming service launched this week, on November 12. The service, although being available only in the US, Canada, and the Netherlands, has already amassed more than 10 million customers in its first 24 hours.

The Disney+ launch was marred by technical issues. Many users reported being unable to stream their favorite movies and shows.

But hidden in the flood of complaints about technical issues was a smaller stream of users reporting losing access to their accounts.

Many users reported that hackers were accessing their accounts, logging them out of all devices, and then changing the account’s email and password, effectively taking over the account and locking the previous owner out.

Complaints like the ones above flooded social networks like Twitter and Reddit.

disney-reddit.png

Image: ZDNet

Disney + launch has been absolutely horrible. Their customer service is no help at all and apparently hundreds of accounts were hacked and sold online. My account got hacked & email/password changed, thankfully I cancelled my subscription before the hack.

— Harry (@Harry8__) November 15, 2019

#distwitter has anyone’s @disneyplus account been hacked? My friend’s was; hackers changed email and password. Now she’s completely blocked from her 3-year prepaid Disney+ account. She’s been on hold for >2 hours

— cat+dog=happyhome (@Travel4vr) November 12, 2019

Two users who spoke with ZDNet on the condition we do not share their names admitted that they reused passwords. However, other users said online that they did not, and had used passwords unique for their Disney+ accounts.

This suggests that in some cases hackers gained access to accounts by using email and password combos leaked at other sites, while in other cases the Disney+ credentials might have been obtained from users infected with keylogging or info-stealing malware.

Up for sale!

The speed at which hackers have mobilized to monetize Disney+ accounts is astounding. Accounts were put up for sale on hacking forums within hours after the service’s launch.

As of this article’s writing, hacking forums have been flooded with Disney+ accounts, with ads offering access to thousands of account credentials.

Prices vary from $3 per account to as much as $11 — which, by the way, is more than what a legitimate Disney+ account costs from Disney, which is $7.

Below are screenshots that ZDNet took of various ads, along with screenshots we received from multiple sources that helped our investigations.

disney-empire-search.png

Search results for Disney+ accounts on a dark web marketplace


Image: ZDNet

disney-plus-sale-banner.jpg

Ad for Disney+ accounts on a Russian language marketplace


Image: Supplied by source

disney-feeds.jpg

Screenshot of a threat intel feed for Disney+ accounts being sold on a Russian marketplace


Image: Supplied by source

screenshot-2019-11-15-at-20-58-48.png

Online store selling hacked Disney+ accounts


Image: Supplied to ZDNet by Gemini Advisory

screenshot-2019-11-15-at-20-50-37.png

Post on a hacking forum advertising access to hacked Disney+ accounts


Image: Supplied to ZDNet by Gemini Advisory

screenshot-2019-11-15-at-20-47-52.png

Similar ad, on the same hacking forum


Image: Supplied to ZDNet by Gemini Advisory

screenshot-2019-11-15-at-20-58-30.png

Another ad for hacked Disney+ accounts on a different hacking forum


Image: Supplied to ZDNet by Gemini Advisory

disney-shoppy.jpg

Ad on an online marketplace selling access to hacked Disney+ accounts


Image: Supplied by source

However, in our search for ads on various hacking forums, we also came across several lists of Disney+ account credentials being offered for free, to be shared and used by the hacker community (Disney+ allows account sharing).

When we looked into the lists, we found usernames and cleartext credentials. We emailed some users on two lists, and some replied, confirming that the credentials were theirs, and still active.

disney1-0.png

Hackers sharing access for free to hacked Disney+ accounts


Image: ZDNet

disney1-1-199.png

Image: ZDNet
disney2-0.png

Hackers sharing access for free to hacked Disney+ accounts


Image: ZDNet

disney2-1-1001.png

Image: ZDNet
disney3-0.png

Hackers sharing access for free to hacked Disney+ accounts


Image: ZDNet

disney3-1.png

Image: ZDNet

ZDNet also reached out to Disney for comment. We asked the company about the security systems it has in place to protect users from account hijacking. We did not receive a response before this article’s publication.

But to be fair, the company has little it can do in these kind of things. It’s usually users’ bad password practices that gets the accounts hacked. As some of the hacked users have admitted, many have reused old passwords.

What Disney+ is facing right now is what other streaming services have been fighting against for years. Hacking forums have been overflowing with hacked Amazon Prime, Hulu, and Netflix accounts. The reason hackers are still puting up new accounts for sale on a regular basis is because people are buying.

The advice for Disney+ account holders is to use unique passwords for their accounts. This won’t prevent malware on their devices from stealing their passwords, but it will prevent the most common scenario of hackers gaining access to accounts just by guessing the password.

ZDNet would like to thank Andrei Barysevich, CEO and Co-Founder of Gemini Advisory, for his help on researching this article.

Previous Post

MacBook Pro 16-inch is powerful enough to drive two 6K monitors

Next Post

WhatsApp in 2019: All the New Features the Chat Service Added This Year

technewshero

technewshero

Related Posts

2020 Shows the Danger of a Decapitated Cyber Regime
Security

2020 Shows the Danger of a Decapitated Cyber Regime

by technewshero
January 13, 2021
A ‘Bulletproof’ Criminal VPN Was Taken Down in a Global Sting
Security

A ‘Bulletproof’ Criminal VPN Was Taken Down in a Global Sting

by technewshero
January 14, 2021
The Worst Hacks of 2020, a Surreal Pandemic Year
Security

The Worst Hacks of 2020, a Surreal Pandemic Year

by technewshero
January 15, 2021
Security

How Your Digital Trails Wind Up in the Police’s Hands

by technewshero
December 31, 2020
How to Understand the Russia Hack Fallout
Security

How to Understand the Russia Hack Fallout

by technewshero
December 22, 2020
Next Post

WhatsApp in 2019: All the New Features the Chat Service Added This Year

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Most Popular

Best microSD cards of 2019: flash memory for cameras, drones and more

November 7, 2019

Cloudflare co-founder Michelle Zatlyn on the company’s IPO today, its unique dual class structure, and what’s next – TechNewHero

September 14, 2019
5G to Launch in France in November, Observatory Being Set Up to Track Rollout

5G to Launch in France in November, Observatory Being Set Up to Track Rollout

December 13, 2020

Browse by Category

  • Apps
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • News
  • PC & Laptops
  • Security
  • Social
Tech News Hero

© 2020 Tech News Hero.

No Result
View All Result
  • Home
  • Landing Page
  • Buy JNews
  • Support Forum
  • Contact Us

© 2020 Tech News Hero.

Welcome Back!

Login to your account below

Forgotten Password?

Create New Account!

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?