Boxee Unboxed: Data Breach Hits Online TV Service

More than 158,000 sets of account details from the user forums of Internet-TV software maker Boxee are currently circulating online after a data breach sometime last month.

The leaked data consists of 158,128 individual user accounts, including about 172,000 email addresses, plus user names and cryptographically scrambled passwords, researchers told the tech blog Ars Technica.  Worse, the leaked data also includes the IP addresses and birthdates of users, as well as message archives and past password changes.

MORE: How to Protect Yourself From Data Breaches

Boxee makes computer software designed to put Internet content on living-room TVs. Before the company was bought by Samsung in 2013, it partnered with D-Link to make a set-top box, called a Boxee Box, that came with several apps, including Netflix, Vudu, YouTube and Pandora, and could also be used to watch over-the-air programming and record shows to a cloud-storage service.

The Boxee user forums seem to have been dormant since early August of last year, shortly after the Samsung purchase was announced.

It's not clear when the Boxee breach took place or who is responsible, but the stolen data became widely available last week, Australia-based security researcher Scott A. McIntyre told Ars Technica.

A blog posting by Risk Based Security of Richmond, Va., said the Boxee data first showed up on a Tor-protected website around March 10. Password-management service LastPass last week alerted users whose email addresses appeared in the leaked Boxee data.

The stolen data appears to only contain Boxee forum accounts, not regular Boxee service accounts. As of midday Wednesday, neither Boxee nor Samsung had issued a statement.

Think you might be affected by the Boxee breach? You can use the "Have I Been Pwned?" online tool to check if your email address is included. "Have I Been Pwned?" searches through data aggregated from several major data breaches, and the 800-megabtye Boxee file has already been added.

If your email address turns up, immediately change your Boxee password. If you use that same password anywhere else online, change it there as well.

The leaked passwords are cryptographically scrambled, but that doesn't necessarily mean users are safe. Last fall, Adobe's enormous 150 million-account data breach was made worse by the fact that every password was encrypted using the same key, and simple passwords such as "password" were easier to unscramble than a newspaper word puzzle.

Risk Based Security said someone had apparently found account data in the Boxee leak pertaining to well-known security reporter Brian Krebs. The Risk Based Security blog offers a screenshot of Krebs' partially obfuscated personal information posted to Boxee's forums, but we could find no such posting in the forums.

According to "Have I Been Pwned?" and McIntyre, Krebs' email address is not in the leaked data.

Email jscharr@techmedianetwork.com or follow her @JillScharr and Google+.  Follow us @TomsGuide, on Facebook and on Google+.

TOPICS

Jill Scharr is a creative writer and narrative designer in the videogame industry. She's currently Project Lead Writer at the games studio Harebrained Schemes, and has also worked at Bungie. Prior to that she worked as a Staff Writer for Tom's Guide, covering video games, online security, 3D printing and tech innovation among many subjects. 

Latest in Online Security
23andME box
23andMe has declared bankruptcy — here's how to delete your data now
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
A man filing his taxes electronically on a laptop
AI-powered tax scams are here - how to stay safe from deepfakes, phishing and more this tax season
MacBook Pro 2023
New Mac attack is tricking users into thinking their computer is locked — how to stay safe
Hacker using a stolen social security card
Your Social Security number is a literal gold mine for scammers and identity thieves — here’s how to keep it safe
An open lock depicting a data breach
Half a million teachers hit in major data breach with SSNs, financial data and more exposed — what to do now
Latest in News
Bill Gates in 2019
Bill Gates just predicted the death of every job thanks to AI — except for these three
NYTimes Connections
NYT Connections today hints and answers — Wednesday, March 26 (#654)
Gemini screenshot image
Google unveils Gemini 2.5 — claims AI breakthrough with enhanced reasoning and multimodal power
Samsung Galaxy Z Flip 6 review.
Samsung Galaxy Z Flip 7 design just teased in new cases leak — and the outer display is huge
Google Chrome
Chrome failed to install on Windows PCs, but Google has issued a fix — here's what happened
nyc spring day AI image
OpenAI just unveiled enhanced image generator within ChatGPT-4o — here's what you can do now
  • Bean007
    Even though the forums have been dead for awhile I'm not surprised that the company hasn't responded since they stop caring about the Boxee Box.
    Reply