Disney+ Account Compromise

Share this post

Disney Plus Account Compromise
Disney Multi Factor Authentication leadership discussion

There are many Disney Plus accounts available for sale by fraudsters. Attackers use Credential Stuffing and Password Spraying attacks to gain access to these accounts.

CNBC has more details on the compromises.

CNBC: Hacked Disney+ accounts are being sold

What are Credential Stuffing and Password Spraying Attacks?

Credential Stuffing is when attackers take known email addresses and passwords from one site compromise and use them on another site. That is why is it very important to use different passwords for all of the systems that you use.

Password Spraying is when attackers try lots of email addresses with common passwords like “Pa$$w0rd” and try lots of them to see if any work. That is why you must not use common passwords!

What Can Disney Do?

Disney could be doing more including offering Multi Factor Authentication (MFA) as an option. MFA is when you login with something you know (password) and something you have (code from a phone). (If you are a cybersecurity professional don’t get pedantic with me. Yes, the definition is more complex but the intended audience for this post is not you.)

Multi Factor Authentication makes it much, much harder for a fraudster to compromise accounts because they need the second factor of authentication. For a service like Disney+, the return on investment would likely be too low to perpetuate the attack. (For your banking credentials, however, it may be worth an attacker’s time.)

What Can I do?

For Disney+ and all accounts you should:

  • Use a complex password.
  • Use an unique password for EVERY site. A password manager is a great tool for managing all of these passwords.
  • Turn on Multi Factor Authentication when available.

Tales From The Click

Sign up for our monthly newsletter for business leaders on minimizing cybersecurity risk.

Suceed at SOC 2

Free eBook:
5 Things to Know for your First SOC 2

  • How to scope your SOC 2
  • Estimate the cost and length of your SOC 2
  • Prepare for your SOC 2
  • Manage the SOC 2 audit period
  • Leverage your SOC 2 for growth

Related Posts

Is your Cyber Insurance really going to cover you?

Only 1/3 of cyber insurance policies actually pay out in incidents. Most companies have cyber insurance policies that insure too little, or too much, and have absurdly low caps and silly exclusions.

To learn more about cyber insurance and determine if you have the right coverage for you, join us for a free vCISO Office Hours session on Tuesday, April 18 at 1 p.m. eastern time. Bring your questions!

New Release: Free SOC 2 eBook!

Getting ready for your first SOC 2? This eBook is full of actionable advice to help you prepare for and succeed in your first SOC 2 audit.

Learn:

  • How to scope your SOC 2 project
  • How to estimate the cost and length of your SOC 2 project
  • How to prepare for your SOC 2
  • How to succeed in your SOC 2 audit period
  • How to leverage your SOC 2 report to enable your business and sales
Is your Cyber Insurance really going to cover you?

Only 1/3 of cyber insurance policies actually pay out in incidents. Most companies have cyber insurance policies that insure too little, or too much, and have absurdly low caps and silly exclusions.

To learn more about cyber insurance and determine if you have the right coverage for you, join us for a free vCISO Office Hours session on Tuesday, April 18 at 1 p.m. eastern time. Bring your questions!

New Release: Free SOC 2 eBook!

Getting ready for your first SOC 2? This eBook is full of actionable advice to help you prepare for and succeed in your first SOC 2 audit.

Learn:

  • How to scope your SOC 2 project
  • How to estimate the cost and length of your SOC 2 project
  • How to prepare for your SOC 2
  • How to succeed in your SOC 2 audit period
  • How to leverage your SOC 2 report to enable your business and sales