Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →The headline “Plex Confirms Database Breach, Data Theft” refers to Plex’s August 2022 security incident. Plex said an unauthorized party accessed a limited subset of a database containing email addresses, usernames, and hashed passwords. Plex also said payment-card information was not stored on its servers and was not compromised. A separate Plex security incident was disclosed on September 8, 2025, involving similar account data plus unspecified “authentication data.”
What happened in the 2022 Plex breach?
Plex said it discovered suspicious activity involving a database on August 22, 2022, and notified users on August 25, 2022. According to Plex’s incident notice, an unauthorized third party accessed a limited subset of data.
The company identified the potentially exposed information as:
- Email addresses
- Usernames
- Hashed passwords
Plex required users to reset their passwords as a precaution. The notice described the passwords as protected with bcrypt, salt, and pepper. That is materially different from storing readable passwords, but it does not make the stolen password data risk-free.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
2022 and 2025 are separate Plex incidents
Current searches can blur two different events. The headline addressed here is associated with the 2022 database breach, not the later incident.
| Date | Incident | Data Plex identified |
|---|---|---|
| August 22, 2022 | Plex discovered suspicious database activity. | Email addresses, usernames, and hashed passwords in a limited subset of data. |
| August 25, 2022 | Plex publicly notified users and required password resets. | Plex said payment-card data was not stored on its servers. |
| August 8, 2025 | Plex published a separate Media Server security update. | This was presented as a separate server-security matter, not as the confirmed cause of the later account-data incident. |
| September 8, 2025 | Plex disclosed another security incident. | Email addresses, usernames, securely hashed passwords, and “authentication data.” |
In its 2025 notice, Plex said it had contained the incident and addressed the method used to gain access. It did not define “authentication data” in the notice. That phrase should not automatically be interpreted as session cookies, API keys, refresh tokens, or active login credentials.
Were Plex passwords stolen?
Plex said the affected passwords were hashed rather than stored in plaintext. Hashing is a one-way transformation intended to prevent a database reader from simply seeing the original password. However, attackers can still attempt offline cracking against stolen hashes, especially when passwords are short, predictable, or reused.
The safest conclusion is therefore:
- There is no evidence in Plex’s notices that readable plaintext passwords were exposed.
- Hashed passwords can still create risk if they are weak or reused.
- Plex’s public notices do not provide every implementation detail needed to independently judge how resistant the hashes were to cracking.
Some 2022 coverage used the phrase “encrypted passwords.” Plex’s more precise terminology was hashed passwords, and that distinction matters.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallWas payment information exposed?
Plex said payment-card information was not stored on its servers and was not compromised in either incident. This addresses payment data held by Plex; it does not eliminate phishing, account-takeover, or social-engineering risks.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
The cited notices do not establish that credit-card numbers, bank details, Social Security numbers, addresses, birth dates, or other financial records were included in the stolen data. The breach should not be described as a credit-card exposure.
What Plex users should do
1. Reset your Plex password
Use Plex directly rather than clicking an unsolicited email link. Plex’s support instructions say to open a private or incognito browser window, go to Plex, select Sign In, choose Forgot?, and enter the account email address. Use the newest reset email: requesting another reset invalidates earlier reset links. Follow the current Plex password-reset instructions.
Choose a long, unique password that is not used for email, shopping, financial, social-media, or other accounts.
2. Change any reused password elsewhere
Password reuse is the most important practical risk. If the old Plex password appeared on another service, change it there too, prioritizing your email account and accounts that contain financial or personal information.
3. Sign out connected devices
When changing the password, select Sign out connected devices after password change where Plex presents that option. Plex’s 2025 guidance told users who sign in through a third-party single sign-on provider to use the account security page and select Sign out of all devices.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
4. Enable two-factor authentication
Turn on Plex two-factor authentication after regaining access. Also protect the email account associated with Plex, because control of that inbox can allow an attacker to reset other accounts.
5. Watch for phishing
Plex said it would not email users asking for a password or payment-card number. Be wary of fake breach notices, look-alike domains, urgent reset requests, and messages that ask you to enter a new password. Navigate to Plex manually instead.
If you cannot find the reset email
Check spam, trash, promotions, and mail-filter rules. Microsoft-hosted accounts should also be checked for Outlook or Hotmail rules. Plex’s support documentation identifies approved sender information and additional troubleshooting steps.
Do not repeatedly request reset emails without checking the latest message. Each new request can invalidate the previous reset link.
What happens to Plex Media Server after a reset?
Signing out devices or changing a password can invalidate Plex authentication credentials. A Plex Media Server owner may need to sign back into client apps, reclaim or reauthorize the server, and reconnect devices. Remote users may also need to authenticate again.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
If the server appears unavailable, shows a “not authorized” message, or temporarily displays an empty library, that does not by itself mean media files were deleted. Authentication or server-claiming problems may be responsible. Plex documents related lockout and reauthorization issues in its guide to being locked out of Server Settings.
The exact recovery steps vary by Windows, Linux, NAS, Docker, and other installations. Avoid applying operating-system-specific commands unless they match your setup and Plex Media Server version.
Were local movies and television files stolen?
Plex reported access to account data, not theft of users’ locally stored movies, television recordings, music, or personal media files. The cited notices provide no evidence that those files were exfiltrated.
That is not an absolute guarantee that every server was unaffected. If authentication credentials or tokens were misused, server access could become a separate concern. Plex did not publicly establish that local media files were accessed or copied.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What Plex has not disclosed
The public notices do not provide:
- The number of affected users or accounts
- The exact database or service involved
- The precise intrusion date
- The initial access method
- A detailed definition of “authentication data” in the 2025 incident
- Whether that data included active sessions, device tokens, refresh tokens, or another category
- Confirmation of widespread account takeover
- Evidence that the 2022 and 2025 incidents were connected
- A public independent forensic accounting of the stolen data
Those gaps should not be filled with speculation. Plex’s notices are the primary evidence for the scope of both incidents, while reporting such as TechCrunch’s 2025 coverage also noted that Plex had not clarified whether the scrambled passwords could be deciphered or how the authentication data could be used.
Recommended Free Tools
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
What the breach does—and does not—mean
- Data theft: Plex said an unauthorized party accessed a limited subset of database information.
- Account takeover: The notices do not establish that every affected account was taken over.
- Payment exposure: Plex said card data was not stored on its servers.
- Media theft: Plex reported account-data access, not theft of locally stored media files.
- Password risk: Hashed passwords are safer than plaintext, but weak or reused passwords remain a concern.
Should you buy a password manager or security product?
A password manager is useful for generating and storing a unique Plex password, but it is not required to remediate the breach. A browser or operating-system password manager may be sufficient.
Services such as Bitwarden and 1Password can generate unique passwords and support autofill, passkeys, and two-factor authentication. Their features and pricing change, so check the providers’ current pages before subscribing. Neither service can undo an exposed email address or invalidate Plex sessions without the user completing Plex’s own security steps.
A VPN does not reset a Plex password or protect against phishing. Identity-theft monitoring is not an obvious requirement based on the cited notices, which do not identify Social Security numbers or financial records as exposed. Switching media-server platforms or buying a paid Plex upgrade is likewise not an immediate breach-remediation step.
Bottom line
The “Plex Confirms Database Breach, Data Theft” headline describes the August 2022 incident. Plex said a limited database subset containing email addresses, usernames, and hashed passwords was accessed, while payment-card data was not stored on its servers. Plex disclosed a separate incident in September 2025 involving similar account information and unspecified authentication data. Users should reset their Plex password, change any reused password elsewhere, sign out connected devices, enable two-factor authentication, and treat unexpected reset messages as phishing risks.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




