On Sept. 5, 2025, Plex, a provider of media server and streaming software, disclosed a data breach that exposed personal information belonging to its users. An investigation determined that an unauthorized actor accessed sensitive customer data on a Plex database.
According to the company’s official notice of security incident, the exposed data included email addresses, usernames, securely hashed passwords and authentication data. Plex has not disclosed the total number of affected users, but it is believed to be in the millions.
Compromised username and password details puts users at risk as many people have a tendency to use the same information across multiple platforms that require a login.
After discovering the breach, Plex GmbH took steps to contain the incident and secure its systems. The company initiated a forced password reset for all affected accounts, requiring users to set new, strong passwords.
Plex also recommended that users enable two-factor authentication (2FA) for additional protection. In their security incident notice, Plex provided detailed instructions on how to reset passwords and activate 2FA.
If you received a data breach notice or believe your personal information may have been compromised in this breach:
For more information about the streaming platform, visit the Plex website.
A breach notice means your personal details could be circulating far beyond the organization involved. One practical step is continuous monitoring: services such as Identity Defender (included with an ExpressVPN subscription) can automatically check dark-web markets, flag new credit-file activity, and request removal of your information from data-broker sites.
This kind of “early-warning system” can’t undo a breach, but it can help you spot misuse quickly and limit further exposure. ExpressVPN is offering 61% off, risk-free for 30 days, with ID Theft Insurance included and no extra cost for those who sign up for one or two years.