TL;DR: A dark‑web listing claims personal data on 40,000 Twitch streamers-usernames, follower counts, emails, legal names-was offered for sale. Researchers say the sample looks like scraped public and linked‑profile data rather than a Twitch breach, though hidden emails and possible OAuth token misuse raise concerns. Enable 2FA and update passwords.
Voice: Jak ConnorSpeed
0:00 / 2:13
Use left and right arrow keys to seek audio.
A hacker is offering a database allegedly containing personal information on 40,000 Twitch streamers. The data was advertised on a renowned dark web marketplace and reportedly includes usernames, email addresses, legal names, follower counts, and more.
Researchers examining a sample of 501 records say the data appears to have been scraped rather than stolen through a direct breach, meaning Twitch itself wasn’t hacked and the information on the streamers was obtained elsewhere.
Popular Now: RTX 5090 stock dries up as prices soar past $10,000
Publicly available information like usernames and follower counts is already accessible, while legal names may have been pulled from linked social profiles. However, the database contained hidden email addresses, suggesting the Twitch API could have been exploited using stolen access tokens. However, that isn’t confirmed, either.
- Read more: Verified Steam game exposed for robbing streamer’s cancer donations
“From what I see, this indeed looks like a data scrape, not a breach,” said one of the CyberNews researchers working on the database
Twitch has responded by advising users to remove third-party browser extensions and review their account security, but, funnily enough, didn’t actually mention which extension to remove.
“The information of many creators is aggregated to one place, making it easier for a malicious actor to profile these people and possibly craft social engineering scams,” one of the researchers explained
How could Twitch streamers’ legal names and hidden email addresses end up in a dark web database without a Twitch breach?
Researchers believe the data was largely scraped rather than taken in a direct Twitch breach, so Twitch itself may not have been hacked. Legal names could have been gathered from linked social profiles, while the hidden email addresses may have been exposed if someone abused the Twitch API with stolen access tokens, though that part is not confirmed.
Question #2
What signs led researchers to think the 40,000-record dataset was scraped instead of stolen?
Which Twitch account security settings should streamers review after this data sale claim?
What does Twitch Enhanced Viewer do, and why was it flagged as malicious?
Have a question that isn’t listed here? Ask below, and TweakBot will answer it.
However, one to absolutely remove is a malicious extension called Twitch Enhanced Viewer, which was found forwarding OAuth tokens to external servers, though no direct link to the advertised database has been confirmed. Creators are urged to enable two-factor authentication, use strong passwords, and verify suspicious communications. Following this discovery it’s highly recommended to change any of your Twitch account passwords.
