PSA: Twitch Data Breach

Twitch has had a data breach; the entire website has been leaked.

Leaked data includes:

  • The entirety of Twitch’s source code with comment history “going back to its early beginnings”
  • Creator payout reports from 2019
  • Mobile, desktop and console Twitch clients
  • Proprietary SDKs and internal AWS services used by Twitch
  • “Every other property that Twitch owns” including IGDB and CurseForge
  • An unreleased Steam competitor, codenamed Vapor, from Amazon Game Studios
  • Twitch internal ‘red teaming’ tools (designed to improve security by having staff pretend to be hackers)

If you use Twitch at all change your password and/or add two-factor authentication.

5 Likes

Thanks for reminding me to delete my twitch account.

11 Likes

That was my response as well.

Only made an account to use curse when they were linked. Haven’t logged in since they split. I had to reset my password to delete my account.

3 Likes

Deleting your account post data breach actually solves nothing.

6 Likes

It doesn’t stop them from using that info to log into your account?

2 Likes

Good.

1 Like

Makes sense Twitch is :poop:!

2 Likes

Indeed, I downloaded it for add-ons and now there’s no need! Thanks, WoWUp!

3 Likes

No because included in the data breech was any information attached. In other words, for people who have used a credit card or something like that, they still have that information. It’s out there. It doesn’t matter if they can’t get into your twitch account because most people use the same passwords for everything, and if their credit card was on their twitch account from a previous payment or something like that, they also have that information there already.

This is mostly going to hit people who were into donating / helping streamers, or streamers themselves of all sizes such as myself who now have to go through and ensure all of our information is correct, enable TFA, and make sure we have an eye on our bank accounts. For a broke person like me, I’m less at risk. Other people with much more financially beneficial streaming careers, they might be in trouble.

Edit: Think of it like this. Your friend does homework. You copy your friend’s homework. Your friend then trashes their homework. You still have that copy of your friend’s homework though regardless of what happened. The people who wanted that information have the copy of your information regardless of what you do involving your twitch account.

2 Likes

Let this be a lesson to why you don’t use the same password for everything on your PC. I would guess we’re going to see a spike in breach ins on accounts on everything from social media, bank accounts, to games like WoW

2 Likes

Honestly, the one failsafe in this whole situation is that people who have 2FA enabled should be safe. It’s a mild scare. The people without 2FA should be concerned for sure though.

1 Like

Even though this is good it still doesn’t protect you when companies “leak” all your information out.

1 Like

It still can limit a pretty sizable amount of damage.

They still got your credit card or bank information depending on the site.

asmongold made 2.5 million off of that …

3 Likes

I love how careful I am with coming up with really strong passwords and protecting accounts and then the websites themselves are like “teehee so they got all your info anyway cause WE didn’t have good enough security. MY BAAAAD.”

7 Likes

That amount doesn’t even include donations, merch, youtube revenue and sponsors apparently either. For all the streamers on the list.

3 Likes

yes, and he lives in that dump

Does he really, or is that part of the show? I wouldn’t be surprised to find he has another house under an LLC or trust.

2 Likes

Wait. People still use Twitch??? :rofl:

1 Like