Get all your news in one place.
100's of premium titles.
One app.
Start reading
The Times of India
The Times of India
World
Global Sports Desk

Twitch Streamer Data At Risk: Dark web scrape fuels scam fears; no confirmed platform breach

A database advertised on a dark web marketplace is drawing attention across the Twitch community after a threat actor claimed to possess personal information linked to around 40,000 streamers. Cybersecurity researchers have reviewed a sample of the alleged records, but early findings suggest this may not be a straightforward Twitch data breach. The bigger concern is how the information could be used against creators.

Get breaking news anytime, anywhere. Download the TOI app now!

Twitch streamer data allegedly appears in dark web database

The database was reportedly put up for sale on an illicit marketplace on September 9. According to an investigation by Cybernews, the seller claimed the collection contained Twitch usernames, profile links, email addresses, follower counts, legal names and account verification details.

Researchers examined 501 records supplied as proof of the seller’s claims. The sample reportedly included information such as usernames, profile URLs, email addresses and follower numbers. Some entries also contained creators’ real names.

However, the findings do not currently establish that a hacker broke into Twitch and stole the information.

One researcher who examined the sample said:

“From what I see, this indeed looks like a data scrape, not a breach,”

That distinction matters. Much of the information included in the database can already be found online. A streamer’s username, profile and follower count are generally visible to the public, while a legal name could potentially be pieced together through linked social media accounts or other public sources.

Some follower numbers in the alleged database were also outdated. That could indicate the information was collected over time rather than through a recent attack on Twitch.

There is, however, one detail that has raised further questions. Cybernews reportedly found email addresses that were not publicly displayed on the affected Twitch profiles. Researchers suggested this could point to misuse of Twitch’s API, although there is no confirmation that Twitch itself was compromised.

Sign up to read this article
Read news from 100's of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.