Dark web hacker claims to have stolen 40,000 Twitch streamers’ personal info


A threat actor is selling a database they claim contains the personal information of approximately 40,000 Twitch streamers, but researchers doubt the data came from a direct breach of the platform.

The dataset was advertised on a well-known illicit marketplace on September 9, according to a Cybernews investigation.

The seller claims it contains Twitch usernames, profile URLs, email addresses, legal names, follower counts and account verification statuses.

Cybernews examined a sample of 501 records provided as evidence. Researchers found usernames, profile links, emails, follower totals and, in some cases, creators’ full names.

However, they believe the information was likely gathered through scraping instead of being stolen by directly hacking Twitch.

“From what I see, this indeed looks like a data scrape, not a breach,” one researcher said.

Twitch streamers warned of targeted phishing risk

Much of the advertised information, including usernames and follower counts, is already publicly accessible. Legal names could also have been collected from creators’ connected social media profiles.

Some follower totals were outdated, suggesting the database may not have been compiled recently.

hacker selling twitch streamer info

However, researchers reportedly found email addresses that were not publicly visible on the affected creators’ Twitch profiles. Cybernews said this raises the possibility that the platform’s API was abused, potentially using either the attacker’s own access token or one stolen from somebody else.

There is currently no confirmation that Twitch itself was breached. Dexerto has contacted the Amazon-owned company for comment.

Even if the database was built largely from public information, researchers warned that collecting it in one place could make targeted scams easier.

“The information of many creators is aggregated to one place, making it easier for a malicious actor to profile these people and possibly craft social engineering scams,” Cybernews explained.

Attackers could pose as brands or Twitch representatives, using a streamer’s real name, audience size and email address to make fraudulent sponsorship offers or account verification messages appear legitimate.

Twitch responds after malicious browser extension impacts 30,000 users

The alleged database sale comes days after security researchers at Socket found that “Twitch Enhanced Viewer | JeetBot,” a third-party Chrome and Firefox extension with approximately 31,000 users, was forwarding live Twitch OAuth tokens through servers controlled by its operator.

Those tokens could potentially be used to access accounts without passwords or two-factor authentication, including sending messages, changing settings, and spending channel points. There is currently no evidence connecting the extension to the database advertised on the dark web.

Twitch responded by stressing that Twitch Enhanced Viewer is an unofficial third-party browser extension and is not affiliated with the platform. The company said it had revoked potentially exposed access tokens, which would automatically sign affected users out, and advised anyone who installed the extension to remove it immediately.

Creators are advised to enable two-factor authentication, use unique passwords and independently verify unexpected sponsorship or Twitch support emails before opening links.

This isn’t the first time Twitch data has been exposed. The Amazon-owned platform suffered a confirmed major data breach in 2021 that exposed source code and creator earnings. The platform subsequently reset every user’s stream key as a precaution.





Source link

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top