Skip to main content
Breach Signal

Breach report

Gaming

Twitch (Amazon)

Twitch confirms hack after source code and creator payout data leaks online

An anonymous hacker leaked roughly 125GB of Twitch's internal data in October 2021, including the site's source code, internal tools and years of creator payout figures, which quickly spread across social media.

Reported by TechCrunch

Records exposed

Undisclosed

About 125GB of internal data, including creator payout records since 2019

When
2021
How they got in
Server configuration error exploited by hacker
Sector
Gaming

On October 6, 2021, an anonymous user posted a torrent link on the 4chan message board containing what was described as a huge trove of data taken from Twitch, the Amazon-owned live-streaming platform. The archive, about 125 gigabytes, was labeled as the first part of a larger leak. Twitch confirmed that day that it had been breached and said it was working urgently to understand the scope.

The leak included source code for Twitch's website and its mobile, desktop and console clients, drawn from thousands of internal code repositories. It also contained proprietary software development kits, internal Amazon Web Services tooling, code related to other properties such as the game database IGDB, material about an unreleased game distribution service reportedly codenamed Vapor, and internal red-team security tools. The item that drew the most attention was a set of creator payout reports dating back to 2019, which revealed what many of the platform's most popular streamers had earned. Several streamers confirmed the figures matched their own records.

Twitch later said the breach resulted from an error in a server configuration change that allowed improper access by a malicious third party. It said it had no indication that login credentials had been exposed and that full credit card numbers were not stored by the company. As a precaution, Twitch reset all stream keys, and it encouraged users to turn on two-factor authentication. The poster said the leak was meant to encourage disruption and competition in the streaming space and criticized the platform's community.

The leak landed during a turbulent period for Twitch. Streamers had recently organized protests over harassment campaigns known as hate raids, and the payout data fueled public debate about how much creators earn and how the company shares revenue. Security experts warned that exposing source code could help attackers find vulnerabilities, although no major follow-on attacks were publicly tied to the leak.

The incident showed that a breach does not need to include passwords or payment data to be damaging. Source code, internal tools and confidential business figures can harm a company's competitive position and relationships with its partners. It also illustrated how configuration mistakes in cloud infrastructure can open the door to wholesale data theft, a recurring theme in breaches across the industry.

More from the wire

More in Gaming.

All 107 reports

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life’s most important information stays protected and accessible.