Dark web hacker claims to have stolen personal information of 40,000 Twitch streamers
US Streamers News: A database advertised on a dark web marketplace is drawing attention across the Twitch community after a threat actor claimed to possess personal info.
A database advertised on a dark web marketplace is drawing attention across the Twitch community after a threat actor claimed to possess personal information linked to around 40,000 streamers. Cybersecurity researchers have reviewed a sample of the alleged records, but early findings suggest this may not be a straightforward Twitch data breach. The bigger concern is how the information could be used against creators.Twitch streamer data allegedly appears in dark web databaseThe database was reportedly put up for sale on an illicit marketplace on September 9. According to an investigation by Cybernews, the seller claimed the collection contained Twitch usernames, profile links, email addresses, follower counts, legal names and account verification details.Researchers examined 501 records supplied as proof of the seller’s claims. The sample reportedly included information such as usernames, profile URLs, email addresses and follower numbers. Some entries also contained creators’ real names.However, the findings do not currently establish that a hacker broke into Twitch and stole the information.One researcher who examined the sample said:“From what I see, this indeed looks like a data scrape, not a breach,”That distinction matters. Much of the information included in the database can already be found online. A streamer’s username, profile and follower count are generally visible to the public, while a legal name could potentially be pieced together through linked social media accounts or other public sources.Some follower numbers in the alleged database were also outdated. That could indicate the information was collected over time rather than through a recent attack on Twitch.There is, however, one detail that has raised further questions. Cybernews reportedly found email addresses that were not publicly displayed on the affected Twitch profiles. Researchers suggested this could point to misuse of Twitch’s API, although there is no confirmation that Twitch itself was compromised.Twitch streamers face potential phishing and scam risksEven if the database mainly consists of scraped information, putting thousands of records together creates a new security problem. A scammer no longer needs to search across different websites to build a profile of a creator.Cybernews warned:“The information of many creators is aggregated to one place, making it easier for a malicious actor to profile these people and possibly craft social engineering scams,”That could make phishing attempts much more convincing. A scammer could use a creator’s real name, email address and audience size to pose as a company offering a sponsorship deal. Another attack could imitate Twitch support and claim that the streamer needs to verify their account.The alleged database also comes amid another recent Twitch security concern. Researchers at Socket found that an unofficial browser extension called “Twitch Enhanced Viewer | JeetBot” had been forwarding live Twitch OAuth tokens to servers controlled by its operator. The extension reportedly had about 31,000 users.Twitch said the extension was not affiliated with the platform and revoked potentially exposed access tokens. Users who installed it were advised to remove it.There is currently no evidence linking that extension incident to the dark web database.For creators, the latest claims are another reminder to tighten account security. Two-factor authentication, unique passwords and caution around unexpected sponsorship offers can reduce the chances of falling for targeted scams.Twitch has not been confirmed as the source of the alleged 40,000-record database, and the claims remain under investigation. The situation therefore raises serious concerns, but it should not yet be described as a confirmed Twitch breach.Catch the latest World News and Live updates. Download the TOI app.
Topics in this story
Gathered from external sources. Rights to this text belong to whoever originally published it.