Hacker claims database of 40,000 Twitch streamers is up for sale
It probably isn’t a hack.

Illustration by Cybernews
- A hacker claims to have data on about 40,000 Twitch streamers.
- Cybernews researchers say the data appears scraped, not taken from a direct Twitch breach.
- Some emails were not public, so the attacker may have abused Twitch’s API.
- Streamers face higher phishing risks if attackers combine names, emails, profiles, and follower counts.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Twitch, which is used by 240 million people worldwide, has found itself in the eye of a storm on the dark web.
A new juicy advertisement has appeared on a well-known hacker forum. A threat actor is boasting about their latest data haul, having allegedly stolen information on about 40,000 Twitch users.
At any given moment, you’d find over 2 million viewers watching streams on Twitch. Naturally, even the remote possibility of a data leak or a breach can affect many people.
What is the hacker claiming?
According to the post, which was published on a well-known illicit marketplace on September 9th, the stolen Twitch user dataset contains information on approximately 40,000 Twitch streamers.
The attacker claims to have stolen:
- Usernames
- URLs
- Emails
- Legal names
- Followers number
- Status of account verification
The Cybernews research team has investigated the claims, and here is what we found.
Has Twitch been breached?
Our researchers examined 501 records provided by the attacker as samples. The data that they shared as proof of theft included:
- Usernames
- Twitch profile URLs
- Email addresses
- Follower counts
- In some cases, users' full names
This correlates with the attacker's claims in the post. However, our researchers are convinced that these claims may not be connected to a direct breach of the Twitch platform.
“From what I see, this indeed looks like a data scrape, not a breach," one of our researchers said.
It is likely that the attacker compiled the dataset through other means, like collecting information from public streamers' profiles.
Much of the advertised information is not particularly secret. Usernames, profile URLs, and follower counts can generally be obtained from Twitch profiles, while full names may also have been collected from creators' linked social media accounts.
The researchers also found signs that the data may not be particularly recent. Some streamers in the sample now have more followers than the number recorded in the alleged database.
This may suggest that the dataset was collected some time ago. Our researchers could not determine exactly when the information was compiled.
The Twitch API may have been abused
Some of the email addresses in the sample were not publicly displayed on the creators' Twitch profiles. That means that the attacker may have not only scraped public profiles, but also exploited Twitch's API.
Accessing Twitch's API requires an access token. According to our researchers, the attacker could have either used their own token to collect the information or they could have obtained a compromised token belonging to someone else.
This incident is not the first one affecting streamers' data. Recently, Streamlabs was allegedly breached by ShinyHunters, an infamous threat actor. Streamlabs is a Logitech subsidiary that makes broadcasting software widely used by Twitch creators.
The Twitch ecosystem relies heavily on Streamlabs, so third-party exposure of user data is significant.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Twitch users should stay cautious
For streamers, there is an increased risk of targeted social engineering attacks. A detailed creator profile can provide enough material for convincing phishing emails. Pressing the wrong link may result in the theft of credentials or other sensitive information.
“The information of many creators is aggregated to one place, making it easier for a malicious actor to profile these people and possibly craft social engineering scams,” one of our researchers explained.
For example, a scammer who knows a creator's Twitch identity, real name, audience size, and contact email has a much easier starting point for impersonating a brand manager.
Attackers could also impersonate a Twitch platform representative and send the user a bogus account verification request to harvest their credentials.
How to protect your data?
If you’ve been using Twitch recently, here are a couple of tips from our cybersecurity experts on how to protect your data:
- Use strong antivirus and anti-phishing software, which offer real-time scanning and automatic updates to catch emerging threats.
- Do not reuse weak passwords across platforms. Instead, use a password manager to generate strong passwords, store them, and autofill when necessary.
- The most effective protection against phishing attacks is enabling 2-factor authentication (2FA). Cybernews recommends using an authenticator app instead of SMS codes, since texts can be intercepted.
- Turn on your email provider's built-in phishing filters. Gmail and Outlook can automatically flag many suspicious messages.
- Keep software regularly updated, as patches close vulnerabilities that attackers exploit.
- Verify before you trust. If someone tries to communicate with you urgently and asks for your details, always check the sender's email address for mismatches, hover over links to preview the real URLs, and independently confirm unexpected requests through the official channel.