Twitch Claims Recent Massive Data Leak Had Minimal User Impact
Twitch states that last week's massive 125GB data leak only affects a small fraction of users and exposes no sensitive login or payment details.
Twitch downplays its recent massive security breach, stating that the incident has only a minimal impact on its community. The company confirms that the leaked data affects only a small fraction of users and promises to contact those individuals directly. Despite the sheer volume of stolen information, Twitch reassures the public that the exposure remains limited in scope.
The streaming platform emphasizes that no login credentials or full payment card numbers are exposed in the leak. Twitch explains that its systems storing hashed passwords remain completely untouched during the attack. The exposed information primarily consists of documents from the company's source code repository and a subset of creator payout records.
The breach occurs due to a faulty server configuration change that mistakenly exposes internal data to the internet. An anonymous attacker claims to steal 125 gigabytes of data from roughly 6,000 internal Twitch Git repositories. This massive archive reportedly contains the entirety of the Twitch website's code, various client applications, internal AWS services, and unreleased Amazon Game Studios projects.