Twitch Confirms User Passwords and Financial Data Unaffected in Security Breach
Twitch reveals that a recent server configuration error exposed source code and some creator payout data, but user passwords and full credit card numbers remain secure. The company is directly contacting the small fraction of users impacted by the leak.
Twitch releases new details about a recent security incident, confirming that an unauthorized third party accesses its systems due to a server configuration error. The exposed data primarily includes documents from Twitch's source code repository and a subset of creator payout information. The company states that the breach only affects a small fraction of users and that the overall customer impact remains minimal.
The streaming platform reassures its community that sensitive user information stays secure during this event. Systems storing Twitch login credentials, which use strong bcrypt hashing, do not suffer any unauthorized access. Furthermore, full credit card numbers and bank information remain completely unexposed to the malicious third party.
As a precautionary measure, Twitch resets all stream keys to prevent any potential misuse of broadcast access. Users of integrated software like Twitch Studio, Streamlabs, and connected OBS do not need to take action, but others must manually update their keys in their broadcasting software. Twitch contacts the specific users impacted by the exposed payout data and implements additional steps to secure its service.