Twitch Data Breach Exposes Source Code and Streamer Payouts
A misconfigured server allows a malicious actor to leak over 125GB of Twitch data, including internal source code and creator revenue reports. The breach highlights the ongoing risks of cloud misconfigurations and the importance of strict access controls.
A massive data leak hits Twitch after a server configuration change exposes sensitive information to the internet. A malicious third party exploits this misconfiguration to access and publish 125GB of compressed data on the 4chan imageboard. The leaked cache reportedly contains over 6,000 internal Git repositories and detailed revenue payout reports for the platform's top streamers.
The threat actor claims the leak is motivated by the #DoBetterTwitch social media campaign, which pushes the Amazon-owned platform to better protect marginalized creators. The stolen data circulates via BitTorrent, indicating a coordinated effort to distribute the files as widely as possible. It remains unclear exactly how the attacker accessed the repositories, whether through direct entry or by finding an exposed backup.
Forensic analysis of the leaked files reveals the unauthorized access occurs between October 1 and October 4, 2021. Payout records suggest the attacker maintains access to the data until at least October 5, just one day before the public release. This incident serves as a stark reminder for all organizations to rigorously audit their server configurations and implement strict access controls to prevent similar exposure.