Twitch Suffers Massive 125GB Data Breach Exposing Source Code

An anonymous hacker breaches Twitch and exposes 125GB of sensitive data, including the platform's entire source code and creator payouts. The company blames the leak on a server configuration error.

An anonymous hacker breaches Amazon-owned streaming platform Twitch and exposes a massive 125GB data cache. The attacker posts a torrent link to the stolen information on 4chan, stating their motive is to foster disruption and competition in the video streaming space due to the platform's toxic community. The breach exposes Twitch's entire source code, creator payout details from the past three years, and proprietary internal Amazon Web Services tools.

The leaked data also contains an unreleased Steam competitor from Amazon Game Studio, various Twitch developer tools, and information security tools. Additionally, the breach impacts other Amazon properties like IGCB and CurseForge. Fortunately, Twitch reports that highly sensitive personally identifiable information, such as credit card details and login credentials, remains safe from the exposure.

Twitch attributes this major security incident to a server configuration error that the threat actor actively exploits. This event marks the second significant data breach for the streaming service since Amazon acquired it in 2014, echoing a history of cloud misconfiguration issues across Amazon S3. The situation highlights the critical need for consistent vulnerability management processes as hackers constantly scan networks for security holes.

Read More at the original source →