News

Twitch Data Leak: 40,000 Streamers Had Data Listed for Sale. A Browser Extension Was the Likely Culprit.

Twitch Data Leak: 40,000 Streamers Had Data Listed for Sale. A Browser Extension Was the Likely Culprit.

On September 9, 2026, a threat actor listed a database of approximately 40,000 Twitch streamer records for sale on a dark web forum. The data includes usernames, emails, legal names, follower counts, profile URLs, and verification status. Cybernews researchers assessed the data appeared scraped or API-collected rather than directly breached. Twitch officially responded on September 14, confirming the issue did not originate from Twitch’s own systems and attributing it to “Twitch Enhanced Viewer,” an unofficial third-party browser extension not affiliated with Twitch. Twitch revoked potentially exposed access tokens as a precaution and advised anyone who installed the extension to remove it immediately.

The story turned out to be more specific, and more useful than most headlines made it sound. Five days after the post appeared, Twitch’s own support account confirmed what actually happened. It wasn’t Twitch’s servers. It wasn’t a direct platform breach. It was a browser extension that creators had willingly installed, one calling itself “Twitch Enhanced Viewer”, that had been collecting their data the whole time.

What the Listing Claims and What’s Actually In It

The forum post appeared on September 9 with a sample dataset and an asking price that wasn’t publicly disclosed in available reporting. The seller claimed to have stolen the information rather than collected it.

Cybernews examined 501 of the sample records provided as proof. What they found matched the seller’s claims on format: usernames, Twitch profile URLs, email addresses, follower totals, and in some cases creators’ full legal names.

Two details stood out from the analysis.

First: some of the email addresses in the sample weren’t displayed anywhere on the creators’ public Twitch profiles. On a normal scrape of public profile data, you’d only collect what’s visible. Hidden emails require either accessing Twitch’s API, which requires an authenticated access token, or collecting credentials from users’ own devices.

Second: some follower counts in the database were lower than those same creators have today. That suggests the data collection didn’t happen recently. The dataset could be weeks or months old before it surfaced on the forum.

Taken together, those two observations pointed toward something more sophisticated than pure public scraping, but not necessarily a direct breach of Twitch’s own database systems. The Cybernews researcher summarized it plainly: “From what I see, this indeed looks like a data scrape, not a breach.”

What they didn’t have at the time of publication was the piece that explained both anomalies at once.

The Browser Extension Nobody Was Talking About

Twitch’s @TwitchSupport account posted a response on September 14, 2026, five days after the listing appeared and four days after Cybernews published its investigation. The statement was direct: “As this issue does not originate from Twitch systems, we recommend you do the following…”

What followed was the key detail. Twitch identified “Twitch Enhanced Viewer” as an unofficial third-party browser extension, not affiliated with Twitch, as the source of the issue. The platform had already revoked potentially exposed access tokens, which automatically signed affected users out of their sessions. Twitch advised anyone who had installed the extension to remove it immediately.

This explains everything the initial investigation couldn’t quite reconcile.

A browser extension installed by a creator runs inside their browser, where it has access to whatever the browser can access, including the authenticated Twitch session that session’s access token represents. An extension with the right permissions can quietly read API responses, capture emails returned by private account calls, and log session data. The creator sees a functional enhancement tool. The extension is feeding their account data somewhere else.

This is why some emails weren’t publicly visible on profiles. The extension captured them from authenticated API responses that only the logged-in account holder should see. And because the extension wasn’t collecting data from Twitch’s servers directly, Twitch’s own systems had no breach to detect. The collection happened in the creators’ own browsers, through their own authenticated sessions.

It’s a variation of the same supply chain logic we covered in our broader piece on how dark web warning signs often trace back to third-party access rather than direct server compromise. The primary platform isn’t hacked. Something that touches it, an extension, a plugin, an integration, becomes the collection point.

The Streamlabs Attack Three Weeks Earlier

This Twitch listing didn’t arrive in a vacuum. The streaming ecosystem had already been in the crosshairs throughout August 2026.

On August 18, ShinyHunters, one of the most active and well-documented cybercrime groups of the past several years, claimed to have breached Streamlabs, a Logitech subsidiary whose broadcasting software is used by millions of Twitch creators. The group posted what it described as a “final warning” to Logitech on its dark web leak site, threatening to publish stolen data unless the company made contact by August 21.

Streamlabs is not a peripheral service for Twitch creators. It handles overlays, alerts, donations, subscriber notifications, and stream management tools. For many streamers it’s running in the background of every broadcast. Its user base is estimated at over 15 million creators.

ShinyHunters didn’t provide data samples in its Streamlabs listing, so researchers couldn’t verify what, if anything, was actually taken. Logitech hadn’t publicly confirmed the incident as of available reporting. But the group’s track record gives the claim weight. In 2026 alone, ShinyHunters has been linked to the Aura breach (900,000 records), Sysco, Ralph Lauren, and RingCentral. They are not known for bluffing without assets.

When you place the Streamlabs extortion listing (August 18) and the Twitch streamer data sale (September 9) side by side, a pattern emerges. Someone has been targeting the specific ecosystem that live streamers depend on, both the platform itself and the third-party tools running alongside it. Whether those two incidents are connected to each other or simply coincidental isn’t publicly confirmed. But they’re running on the same timeline, targeting the same community.

Why Streamers Are a Particularly Valuable Target

Most data breach coverage treats all users as interchangeable. For streaming platform breaches, that framing misses something significant.

Twitch streamers, particularly any with a meaningful audience, are public figures with documented reach. Their follower counts are visible. Their content niches are known. Their emails, at least until now, were supposed to be semi-private. A dataset that combines all three creates a ready-made targeting list for specific, high-value social engineering attacks.

Fake sponsor outreach is the most immediately obvious risk. A scammer with your channel name, your viewer count, your content category, and your contact email can send a fake brand partnership offer that looks far more credible than a generic phishing attempt. “We’d love to sponsor your gaming content, 12,000 viewers in your niche is exactly our target demographic. Here’s a contract to review” is a more convincing opener when the attacker already knows it’s accurate.

Impersonation of platform support is the second risk. Twitch’s own advice flag this specifically: a fake email from “Twitch Support” referencing your verified creator status and asking you to confirm your login credentials for a routine security review is more convincing when the attacker knows you’re verified. The email looks right. The context is plausible. The link is the only thing that’s fake.

Credential theft aimed at streaming revenue is the downstream target. A Twitch creator’s account isn’t just social media access. It’s connected to payout information, subscription revenue, and in many cases linked to affiliated platforms like Patreon, YouTube, and sponsorship management tools. Taking over a creator account can mean redirecting income, accessing linked payment methods, or monetizing a built audience.

This framing connects to something we covered in the context of data aggregation generally, as explored in our piece on whether data broker profiles create real risk: the danger isn’t any single data point, it’s what combining them allows. An attacker with name, email, viewer count, content category, and verification status has everything needed to run a convincing targeted scam. Individually, none of those fields looks especially sensitive.

This Is Not the 2021 Twitch Breach

Twitch has been here before, and the comparison is worth making clearly so the two incidents aren’t confused.

In October 2021, an actual breach of Twitch’s own servers resulted in a 125GB data dump appearing on 4chan. The method was a server misconfiguration, not a complex hack. Someone found a door left open and downloaded what was behind it. The dump included Twitch’s internal source code, proprietary security tools, and creator earnings data that had never been intended to be public. Twitch reset all stream keys across the platform as part of its response.

The 2021 breach was a confirmed, platform-level incident involving Twitch’s own infrastructure. The 2026 listing is different in almost every structural way: it involves far fewer records (40,000 vs. what would have been millions), the source was a third-party browser extension rather than Twitch’s own systems, and the data type is creator contact and profile information rather than source code or financial internals.

That distinction matters for how affected users should respond, because the risk profile is different. In 2021 the concern was internal platform exposure. In 2026 it’s targeted social engineering against individual creators.

What Twitch Has Already Done

By the time Twitch issued its September 14 statement, the most critical short-term action had already been taken automatically: access tokens tied to potentially exposed accounts were revoked. That means any active session the Twitch Enhanced Viewer extension had been using to make authenticated API calls was invalidated. Creators with the extension installed would have found themselves signed out.

This is meaningful because access token revocation cuts off any ongoing data collection through that authentication path. It doesn’t recover data already collected, but it closes the active collection window. As we covered in our guide on what to do when your data is already on the dark web, the immediate containment action is separate from the longer-term exposure, data collected before the revocation is still wherever it was sent.

Twitch’s public guidance for affected creators centered on three things: remove the extension immediately, enable two-factor authentication if not already active, and independently verify any unexpected communications before clicking links or sharing credentials.

How to Check and What to Do

If you’re a Twitch creator and you’ve ever installed a browser extension that claimed to enhance your Twitch experience, the first step is simple: open your browser’s extension list and check what’s there. An extension called “Twitch Enhanced Viewer” should be removed immediately if it’s present. While you’re there, it’s worth auditing every extension in your browser for legitimacy, extensions with broad permissions to read webpage content are a persistent security risk, regardless of what they claim to do.

If you use Twitch as a viewer and have used the same extension, the same advice applies. The listing focuses on creators, but any user data an extension could access is potentially within scope.

Have I Been Pwned is worth checking for your email address. The Twitch listing hasn’t been incorporated into HIBP’s database as a confirmed breach entry as of available reporting, but if it is added, HIBP will flag any email address included.

Enable two-factor authentication on your Twitch account using an authenticator app rather than SMS codes. Authenticator app codes exist only on your device and can’t be intercepted or SIM-swapped the way text messages can. If someone attempts to log into your account with your email and a guessed or purchased password, 2FA stops them at the second step.

Watch for fake sponsorship or platform verification emails for the next several months. If an email references your specific channel data accurately, treat that accuracy as a warning sign rather than a legitimacy signal. Scammers with accurate data are more convincing, not more trustworthy. Confirm anything unexpected through Twitch’s official creator support channels directly.

For a broader checklist on what to do when your email and profile details are exposed in a dark web listing, our guide on whether data can be removed from the dark web covers the full picture, including why the listing being active doesn’t change much once data has circulated.

The Bigger Pattern: The Streaming Ecosystem Is Being Targeted

Three incidents in five weeks tell a story about where attention has shifted.

Streamlabs, August 18. Twitch creator database, September 9. Twitch’s response and access token revocation, September 14. All three involve the same community, live streaming creators, and two of them involve the same underlying mechanism: authenticated access to streaming platforms being exploited through third-party software rather than the platforms themselves.

The streaming creator economy is large, increasingly professionalized, and for many creators represents their actual income. That makes it a more valuable target than it might have been five years ago when most streamers were hobbyists. The combination of public audience data, private contact information, and income tied to platform credentials makes a compromised creator account significantly more valuable than a compromised general consumer account.

The tools that creators use to do their jobs, extensions, streaming software, alert systems, sponsorship management platforms, are all potential collection points. As we’ve covered in looking at how the synthetic identity market feeds off breach data, in our piece on the $200 dark web fake identity packages, the value of personal data compounds when it’s combined. A creator’s name, email, audience demographics, and verified status is a package. Someone sold that package.

Frequently Asked Questions

Was Twitch hacked directly?

No. Twitch confirmed the issue did not originate from its own systems. The data appears to have come from a third-party browser extension called Twitch Enhanced Viewer, which collected creator data through authenticated user sessions.

What data was exposed?

Usernames, profile URLs, email addresses, legal names, follower counts, and account verification status for approximately 40,000 creators. Some emails were not publicly visible on profiles, suggesting they were collected through authenticated API access rather than simple public scraping.

Is this the same as the 2021 Twitch breach?

No. The 2021 breach was a confirmed platform-level server incident that exposed source code and creator earnings data. This is a third-party browser extension incident affecting a subset of creators.

What has Twitch already done?

Revoked potentially exposed access tokens, automatically signing out affected users, and publicly advised anyone who installed Twitch Enhanced Viewer to remove it.

Was Streamlabs also involved?

A separate incident: ShinyHunters claimed to have breached Streamlabs on August 18, 2026, three weeks before the Twitch listing. The two incidents may be unrelated but both target the same streaming creator ecosystem.

What should I do if I’m a Twitch creator?

Remove Twitch Enhanced Viewer from your browser immediately if installed. Enable 2FA using an authenticator app. Verify any unexpected sponsorship or platform emails through official Twitch channels before clicking links

Written by Muhammad Anas

Contributing writer at DarkWebDecoded.com covering dark web security, scam alerts, and privacy tools.

📋 Latest Articles

View all →
Seven Chinese AI Labs Stole 190 Million Claude Exchanges. Here's How They Did It.
News

Seven Chinese AI Labs Stole 190 Million Claude Exchanges. Here’s How They Did It.

Between May and July 2026, accounts linked to Alibaba’s AI division generated more than three million conversations with…

Sep 14, 2026
11 min read
Greenberg Traurig Data Breach
News

Greenberg Traurig Data Breach: One Law Firm Hit. Six in Three Weeks. Here’s the Real Story.

Greenberg Traurig confirmed a data breach to Vermont’s Attorney General on September 8, 2026. A ransomware group called…

Sep 12, 2026
10 min read
Operation Alice dark web
News

Operation Alice: One Person Was Running 373,000 Dark Web Sites. Every Customer Is Now a Suspect.

Between March 9 and March 19, 2026, law enforcement agencies from 23 countries quietly dismantled one of the…

Sep 10, 2026
10 min read
Bank of Baroda Data Breach
News

Bank of Baroda Data Breach: Why TripleX Released 1TB for Free And Why That’s the Whole Story

When a ransomware group steals data, the usual move is to demand payment. Hand over the money, or…

Sep 10, 2026
10 min read
Infostealer logs illustration showing a glowing ZIP archive leaking stolen passwords, browser cookies, credit cards, and crypto wallet data from a laptop
Guides

Infostealer Logs – The Breach That Rarely Gets Reported

Infostealer logs: In the first half of 2025, over 1.8 billion credentials containing saved passwords, usernames, phone numbers,…

Sep 10, 2026
12 min read
Wireframe chat marketplace stamped "SEIZED" beside frozen crypto wallets, illustrating the Xinbi Guarantee takedown and $52.8M freeze.
News

Xinbi Guarantee Seized – Inside the $24B Telegram Scam Marketplace

If you ask the average person where the largest criminal marketplaces on the internet are located, they’ll say…

Sep 10, 2026
10 min read
0 0 votes
Article Rating
Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted