Twitch in crisis as it blames server error for massive data breach

A laptop and phone displaying the Twitch logo.
(Image credit: NurPhoto via Getty.)

The Twitch hack is real, it's massive, and security experts are aghast at the scale of the thing: "this is as bad as it could possibly be." The leak, which the hackers claim is only "part one," contains the site's source code, unannounced projects such as a Steam competitor, and the earnings of streamers.

Yesterday Twitch issued what was very much a holding statement, and has now expanded upon what it believes happened. Per the Twitch blog:

"We have learned that some data was exposed to the internet due to an error in a Twitch server configuration change that was subsequently accessed by a malicious third party. Our teams are working with urgency to investigate the incident.

"As the investigation is ongoing, we are still in the process of understanding the impact in detail. We understand that this situation raises concerns, and we want to address some of those here while our investigation continues."

That is, Twitch is putting this down to the human element: someone set up the company's servers incorrectly, and the hackers were able to find and access it. Whether this is human error or something more nefarious is unknown for now.

And the other thing this statement makes clear is that Twitch itself is still trying to understand just how bad this is.

Twitch

(Image credit: Bloomberg (Getty images))

Twitch notably doesn't say when this breach happened, though the data included in the leak goes back up to three years. Twitch's statement goes on to clarify that it believes personal data such as logins is not at risk, and emphasised that "full credit card numbers are not stored by Twitch, so full credit card numbers were not exposed." Whether the former can be taken at face value remains to be seen.

Finally, Twitch has reset all stream keys "out of an abundance of caution." Streamers can get their new key here.

Twitch will be in full crisis mode behind-the-scenes because, even if it's worked out what happened, that doesn't do anything about the fact it has happened—and what that means now and in the future. The repercussions are potentially enormous and elements of that are far beyond the control of even an Amazon-backed company.

"A lot more damage is now in store for Twitch," Candid Wuest from cyber-security company Acronis told the BBC. "The breach is already harming Twitch on all the fronts that count. [This leak] could contain nearly the full digital footprint of Twitch, making it one of the most severe data breaches of late. Releasing payout reports for streaming clients will not make the influencers happy either."

We'll keep you updated as this story develops. Meantime, do change your password and set up two-factor authentication.

TOPICS
Rich Stanton
Senior Editor

Rich is a games journalist with 15 years' experience, beginning his career on Edge magazine before working for a wide range of outlets, including Ars Technica, Eurogamer, GamesRadar+, Gamespot, the Guardian, IGN, the New Statesman, Polygon, and Vice. He was the editor of Kotaku UK, the UK arm of Kotaku, for three years before joining PC Gamer. He is the author of a Brief History of Video Games, a full history of the medium, which the Midwest Book Review described as "[a] must-read for serious minded game historians and curious video game connoisseurs alike."

Read more
Path of Exile 2 early access class key art
Around 66 accounts in Path of Exile 2 were compromised, due to a one-two punch of an old unused Steam account and a backend bug
A Path of Exile 2 sorceress casting flaming skulls in a hellish landscape
'We are incredibly sorry': Path of Exile 2 devs apologise for data breach that saw 66 accounts snatched and personal info potentially stolen
Kinzie, in an FBI jacket, uses a computer with the logo of the Third Street Saints on it
Have I Been Pwned adds over 284 million compromised passwords from latest breach
Mister Fantastic giving a thumbs up
A Marvel Rivals player has uncovered 'one of the most dangerous vulnerabilities a game can have' that'll let cheaters take over your PC and find your passwords
The streamer Emiru gives the peace sign to camera.
Three women livestreaming on Twitch harassed by man who then goes for them while making repeated death threats: 'This happens off-camera to women all the time'
Hacker
$1.5 billion crypto heist could be the biggest yet, more than doubling the previous record, but don't worry: The affected firm says it can take the hit
Latest in Platforms
discord
Brace yourself for Discord to get worse: Reports swirl that the company is in talks with bankers about opening itself up to shareholders
The Spy from Team Fortress 2 holds up a folder with an accusatory expression.
Steam users react ecstatically to update that lets them access their heaving game notes via the web, also it fixes Monster Hunter Wilds video recording
HasanAbi
Twitch streamer Hasan Piker suspended after saying Republicans would 'kill Rick Scott' if they really cared about Medicare fraud
Screenshot from Faceminer showing a PC desktop with several windows open
Five new Steam games you probably missed (March 3, 2025)
PORTSMOUTH, UNITED KINGDOM - OCTOBER 20: A man smokes a cigarette while he looks at a smart phone screen on October 20, 2024 in Portsmouth, England. (Photo by Matt Cardy/Getty Images)
Meta says sorry for turning Instagram into a horror show of violence, gore, dead bodies, and other graphic content that 'should not have been recommended'
A screenshot from Cabernet showing a vampiric woman sucking blood from a victim
Five new Steam games you probably missed (February 24, 2025)
Latest in News
the next battlefield
Battlefield playtest gameplay is leaking all over the internet, and fans seem cautiously but genuinely excited: 'Okay, we might be back'
Milla Jovovovovovich pointing a sawed-off shotgun at something offscreen, presumably a monster or zombie or something
The Resident Evil movie reboot bidding war is over, and the winner is… Sony, who did every one of those other pretty terrible Resident Evil movies
Judge Dredd promotional image in Warzone
Half-a-dozen 2000AD games were in the works before fizzling out: 'The games you get to see are a tiny representative of the number that get started—sadly'
Killing Floor 3 screenshot
Following a disastrous beta test, Killing Floor 3 is delayed less than three weeks before launch: 'We've realized we missed the mark'
Cheese platter with camembert, walnut cheese, gorgonzola and taleggio
I've never wanted a keyboard with cheese keycaps and a little mouse on it until I saw this one
AMD RX 7900 XT with its original packaging.
AMD clawed back 7% graphics market share from Nvidia at the end of 2024, but the outlook for the whole industry in 2025 looks iffy