Security experts aghast at the scale of Twitch hack: 'This is as bad as it could possibly be'

Twitch
(Image credit: Bloomberg (Getty images))

Just when we thought that Facebook's lengthy downtime would be the biggest cybersecurity news of the week, hackers went and absolutely bulldozed Twitch, swiping the site's source code and revealing everything from how much the top streamers make (a lot) to the existence of a Steam-like game client Twitch has in development, codenamed Vapor.

Twitch is still trying to figure out what exactly happened, but while that internal investigation unfolds—and it could very well take a long while, given the scale of the hack—security experts are warning of potentially dire consequences for the livestreaming platform.

"Reading of a data breach that includes the entire source code, including unreleased software, SDKs, financial reports and internal red-teaming tools will send a shudder down [the spine of] any hardened infosec professional," ThreatModeler founder and CEO Archie Agarwal told the Threatpost blog. "This is as bad as it could possibly be."

"The first question on everyone’s mind has to be, 'How on earth did someone exfiltrate 125GB of the most sensitive data imaginable without tripping a single alarm?' There’s going to be some very hard questions asked internally."

Our colleague Ian Brownhill, information security director at Future, which operates PC Gamer, said the theft of the Twitch source code could give hostile actors a "massive insight" into the platform's systems and infrastructure, and expose other weaknesses that could enable future attacks—not just against Twitch, but its parent company Amazon as well.

That risk could potentially be heightened if the attackers are ideological, as it currently appears, and not criminal or state-based. "The monetary rewards are limited, unless a ransom can be extracted," Brownhill said. "The criminal gangs want the credit cards (or PII [personally identifiable information] to a lesser extent) which does not seem to be the target here, or would be demanding ransoms. It’s not [likely] a nation-state—they want the Colonial Pipeline, critical infrastructure-type takedowns (or election tampering)—although as it all leads up to Jeff Bezos this cannot be completely ruled out."

Synopsys Software Integrity Group senior security strategist Jonathan Knudsen echoed that point in a statement, saying that access to the source gives attackers an opportunity to "reverse engineer software applications to understand how they work," and that anyone in the world who wants Twitch's source code can now have it.

"Whatever Twitch was doing for application security, they need to redouble their efforts," Knudsen said. "Anyone can now run static analysis, interactive analysis, fuzzing, and any other application security testing tools. Twitch will need to push their application security to the next level, finding and fixing vulnerabilities before anyone else can find them."

But plugging security holes only goes so far when, as Brownhill explained, breaches often aren't the result of Hollywood-style high-tech hijinks, but simple exploitation of human frailty, including "phishing to capture credentials and then moving laterally and escalating privileges [or] disgruntled employee action." In fact, a "phone spear phishing attack" is how a Florida teenager was able to hijack dozens of famous Twitter accounts (and steal more than $117,000) in 2020.

Because of that inherent vulnerability, Comforte AG product manager Trevor Morgan said companies like Twitch need to focus more on "data-centric" approaches to security, rather than pouring all their resources into trying to keep hackers out. "Threat actors will penetrate any perimeter put in place to keep them out," he said. "Protecting the data itself will render that ultimate prize worthless on the black market and blunt the negative repercussions of a successful hack."

The good news for Twitch users is that at this point, personal data like usernames, passwords, and credit card info doesn't appear to be accessible through the leak, although Knudsen said the published data does include hashed passwords. We'll need to wait for Twitch to confirm the extent of the data loss, but in the meantime users should at the very minimum change their passwords as soon as possible. It would also be a good idea to enable 2FA, and if you've used the same password on other sites, change it across the board to avoid "credential stuffing" attacks, where hackers try using username and password combos across a range of different sites. You should also be wary of any followup requests for personal information.

"This kind of thing can lead to more secondary phishing campaigns," Brownhill said. "People [may be] pretending to be Twitch offering support/compensation/services to trick people into handing over more information."

TOPICS
Andy Chalk
US News Lead

Andy has been gaming on PCs from the very beginning, starting as a youngster with text adventures and primitive action games on a cassette-based TRS80. From there he graduated to the glory days of Sierra Online adventures and Microprose sims, ran a local BBS, learned how to build PCs, and developed a longstanding love of RPGs, immersive sims, and shooters. He began writing videogame news in 2007 for The Escapist and somehow managed to avoid getting fired until 2014, when he joined the storied ranks of PC Gamer. He covers all aspects of the industry, from new game announcements and patch notes to legal disputes, Twitch beefs, esports, and Henry Cavill. Lots of Henry Cavill.

Read more
Path of Exile 2 early access class key art
Around 66 accounts in Path of Exile 2 were compromised, due to a one-two punch of an old unused Steam account and a backend bug
Mister Fantastic giving a thumbs up
A Marvel Rivals player has uncovered 'one of the most dangerous vulnerabilities a game can have' that'll let cheaters take over your PC and find your passwords
Kinzie, in an FBI jacket, uses a computer with the logo of the Third Street Saints on it
Have I Been Pwned adds over 284 million compromised passwords from latest breach
A Path of Exile 2 sorceress casting flaming skulls in a hellish landscape
'We are incredibly sorry': Path of Exile 2 devs apologise for data breach that saw 66 accounts snatched and personal info potentially stolen
Hacker
$1.5 billion crypto heist could be the biggest yet, more than doubling the previous record, but don't worry: The affected firm says it can take the hit
3D illustration of a grid of black cpus with different IoT symbols, representing a botnet concept
Cloudflare claims to have mitigated biggest DDoS attack on record with requests flying in from 5,500 IP addresses per second
Latest in Security
An FBI wanted poster for alleged hacker Zhou Shuai.
US Justice Dept announces $10 million bounty on at-large 'hacker-for-hire' cabal it says targeted China critics, religious missionaries, and the Treasury
Kinzie, in an FBI jacket, uses a computer with the logo of the Third Street Saints on it
Have I Been Pwned adds over 284 million compromised passwords from latest breach
A still from a YouTube video of Senator Mark Warner speaking
Telecoms hack on US government officials is 'worst in nations history' and 'the barn door is still wide open' says senator
HDMI cable
Hackers can wirelessly spy on your display by collecting HDMI signal leaks and churning them through an AI, but I wouldn't break out the tin foil just yet
Computer code and text displayed on computer screens. Photographer: Chris Ratcliffe/Bloomberg
Forcing users to periodically change their passwords should go the way of the dodo according to the US government
An original Apple Macintosh Model M0001, as they celebrate 40th anniversary, is on display in between 2024 Apple models at the independent Apple products store chain Amac, on January 24, 2024 in Utrecht, The Netherlands. Based on the Motorola 68000 microprocessor, the Macintosh was the first successful mouse-driven computer with a graphical user interface.
Major browser providers scramble to patch an 18-year-old vulnerability affecting MacOS and Linux systems but Windows remains gloriously immune
Latest in News
Pedro Pascal as Joel in a coat in winter looking unhappy
'Don't you know what he did?': The truth comes out in The Last of Us Season 2 trailer
Aloy
'Creepy,' 'ghastly,' 'rancid': Viewers react to leaked video of Sony's AI-powered Aloy
Split Fiction trailer still - Zoe and Mio standing side by side, wearing glowing neon sci-fi jammies
Split Fiction sells 1 million copies over 2 days
A soldier looks out over the Verdansk map, as a single tear rolls down his cheek.
The original Verdansk map is returning to Call of Duty: Warzone, to celebrate which we get a soldier crying to Nat King Cole
More than 5 years after launch, Control gets a surprise patch that lets everyone play the Hideo Kojima mission
Swen Vincke
Swen Vincke stamps seal of approval on Stardew Valley mod that yoinks the Baldur's Gate 3 cast out of D&D and into a cosy pastoral life