Twitch says passwords were not exposed in last week's massive security breach

Twitch logo
(Image credit: MARTIN BUREAU via Getty Images)

Twitch says user passwords and financial information were not exposed in the massive data breach that occurred last week, and that it is "confident" that systems that store encrypted login credentials were not accessed.

"The exposed data primarily contained documents from Twitch’s source code repository, as well as a subset of creator payout data," Twitch said. "We’ve undergone a thorough review of the information included in the files exposed and are confident that it only affected a small fraction of users and the customer impact is minimal. We are contacting those who have been impacted directly."

It also confirmed that the incident was the result of a server configuration error "that allowed improper access by an unauthorized third party." The issue has since been fixed.

The wording of the statement, specifically the reference to the examination of "information included in the files exposed," could be intended to give Twitch some wiggle room down the road should more damaging information come to light: The hacker behind last week's leak referred to it as "part one," implying that there's more to come in the future, the specific nature of which Twitch may not yet be aware of.

Still, it's about as good an outcome as Twitch could hope for given the extent of the breach, which totaled 125GB of data that included streamer payout information, the source code for the entire Twitch site, and news of an unreleased Steam competitor codenamed Vapor. Security experts were appalled by the scale of the hack: One said the breach was "as bad as it could possibly be."

Despite the relatively good news, reaction to Twitch's statement on Twitter was not uniformly positive. One user claimed there was a "myriad" of two-factor authentication requests the day after the hack, suggesting that some passwords were leaked; another pointed out that 10,000 streamers had their payout information leaked, and while that might indeed be a "small fraction" of Twitch's total user base, it's still a hell of a lot of people. And there's still some concern about the potential for fraud arising from the data that did get out.

Twitch concluded by saying that it has "taken steps to further secure" the platform, although it didn't get into any specifics on that front, and apologized to its users for the breach.

TOPICS
Andy Chalk
US News Lead

Andy has been gaming on PCs from the very beginning, starting as a youngster with text adventures and primitive action games on a cassette-based TRS80. From there he graduated to the glory days of Sierra Online adventures and Microprose sims, ran a local BBS, learned how to build PCs, and developed a longstanding love of RPGs, immersive sims, and shooters. He began writing videogame news in 2007 for The Escapist and somehow managed to avoid getting fired until 2014, when he joined the storied ranks of PC Gamer. He covers all aspects of the industry, from new game announcements and patch notes to legal disputes, Twitch beefs, esports, and Henry Cavill. Lots of Henry Cavill.

Read more
Path of Exile 2 early access class key art
Around 66 accounts in Path of Exile 2 were compromised, due to a one-two punch of an old unused Steam account and a backend bug
A Path of Exile 2 sorceress casting flaming skulls in a hellish landscape
'We are incredibly sorry': Path of Exile 2 devs apologise for data breach that saw 66 accounts snatched and personal info potentially stolen
Kinzie, in an FBI jacket, uses a computer with the logo of the Third Street Saints on it
Have I Been Pwned adds over 284 million compromised passwords from latest breach
Mister Fantastic giving a thumbs up
A Marvel Rivals player has uncovered 'one of the most dangerous vulnerabilities a game can have' that'll let cheaters take over your PC and find your passwords
Twitch Nvidia NVENC encoding
Twitch is changing its suspension policy so that violations have an expiry date because the system 'didn’t acknowledge community members who had learned from their past mistakes'
Steam logo
A web3 free-to-play survival game found to be a front for installing malware on your PC has finally been removed from Steam
Latest in Platforms
A screenshot from game Mudborne of a little humanoid frog in a marsh
Five new Steam games you probably missed (March 24, 2025)
midnight murder club
Five new Steam games you probably missed (March 17, 2025)
Screenshot of Children of Clay showing a mysterious clay model
Five new Steam games you probably missed (March 10, 2025)
discord
Brace yourself for Discord to get worse: Reports swirl that the company is in talks with bankers about opening itself up to shareholders
The Spy from Team Fortress 2 holds up a folder with an accusatory expression.
Steam users react ecstatically to update that lets them access their heaving game notes via the web, also it fixes Monster Hunter Wilds video recording
HasanAbi
Twitch streamer Hasan Piker suspended after saying Republicans would 'kill Rick Scott' if they really cared about Medicare fraud
Latest in News
A mech awakens.
Mecha Break developer is considering unlocking all mechs following open beta feedback
Lara Croft Unified Art
Tomb Raider developer Crystal Dynamics lays off 17 employees 'to better align our current business needs and the studio's future success'
A long bendy arm stealing money from people in a subway car
'You're a very long arm. You steal things. It's a comedy game,' explains developer of comedy game where you steal things with a very long arm
The heroes are attacked by monsters
Pillars of Eternity is getting turn-based combat to mark its 10th anniversary, and that means PC Gamer editors will soon be arguing about combat mechanics again
Image of Ronaldo from Fatal Fury: City of the Wolves trailer
It doesn't really make sense that soccer star Ronaldo is now a Fatal Fury character, but if you follow the money you can see how it happened
Junah beginning a battle in Metaphor: ReFantazio.
Today's RPG fans are 'very sensitive to feeling like they wasted time' when they die, says Metaphor: ReFantazio battle planner—but Atlus still made combat hard anyway