Creator Drama
Twitch Streamer Data Scrape and Security Incident
No new developments since Sep 14
Photo: livdose.com (from the cited article) All clips and posts below are embedded from their original sources.
By the numbers: this timeline documents 6 events from Sep 9, 2026 to Sep 14, 2026, drawn from 3 sources.
“From what I see, this indeed looks like a data scrape, not a breach,”
via dexerto.com
Background
Online creators and Twitch streamers have increasingly become targets for cybercriminals due to their public visibility, connected social profiles, sponsorship relationships, and professional communication channels. Public profiles often display usernames and follower counts, which malicious actors can leverage when combined with harvested email addresses.
Security concerns intensified when third-party browser extensions and illicit marketplace listings brought attention to potential vulnerabilities in creator accounts, prompting independent investigations by groups like Cybernews and Socket, as well as formal guidance from Twitch Support.
The timeline
-
Database of 40,000 Streamers Advertised on Illicit Marketplace
A threat actor reportedly advertised a dataset containing information on approximately 40,000 Twitch streamers on a well-known illicit marketplace, as uncovered by a Cybernews investigation and reported by Dark Web Intelligence.[1]
-
Dark Web Listing of 40,000 Twitch Streamers Reported
A dark web forum reportedly advertised a database containing personal details of 40,000 Twitch streamers, raising alarm among creators.[2]
-
Researchers Conclude Data Came From Scraping, Not a Direct Breach
According to security researchers, following an examination of 501 sample records, the advertised database appeared to be gathered through data scraping rather than a direct hack of Twitch infrastructure, potentially abusing the platform's API or public details.[1]
-
Socket Security Reports Third-Party Browser Extension Impact
Security researchers at Socket reportedly discovered that the third-party extension 'Twitch Enhanced Viewer | JeetBot' with roughly 31,000 users was forwarding live Twitch OAuth tokens through operator-controlled servers, posing potential account access risks.[1]
-
Twitch Support Issues Security Guidance and Revokes Tokens
According to Twitch Support, the browser extension issue did not originate from official Twitch systems, announced that potentially exposed access tokens had been revoked to sign users out automatically, and advised removing suspicious extensions.[1]
-
Malicious Twitch Browser Extension Leaked OAuth Tokens
A malicious Twitch browser extension, 'Twitch Enhanced Viewer | JeetBot', reportedly leaked OAuth tokens for nearly 31,000 users to proxy servers operated by a Russian commercial bot service.[3]
Frequently asked
Is the Twitch data breach over?
As of September 14, 2026, per dexerto.com, researchers said the data came from scraping, not a breach, and Twitch revoked the exposed tokens and told users to check security settings.
Was Twitch directly hacked in the September 2026 data incident?
Currently, researchers and investigators indicate there is no confirmation that Twitch itself was breached. The advertised database of 40,000 streamer records appears to be the result of data scraping or API abuse rather than a direct compromise of Twitch infrastructure.
What data was allegedly included in the dark web database listing?
The dataset reportedly includes Twitch usernames, profile URLs, email addresses, legal names, follower counts, and account verification statuses, with some records identifying creators associated with cryptocurrency categories.
How did Twitch respond to the third-party browser extension security concerns?
Twitch clarified that the unofficial 'Twitch Enhanced Viewer' extension is not affiliated with the platform, confirmed that potentially exposed OAuth tokens were revoked, and recommended that users review third-party app connections and remove suspicious extensions.
More related drama (4)
Sources (3)
Cite this timeline
This timeline compiles 6 dated events from 3 sources. If it helped your reporting, cite it:
GenZHype. “Twitch Streamer Data Scrape and Security Incident.”
GenZHype, 14 September 2026,
https://genzhype.com/drama/twitch-streamer-data-scrape-and-security-incident/.