Dark Web Seller Claims 40,000 Twitch Streamers’ Data for Sale

A dark web listing targets 40,000 streamers with emails and legal names while a browser extension separately leaked OAuth tokens for 31,000 users

Al Landes Avatar
Al Landes Avatar

By

Image: Deposit Photos

Key Takeaways

Key Takeaways

  • Threat actor lists alleged database of 40,000 Twitch streamers’ personal data for sale.
  • Bundled public and private details enable convincing social engineering attacks targeting creators.
  • JeetBot browser extension secretly routed live OAuth tokens through operator-controlled proxies, exposing 31,000 accounts.

On September 9, 2026, a threat actor listed an alleged database containing personal information on roughly 40,000 Twitch streamers for sale on an illicit marketplace, according to a Cybernews investigation. If your Twitch account information appears in this database, it may already be in the hands of someone looking to impersonate a sponsor, a colleague, or Twitch support.

The claimed dataset includes Twitch usernames, profile URLs, email addresses, legal names, follower counts, and account verification statuses, according to Cybernews.

Scrape, Not a Breach, but the Risk Is Real Anyway

Researchers examined a sample and found real data, but no signs Twitch’s systems were directly compromised.

Cybernews obtained and reviewed a 501-record sample from the alleged database and confirmed the records appear tied to actual Twitch channels. An unnamed security researcher quoted by Cybernews was direct: “From what I see, this indeed looks like a data scrape, not a breach.”

Most fields in the sample, including usernames, follower counts, and profile links, are publicly visible on Twitch. The presence of email addresses, which Twitch does not display on public profiles, raises the possibility of API abuse using valid or stolen access tokens, according to Cybernews.

Outdated follower counts in the sample suggest the database was likely compiled some time ago, not extracted in a fresh 2026 attack.

Why Bundled Data Is Dangerous on Its Own

Combining public and private details in one place dramatically lowers the effort required to target a specific creator.

Even if most fields are technically public, aggregating real names, contact emails, audience size, and verification status into one searchable database changes the threat calculus entirely. That concentration is exactly what makes targeted social engineering so effective.

Researchers describe a specific threat scenario. An attacker poses as a brand or Twitch staff member, references a streamer’s legal name and follower count, and sends a convincing fake sponsorship offer or account-verification request designed to harvest credentials.

Streamers accept sponsorship pitches constantly. That routine makes this attack vector harder to spot and easier to act on.

A Separate Twitch Extension Was Quietly Leaking Your Login Tokens

The JeetBot browser extension routed live OAuth tokens through operator-controlled proxies, exposing roughly 31,000 accounts.

Security firm Socket identified a parallel incident involving a surveillance app called “Twitch Enhanced Viewer | JeetBot.” The extension exposed live OAuth tokens for approximately 31,000 users: around 30,000 on Chrome and 552 on Firefox.

Socket’s Threat Research Team described the mechanism precisely: “Current builds (v85.x) forward the token inline as an &auth= query parameter on a network-layer redirect to the operator’s proxy.”

An OAuth token lets someone access your account without your password or two-factor authentication code. Socket also found the extension excluded a hard-coded allowlist of ten Russian streamer channels from token forwarding, a deliberate design choice that raises serious questions about intent.

Twitch revoked the affected tokens and called JeetBot an unofficial third-party tool with no affiliation to the platform.

These Are Two Separate Incidents

Current reporting finds no confirmed connection between JeetBot and the dark web database.

The timing is close and both incidents involve Twitch account exposure, but investigators have not linked them. Treat them as distinct threats until evidence says otherwise.

This situation also differs meaningfully from Twitch’s confirmed 2021 breach, which involved direct infrastructure compromise, exposed source code and streamer earnings, and forced a platform-wide stream key reset. The 2026 dark web listing lacks that level of confirmation; the available evidence points to scraping and potential API misuse, not a repeat of 2021.

What to Do Right Now

Twitch’s own guidance, plus researcher recommendations, point to the same immediate actions.

Remove any browser extensions you do not actively use and recognize, then review all third-party apps connected to your Twitch account. Enable two-factor authentication if you have not already, use a unique password for Twitch, and independently verify any unexpected sponsorship offer or support message before clicking a single link.

For creators specifically, your real name and contact email appearing in a searchable database means the next fake brand deal in your inbox could be more convincing than anything you have seen before. Verify first, click never, and learn how to stay safe against the broader landscape of digital threats targeting your accounts.

Share this

At Gadget Review, our guides, reviews, and news are driven by thorough human expertise and use our Trust Rating system and the True Score. AI assists in refining our editorial process, ensuring that every article is engaging, clear and succinct. See how we write our content here →