TWITCH hacking. The streaming platform that specializes in distributing video game-related content has been hacked. The source code of applications and user data will be circulated on the Internet.
[Mis à jour le mercredi 6 octobre à 20 h 10] On Wednesday, October 6, 2021, a torrent link pointing to a large data file – representing over a hundred gigabytes – was posted by an anonymous forum user. 4 chan. It contained, he said, highly sensitive data related to the Twitch streaming platform, which is owned by Amazon. The information was disclosed by the site VGC (Video Game Chronicle) At the beginning of the day, noting at the same time that confirmation was obtained, via an anonymous source within the company, that the leak was very real. If the veracity of this data was in doubt during the hours after its publication, its veracity now appears to be certain. The company itself responded via its Twitter account early in the evening, acknowledging that a hack had occurred in its system.
According to the information currently available, the distributed file contains a lot of sensitive information.
- All the source code of the twitch.tv page and various applications for computers, phones, game consoles and connected TVs, which can therefore be used to identify security vulnerabilities in the infrastructure of this ecosystem.
- Code related to SDKs (development tools) and AWS services (Amazon web services, Amazon cloud services) used by Twitch.
- Revenue data from the platform to the streamers for the past 3 years
- An unpublished draft of a store Online video game, named steam It aims to compete with platforms such as Steam or the Epic Game Store, developed by Amazon Game Studios.
- Information regarding Twitch’s internal security tools, which are specifically intended to combat hackers, bots and hateful behavior on the platform.
ZeratoR, the largest French streamer, whose supposed income appears in the file, posted a message on Twitter, in response to the emerging controversy, and confirmed that the data on it was accurate. In addition, other French videographers confirmed, whose names and incomes appear on the file JeuxVideo.comOn condition of anonymity, the correctness of the financial statements relating to them.
On the sensitive topic of platform user identifiers, some evidence suggests they may be in the file. As a precaution, it is therefore recommended to all users Change their password instantly and activate two-factor authentication in their account security settings.
To do this:
- Log in to your Twitch account, and tap profile icon in the upper right of the window.
- In the drop-down menu, tap Settings.
- On the next page, select the tab Security and confidentiality Scroll down the page until you find the section protection.
- Then click change Password then on Configure two-factor authentication And follow the steps for each procedure.
“Hipster-friendly tv trailblazer. Problem solver. Infuriatingly humble introvert. Reader. Student. Subtly charming bacon maven.”