Skip to content
  • Products & Services
  • Security Operations
  • Threat Research
  • AI Research
  • Sophos Life
  • Products & Services
  • Security Operations
  • Threat Research
  • AI Research
  • Sophos Life
Twitch resets passwords, says user details may have been stolen
Naked Security Naked Security

Twitch resets passwords, says user details may have been stolen

Video game streaming service Twitch reveals it was hacked, but it doesn't say how it happened or how many users are affected.
Written by Lee Munson
March 24, 2015
Naked Security 2FA breach hack Lizard Squad login verification password reuse twitch two-factor authentication

Twitch logoUsers of the popular live streaming service Twitch were yesterday told that all their stream keys and passwords have been voided after the San Francisco-based startup noted “unauthorized access to some Twitch user account information”.

The company, which allows users to stream their gameplay to interested spectators, also revealed that accounts had been disconnected from Twitter and YouTube as part of its security response, presumably as a precaution to prevent further account hijacking.

While we hope that Twitch-using Naked Security readers are savvy enough to never use the same password twice, the company posted advice to users to change their login credentials elsewhere on the web if they had made that mistake.

Twitch also issued some advice about creating a new password, highlighting the insecurity of using dictionary words and promoting the use of a password manager.

Of course, a properly crafted password is one thing, but adding two factor authentication would offer an extra level of protection – something which Twitch currently doesn’t offer.

The blog post makes no mention of how the security incident occurred or just how many accounts were targeted – Twitch says it is in the process of contacting affected users directly – but the service, which was bought by Amazon for $970 million last year, is thought to have over 55 million users.

Those who have been affected by the breach are receiving an email from Twitch which gives some detail about the type of information the attackers may have walked off with:

We are writing to let you know that there may have been unauthorized access to some of your Twitch user account information, including possibly your Twitch username and associated email address, your password, the last IP address you logged in from, limited credit card information (card type, truncated card number and expiration date), and any of the following if you provided it to us: first and last name, phone number, address, and date of birth...

... While we store passwords in a cryptographically protected form, we believe it's possible that your password could have been captured in clear text by malicious code when you logged into our site on March 3rd.

So, if you have re-used your password elsewhere online, please go and change it. And make sure your passwords are different for each and every account you have. Always.

The slightly better news is that Twitch has told its users that the service neither stores nor processes full credit or debit card data – so users are unlikely to see unauthorised payments leaving their accounts.


Share this:

  • Click to share on Mastodon (Opens in new window) Mastodon
  • Click to share on Bluesky (Opens in new window) Bluesky
  • Click to share on Reddit (Opens in new window) Reddit
  • Click to share on LinkedIn (Opens in new window) LinkedIn
  • More
  • Click to share on Tumblr (Opens in new window) Tumblr
  • Click to share on Pocket (Opens in new window) Pocket
  • Click to print (Opens in new window) Print
  • Click to email a link to a friend (Opens in new window) Email
  • Share on Facebook
  • Share on X
  • Share on LinkedIn
  • 2
About the Author

Lee Munson

Read Similar Articles

May 24, 2021

What to expect when you’ve been hit with Avaddon ransomware

May 19, 2021

What’s New in Sophos EDR 4.0

May 19, 2021

Sophos XDR: Driven by data

Subscribe to get the latest updates in your inbox.
Which categories are you interested in?
Change Region
  • América Latina
  • Brasil
  • Deutschland
  • English
  • France
  • Iberia
  • Italia
  • Japan
Terms Privacy
  • Privacy Notice
  • Cookies
Legal
  • General
  • Modern Slavery Statement
  • Speak Out
© 1997 - 2025 Sophos Ltd. All rights reserved