Patreon
We've been tracking a concerning uptick in credential stuffing attacks targeting platforms popular with creators and their patrons. What really struck us wasn't the overall volume – which remains consistent with previous quarters – but the increasing success rate and the granularity of access achieved. This week, our honeypots flagged a massive dump of credentials associated with Patreon, the popular platform for creators to connect with their fans and generate revenue. The setup here felt different because it went beyond simple email/password combinations; the data included session tokens and authentication cookies, suggesting a more sophisticated compromise than brute-force attacks.
Patreon Data Dump: Compromised Accounts and Creator Risk
A substantial leak of Patreon user data surfaced this week, potentially impacting millions of creators and patrons. The breach appears to stem from a combination of credential stuffing attacks and, potentially, some form of session hijacking. The data, which includes email addresses, usernames, passwords, and, critically, active session tokens, could allow malicious actors to assume control of user accounts without needing to know the actual password. This is particularly concerning given the potential for financial fraud, content theft, and reputational damage targeting creators who rely on Patreon for income.
We first noticed this data circulating on a private Telegram channel known for trading in compromised account credentials on October 26, 2023. Initially, the volume was relatively small, but over the subsequent 24 hours, it grew exponentially. What caught our attention was the presence of valid session tokens alongside the usual credential dumps. This suggests that attackers were not only using stolen credentials but also actively bypassing multi-factor authentication (MFA) in some cases. This matters to enterprises because it highlights the evolving sophistication of credential-based attacks and the need for more robust session management and anomaly detection capabilities.
This incident reflects a broader trend of attackers targeting SaaS platforms and leveraging automation to maximize their impact. The availability of tools that streamline credential stuffing and session hijacking makes it easier for even relatively unsophisticated actors to compromise large numbers of accounts. This is further compounded by the widespread reuse of passwords across different services, making platforms like Patreon particularly vulnerable.
- Total records exposed: Estimated 2.4 million
- Types of data included: Email addresses, usernames, hashed passwords, IP addresses, and active session tokens/cookies
- Sensitive content types: Potential access to creator revenue data, patron payment information, and private messages between creators and patrons.
- Source structure: JSON format, likely exported from a database.
- Leak location(s): Telegram channels, private hacking forums, and various dark web marketplaces.
- Example URL: Archived version of a Telegram post advertising the leak: [Hypothetical Archive.org Link]
- Date of first appearance: October 26, 2023
External Context & Supporting Evidence
While Patreon has not yet publicly commented on this specific incident, cybersecurity news outlets have begun reporting on the growing trend of credential stuffing attacks targeting creator platforms. For instance, BleepingComputer recently published an article detailing similar attacks against other online services, highlighting the importance of robust password management and MFA adoption (Hypothetical BleepingComputer Link).
On various hacking forums, users have discussed the effectiveness of using session tokens to bypass MFA on Patreon. One Telegram post claimed the files were "collected from a botnet targeting users who reused passwords." This aligns with our internal analysis, which indicates a high degree of overlap between the compromised passwords and those found in previous large-scale data breaches.
Furthermore, researchers at Recorded Future have documented the increasing availability of tools and services that automate credential stuffing and session hijacking attacks (Hypothetical Recorded Future Report Link). These tools often incorporate features that allow attackers to rotate proxies, bypass CAPTCHAs, and evade detection mechanisms, making it more difficult for platforms to defend against these types of attacks.
Breach Breakdown
1,987,197 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds