XSplit
We've been tracking a concerning uptick in credential stuffing attacks targeting the gaming and streaming communities. What really struck us about this particular breach wasn't the size of the leak, but the specific targeting of XSplit, a popular live streaming and video mixing application. The data, which included usernames, email addresses, hashed passwords, and even in some cases, purchase histories, had been quietly circulating for weeks before its significance became clear. The setup here felt different, less like a broad scraping operation and more like a targeted campaign against a specific user base.
XSplit User Data Dumped on Cybercrime Forum
A significant data breach impacting XSplit, a widely used application for live streaming and video production, has surfaced on a known cybercrime forum. The breach exposes sensitive user information, potentially putting streamers and content creators at risk of account compromise and further exploitation. We discovered the leak while monitoring underground forums known for trading stolen credentials. The initial post offered a "database" of XSplit users, advertising the potential for account takeover and access to associated streaming platforms. What caught our attention was the relatively high percentage of valid email addresses and the presence of purchase history details, suggesting successful breaches of user accounts and potentially financial information. This incident highlights the continued threat of credential stuffing attacks and the importance of unique, strong passwords across all online platforms.
- Total records exposed: Approximately 2.4 million
- Types of data included: Email addresses, usernames, hashed passwords (various algorithms including bcrypt), IP addresses, purchase histories (limited), forum activity data
- Sensitive content types: Potentially linked payment information via purchase histories, IP addresses that can reveal location.
- Source structure: SQL database dump
- Leak location(s): A prominent cybercrime forum known for trading stolen databases and credentials.
- Date of first appearance: Approximately November 14, 2024 (per forum timestamps).
External Context & Supporting Evidence
While mainstream media hasn't yet widely reported on this specific XSplit breach, similar incidents targeting streaming platforms have been covered extensively. For example, in 2020, Twitch suffered a major data breach that exposed source code and creator payout information (reported by The Record: https://therecord.media/twitch-source-code-leak-details). This highlights the ongoing vulnerability of streaming services and their users to cyberattacks. Furthermore, chatter on related Telegram channels suggests that the XSplit data is being actively used in credential stuffing campaigns targeting linked accounts on platforms like Twitch, YouTube, and Kick. One Telegram post claimed the files were "gold for hitting streamer accounts." The presence of various password hashing algorithms suggests the data may have been compiled from multiple sources over time, rather than a single recent breach of XSplit's core infrastructure. This could indicate the compromise of third-party services or older, less secure systems associated with the platform.
Breach Breakdown
2,126,126 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds