The Fake Copyright Notice Targeting Streamers
Twitch creators have had a few reasons to think about account security this month. A fake copyright notice is circulating, a browser extension with thousands of users was found leaking login tokens, and a database containing 40,000 streamer records appeared for sale. There's no need to panic, but there are a few checks worth making before you next go live.
The fake copyright email
The email claims (opens in a new tab) an automated scan has detected copyrighted music in your recent streams. It gives you 24 hours to act before your VODs are muted and your monetisation is affected. At a glance, it could look convincing. The highlighted sections show the details worth checking:
- It's addressed "to Twitch." Your address isn't shown in the recipient line, which can indicate a message sent to a hidden mailing list. Expand the sender details to see the actual email address behind the display name.
- It opens with "Hello Broadcaster." There's no mention of your channel anywhere in the message.
- It never names the rights organisation. It refers vaguely to "the corresponding rights administration organization" without telling you who is making the claim.
- You have 24 hours to respond. The deadline puts pressure on you to act before you've had time to check.
- Your monetisation is supposedly at risk. A threat to your earnings makes that deadline feel more urgent.
- It sends you to a "Twitch Audio Systems Portal." This isn't a legitimate Twitch portal.
Taken together, those details should give you plenty of reason to stop before clicking. Open Twitch yourself and check your Creator Dashboard for copyright strikes or account warnings.
This month's Twitch security incidents
On September 11, Socket's threat research team reported (opens in a new tab) that Twitch Enhanced Viewer was sending users' active Twitch login tokens to servers controlled by its developer. The Chrome and Firefox extension, which blocks ads and automatically collects channel points, had around 31,000 users. An exposed login token can let someone access your account without going through your password or two-factor authentication.
Twitch Support addressed the extension on September 14 and said it had revoked the login tokens it believed were exposed:
On September 12, a separate listing appeared on a dark web marketplace offering around 40,000 Twitch streamer records. Cybernews reviewed a sample (opens in a new tab) containing usernames, profile links, follower counts, and some legal names and email addresses. Its researchers believe the information was scraped rather than taken in a breach of Twitch. Some email addresses weren't visible on the public profiles, though, which they suggest could mean someone used an access token to query Twitch's API.
There's no evidence that either incident is connected to the fake copyright email, and streamers were receiving scams like this well before September. But more creator email addresses being passed around gives scammers more people to target.
How to secure your account
- Enable two-factor authentication through an authenticator app. If you're currently using SMS, that's still better than having no second step, but an app avoids the risks associated with intercepted text messages.
- Check which apps still have access. Open twitch.tv/settings/connections (opens in a new tab) and remove anything you no longer use or don't recognise. It's easy to connect a tool once and forget about it.
- Review your Twitch browser extensions. Depending on their permissions and how they work, extensions can access sensitive account information.
- Give Twitch its own password. Reusing one means a breach of another service could put your Twitch account at risk too. A password manager saves you having to remember a different password for every site.
- Go directly to Twitch to check a warning. Open the site yourself and look in your dashboard, rather than using a link in an unexpected email.
- Ask your mods and editors to do the same. Anyone with access to your channel should be taking the same precautions with their own account.
Pete’s Content Corner
My weekly picks from across the content creation world.
- Kick has sent backpay for September's underpaid Partner Program earnings (opens in a new tab), blaming a manual calculation error. Check Stripe, as the payment won't appear in Kick's dashboard. Rates now use a rolling calculation across recent streams, which should make payouts less volatile.
- Twitch CEO Dan Clancy says AI disclosure rules aren't needed yet (opens in a new tab), claiming streamers replacing themselves with AI "just isn't happening." Kick, YouTube, TikTok and Instagram already require disclosure.
- Discord is rolling out its revised age assurance system globally (opens in a new tab) after February's delay, and says over 90% of users won't need to confirm their age. Those who do can now use a credit card or Google Wallet instead of an ID or selfie. If your server has age-restricted channels, teens and users awaiting confirmation won't be able to access them.
Thanks, as always, for taking the time to read Stream Report.
Pete ✌️

