
Cloud-based streaming tools provider StreamElements has confirmed a data breach involving a third-party service provider it severed ties with last year. The company assured users that its own servers remained unaffected, though older customer data stored by the former partner was exposed.
The breach came to light after a threat actor, using the alias "victim," claimed responsibility for the attack on March 20, 2025. The hacker alleged they had obtained the personal data of 210,000 StreamElements customers and leaked samples on a hacking forum. These records reportedly included full names, addresses, phone numbers, and email addresses.
StreamElements addressed the incident publicly, stating: "We recently became aware of a data security incident involving a third-party service provider we stopped working with last year. We can confirm no StreamElements servers have been breached."
The company emphasized that, while the breach did not originate within its own infrastructure, it remains committed to protecting customer data and is reaching out to those affected to assess the impact.
According to streaming journalist Zach Bussey, who was contacted by someone linked to the hacking group, the leaked data appears to be authentic. Bussey recounted his verification attempt on social media platform X: "I attempted to verify the legitimacy of the data breach by requesting my own personal details from orders placed in 2021 or 2022. Seconds later, they provided that information, including my name, address, postal code, phone number, and email."
The hacker further alleged that the breach was enabled by malware targeting a StreamElements employee, allowing unauthorized access to an internal account. This reportedly led to the exfiltration of customer data from 2020 to 2024, specifically from the platform’s order management system.
Although StreamElements has not yet begun sending official breach notifications, affected users—especially those registered between 2020 and 2024—are urged to exercise caution. The company has warned of phishing attempts leveraging the breach, where malicious actors send fraudulent “data breach” emails in an effort to scam recipients.
Despite the initial leak, the hacker’s post on the dark web marketplace BreachForums has since been removed. Meanwhile, StreamElements has confirmed that an investigation is ongoing to determine the full extent of the breach and its implications.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543