Data breach
XSplit
- Records
- 2,992,382
- Breach date
- 7 November 2013Estimated
- Added
- 1 December 2024
What was exposed
4 types of data · 1 puts you at serious risk
- Usernames2,992,377
- Email addresses2,992,339
- Names2,991,969
- Passwords2,936,977
About this breach
In November 2013, XSplit, the company behind popular live streaming and recording software used by gamers, suffered a data breach that exposed information tied to roughly 2.99 million user accounts. According to our investigation team, the estimated breach date is November 7, 2013, and the records in this listing include usernames, email addresses, real names, and passwords for the overwhelming majority of affected accounts. The listing was not claimed by any known actor.
XSplit itself confirmed problems at the time. On November 7, 2013, the company posted a system wide password reset alert, saying it believed data on its servers had been compromised, including XSplit account names, hashed passwords, and account names and stream keys for live streaming services users had connected. The company told users that no PayPal or credit card payment information was stored with XSplit account data. Twitch, the streaming platform, also published a warning the same period, telling its users that XSplit credentials and Twitch account names and stream keys may have been exposed, and that such exposure could allow an outsider to broadcast to a user's Twitch channel.
Breach Timeline
November 6, 2013: Twitch published an alert warning that data on XSplit's servers had been compromised and that Twitch account names and stream keys may have been exposed.
November 7, 2013: XSplit issued a system wide password reset, citing reports of suspicious activity and stating that account names, hashed passwords, and stream keys for connected streaming services may have been taken.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses, usernames or nicknames, real names, and passwords.
The password field was present in about 2.94 million of the roughly 2.99 million records, while email addresses, usernames, and names appeared in nearly all of them. XSplit's own notice from the time of the breach also indicated that account names and stream keys for live streaming services users had linked to XSplit may have been compromised.
Not every individual is affected by every type of data listed here.
XSplit said at the time that passwords were stored in hashed form. The company also stated that no PayPal or credit card payment information was stored in XSplit account data.
What Are the Potential Risks for Affected Individuals?
The most immediate risk involves passwords. Even hashed passwords can be cracked, especially weaker ones, and attackers routinely test stolen credentials against other websites. If you reused your XSplit password anywhere else, those accounts could be at risk through credential stuffing, where automated systems try stolen username and password pairs across many services.
Twitch's notice from the breach period highlighted a second concern: stream keys. Anyone who obtained a user's stream key could broadcast to that user's channel without permission. The company advised affected streamers to reset their stream keys.
Names and email addresses exposed in a breach like this also support phishing. Attackers who know your email address and the services you use can craft more convincing messages that appear to come from a legitimate company, often urging you to reset a password or verify an account.
What Is XSplit Doing in Response?
XSplit's verified response at the time was a system wide password reset, announced on November 7, 2013, with a link users could follow to reset their passwords by email. The company also encouraged users to update passwords on other sites where they had used the same or similar passwords. We did not find any more recent public statement from XSplit about this 2013 incident, as of September 25, 2026.
What Should You Do If You Were Affected?
If you had an XSplit account around 2013, take these steps:
Change your XSplit password if you have not done so since the breach, and make the new one unique.
If you used the same or a similar password on other accounts, change those too. This matters most for email, banking, and social media.
If you streamed to Twitch through XSplit, reset your Twitch stream key to prevent unauthorized broadcasts on your channel.
Watch for phishing emails that reference XSplit or streaming services, and avoid clicking password reset links in unsolicited messages.
Consider a password manager so each account gets a distinct password.
In the news
- XSplit Password Reset Alert, November 7, 2013xsplit.com (opens in a new tab)
- Twitch blog: XSplit Password Reset Alertblog.twitch.tv (opens in a new tab)
- Mozilla Monitor: XSplit Data Breachmonitor.mozilla.org (opens in a new tab)
- CyberInsurance.com: XSplit breach summarycyberinsurance.com (opens in a new tab)
