leaksear.ch has indexed a Stripchat leak containing 10,002,085 user records from the adult live-streaming platform, with email addresses, usernames, IP addresses, country data, ISP data, and browser fingerprints present in the dataset (leaksear.ch metadata). Public reporting tied the 2021 exposure to an unsecured Elasticsearch cluster discovered on November 5, 2021, and Stripchat later described the incident as a temporary server breach during server reconfiguration (comparitech.com, stripchat.com).
What happened
Comparitech reported that its cybersecurity research team, led by Bob Diachenko, found a database that appeared to belong to Stripchat on November 5, 2021, alerted Stripchat that day, and found the database was no longer available on November 7. The report said the database was accessible on the internet without a password or other authentication and that it was unclear how long it had been exposed before being indexed by search engines (comparitech.com).
Stripchat acknowledged the issue in a November 12, 2021 blog post, saying a temporary data breach was detected during routine server reconfiguration and that the company had secured the servers. Stripchat said its assessment at the time found that passwords, payment details, account verification documents, and private live sex chat messages were not accessed (stripchat.com).
Have I Been Pwned lists Stripchat as a sensitive breach, says several databases were left exposed and unsecured in November 2021, and says more than 10 million Stripchat records appeared on a popular hacking forum in June 2022. Threatpost reported at the time that it was unclear whether anyone with malicious intent accessed the exposed data before it was secured (haveibeenpwned.com, threatpost.com).
What data was exposed
According to the leaksear.ch indexing metadata, the searchable pivots in this Stripchat dataset are country, email address, IP address, and username (leaksear.ch metadata). Other fields stored with records include a browser fingerprint, an internal ID, and the ISP associated with the IP address, but those fields are not direct search pivots on leaksear.ch (leaksear.ch metadata).
Public reports on the broader 2021 exposure described additional categories in the unsecured cluster, including user account data, model records, transaction information about tokens and tips, and moderation data. Stripchat's own statement said passwords, payment details, account verification documents, and private live sex chat messages were not accessed, so those should not be assumed to be present in this indexed dataset unless confirmed by the metadata (comparitech.com, stripchat.com).
Why this matters
Stripchat is an adult platform, so linkage between an email address, username, IP address, country, ISP, and browser fingerprint can create privacy risk even without passwords or payment cards. HIBP flags the breach as sensitive, meaning the fact that an account appears in the breach can itself be harmful if exposed to the wrong person (haveibeenpwned.com).
The practical risks are targeted phishing that references Stripchat, attempts to connect pseudonymous usernames to real identities, and harassment or extortion threats using location clues derived from IP and country data. Comparitech warned that exposed data from the incident could put viewers and models at risk of phishing, stalking, harassment, humiliation, and extortion (comparitech.com). Anyone who may have used Stripchat should check whether their email address, username, IP address, or country appears in this leak using the exposure check on this page.
Check your exposure
Vetted researchers and incident-response teams can request access or sign in if they already have access to check this dataset. Searchable pivots for this leak include country, email, ip address, and username.
Sources
- Have I Been Pwned: Stripchat Data Breach
- Comparitech: Sex cam site Stripchat exposes user, model info on the web: report
- Stripchat: Temporary Server Breach Identified
- Threatpost: 200M Adult Cam Model, User Records Exposed in Stripchat Breach
- HackRead: Stripchat database mess up exposes 200M adult cam models, users' data
- DeHashed: StripChat Data Breach November 2021: 10 Million User Records Leaked