Unverified claim: On July 20, 2026, threat-intel coverage reported that a forum actor calling themselves Erich dumped what they described as the full YouNow user database — roughly 22+ million records with emails, social IDs, IPs, device data, and spending/moderation fields. YouNow had not confirmed the YouNow data breach claim at indexing time.
Canonical record: YouNow forum dump claim.
What happened according to the leak listing
YouNow is a live-streaming platform where broadcasters and viewers build social graphs, tip with virtual currency, and often link Facebook, Google, or X accounts. That product surface makes a “full user export” listing especially sensitive: it is not just emails and password hashes; it can include behavioral and device identifiers useful for stalking or account takeover on linked networks.
Beralock’s July 20, 2026 write-up said Erich posted a database export spanning over 22 million rows, with UIDs cited in a high range, and described fields including username, email, social network IDs, names, gender, age, birth date, country, IP addresses, language/locale, registration and last-login dates, VIP and coin/points balances, device IDs and OS versions, moderation scores, spending history, and admin-related flags.
Daily Dark Web and other monitors amplified similar “22+ million user records” language. Some secondary summaries online use different partial figures; BreachHistory indexes the ~22 million actor/reporter count from the detailed dump coverage while labeling the entire incident unverified.
What was allegedly exposed
If authentic, the mix of social tokens/IDs, IP history, device fingerprints, and moderation verdicts is more dangerous than a bare email list. Attackers can craft messages that reference a user’s broadcast history or linked Google identity, raising click-through on phishing.
Spending history and coin balances can support romance-scam or “refund” social engineering. Moderation flags could enable harassment if leaked alongside real names and locations.
There is a separate historical Have I Been Pwned YouNow breach entry involving on the order of 18 million unique emails from an earlier incident. Do not assume the July 2026 forum dump is the same dataset; treat it as a new unverified claim until HIBP or YouNow says otherwise.
Company confirmation status
At the time Beralock published, YouNow had not issued a public statement. Absence of a denial is not confirmation. Until the company, a regulator, or a trusted loader such as HIBP attests a new 2026 load, search results for “YouNow breach 2026” should emphasize the unverified label.
Users who still have YouNow apps installed should review connected OAuth permissions regardless — that hygiene helps whether or not this particular dump is genuine.
Who is at risk
Current and former YouNow broadcasters and viewers whose emails or phone-adjacent identifiers appear in any circulating sample.
People who used the same password on YouNow and email — rotate immediately if you ever reused credentials.
Anyone who linked Facebook, Google, or Twitter/X to YouNow — revoke those grants in each provider’s security settings.
Minors’ guardians should be aware live-streaming platforms can expose social graphs; watch for stalking or sextortion lures referencing old usernames.
Live-streaming platforms and dump culture
Entertainment and creator platforms repeatedly appear in forum dumps because they accumulate rich profile metadata. 2026 continues that trend with both verified corporate disclosures and unverified actor marketing.
Compare YouNow’s alleged export to other creator-economy incidents in the catalog: always separate companyConfirmed true rows from leak-site claims. Scale alone does not equal verification.
Action items
- Revoke YouNow’s access to Facebook, Google, and X/Twitter in each provider’s connected-apps page.
- Change email passwords if they were ever reused with YouNow.
- Enable MFA on email and any linked social accounts.
- Watch for phishing that references your old YouNow username or coin balance.
- Review bank/PayPal statements if you purchased coins or subscriptions.
- Consider deleting or locking dormant YouNow profiles you no longer use.
- Parents: talk to teens about not reusing streamer passwords across games and email.
- Follow YouNow’s official channels only for any future confirmed notice.
Canonical record and sources
Catalog: https://breachhistory.com/younow/younow-forum-dump2026. Coverage: Beralock; historical context via Have I Been Pwned — YouNow.
OAuth and social-graph fallout
Live platforms that encourage social login create blast radius beyond the app itself. A dumped Facebook ID or Google subject identifier helps attackers correlate identities across sites even when passwords differ.
Revoking OAuth grants is the highest-leverage step for YouNow users after this claim. It costs little and closes a door whether Erich’s dump is authentic or exaggerated.
Broadcasters who reused stream titles and donation links across Twitch or Kick should expect impersonation channels to appear; claim brand handles early and enable platform 2FA.
Moderation score fields, if real, raise ethics issues for republication — researchers should redact aggressively.
Field-level risk analysis for the alleged YouNow export
Email plus username is enough for credential-stuffing tests against other sites. Adding Facebook, Google, and Twitter IDs enables correlation attacks and targeted social engineering that references a real linked identity.
IP addresses and device UUIDs support stalking and physical threat models for public broadcasters, especially those who streamed from home networks. Lifetime coin and spending fields help attackers invent fake “refund” stories with plausible numbers.
Moderation scores and abuse verdicts are particularly sensitive. If authentic, they can be weaponized for harassment. Researchers should not mirror those columns publicly.
Birth dates and gender fields increase identity-fraud utility when combined with emails. Even without government IDs, the package resembles a marketing enrichment dump more than a simple password list.
Admin role permissions in an export — if present — would be a severe privilege-map leak. Treat any such column as high severity in incident response tabletop exercises.
Why local creator platforms keep appearing in dumps
Creator economies concentrate PII, payment adjacency, and social graphs in a single product database. Attackers know fans will click messages that mention a streamer’s handle.
Unverified dumps still generate real-world harm because scammers do not wait for confirmation. The news cycle itself is the payload.
YouNow’s earlier HIBP presence means many users already recycle breach fatigue. Emphasize that July 2026 is a new claim requiring fresh OAuth revocation, not a reason for complacency.
Platforms that allow tipping should assume financial phishing will reference coin balances after any dump rumor.
Verification checklist for future YouNow statements
Look for a signed statement on younow.com, not a random Discord admin. Prefer notices that describe date ranges, data elements, and whether passwords were salted hashes or plaintext.
If HIBP announces a new YouNow load with a 2026 breach date, that becomes strong independent verification. Until then, keep companyConfirmed false.
UID ranges cited in coverage are interesting but forgeable. Do not treat screenshots of row counts as proof.
Compare actor reputation: Beralock noted Erich’s low forum reputation. Low reputation does not prove fabrication, but it argues for caution.
Extended FAQ
Is the YouNow database leaked? A forum actor claims a ~22M row dump; YouNow had not confirmed at indexing.
I only watched streams — am I included? Viewers with accounts can appear in user tables even if they never broadcast.
Should I delete the app? Optional, but revoke OAuth and rotate reused passwords either way.
What about the 3.96 figure I saw elsewhere? Secondary posts sometimes cite partial metrics; BreachHistory uses the ~22M actor/reporter figure from detailed dump coverage while keeping the unverified label.
Additional context and practical guidance
Live-streaming audiences skew young. Guardians should help teens revoke OAuth links and understand that an old YouNow username can still power impersonation years later.
Broadcasters who collected fan Discord invites through YouNow should warn communities about admins unexpectedly asking for wallet seed phrases after “database leak” panic.
If you purchased coins with a stored card, monitor that card for micro-charges. Card data was not the centerpiece of the alleged dump description, but adjacent financial phishing remains likely.
Device ID and UUID fields, if real, can support persistent tracking narratives in scareware pages that claim “we still see your phone.” Those pages are scams; factory-reset fear is the goal.
Creators who reused YouNow passwords on email must assume inbox takeover risk and enable MFA before debating whether Erich’s reputation score undermines authenticity.
Platform trust-and-safety alumni know moderation tables are radioactive in leaks. Even unverified claims should trigger internal reviews of how long such scores are retained.
Compare the alleged 22 million row export with YouNow’s historical HIBP footprint so you do not mis-attribute old fills to the July 2026 forum post when checking email search tools.
International users should remember that IP fields can reveal travel patterns. Be careful accepting “account recovery” calls that recite a city you streamed from years ago.
If YouNow eventually confirms, expect a cleaner data-element list and guidance on coin balances. Until then, prioritize OAuth revocation over waiting for a perfect FAQ.
Researchers mirroring the dump should strip social tokens and moderation columns before any limited analysis sharing. Secondary harm is not required to evaluate authenticity.
Brand partnerships that ran campaigns on YouNow in past years may see spear-phish against marketing ops claiming leaked influencer contact sheets — verify through known agency contacts.
Bookmark the BreachHistory YouNow claim record so community mods can point panicked fans to a labeled unverified summary instead of screenshot chains.
Creator-economy security lessons from the YouNow claim
Live platforms blur the line between entertainment accounts and identity hubs. Fans reconnect across Discord, Instagram, and payment tips using the same email. When a YouNow data breach rumor hits, attackers only need a familiar username to open a conversation that feels personal. Moderators of fan servers should pin a short statement: no admin will ever ask for seed phrases, remote access, or gift cards because of a database leak.
Agencies that booked talent through YouNow campaigns in prior years should alert talent managers to expect fake booking confirmations referencing “leaked contact sheets.” Verify every new wire instruction by phone. Brands that still have pixels or login integrations with YouNow should review whether those OAuth apps remain necessary; unused grants are free attack surface.
If you are a former broadcaster cleaning up your footprint, export any content you need, revoke social links, change email passwords, and consider requesting account deletion where the platform allows it. Even unverified dumps teach the same hygiene lesson: social login convenience becomes correlation fuel in the wrong hands.
Parents and schools running media literacy sessions can use this incident as a concrete example. Teens understand streaming better than password hashing. Explain that “22 million records” headlines are signals to lock down accounts, not invitations to paste emails into random checkers.
Security researchers evaluating authenticity should look for consistent UID sequencing, bounce rates on sampled emails, and overlap with historical YouNow corpuses — without publishing sensitive moderation fields. Responsible handling matters as much as scoops when the alleged victim has not confirmed.
Finally, watch YouNow’s official site and app store listings for any security banner. Third-party Telegram channels claiming insider confirmation are unreliable. BreachHistory will flip companyConfirmed only when primary attestation arrives.
Stay aligned with primary sources linked in this article, keep MFA enabled on related accounts, and treat unexpected payment or identity requests that cite this news cycle as fraud until verified through official channels you already trust.
Organizations should update threat briefings with the correct verification status, brief support staff on social-engineering scripts, and document decisions for auditors who will ask how the firm responded to widely shared headlines.
Individuals should prefer official apps and bookmarked portals over search ads, refuse remote-support tools offered by cold callers, and record dates of any suspicious contacts for law-enforcement reports if financial loss occurs.
Researchers and journalists can reduce harm by withholding raw PII samples, emphasizing unverified labels, and updating stories promptly if company confirmation or a credible denial with forensic detail arrives.
Bookmark the BreachHistory canonical record for this incident so internal tickets, community posts, and customer replies point to a stable summary rather than a changing chain of screenshots.
Additional protective reminder: verify sender domains carefully, prefer passkeys or phishing-resistant MFA where available, and discuss this incident only through channels your security team has approved for customer or employee communications.
Additional protective reminder: verify sender domains carefully, prefer passkeys or phishing-resistant MFA where available, and discuss this incident only through channels your security team has approved for customer or employee communications.
Additional protective reminder: verify sender domains carefully, prefer passkeys or phishing-resistant MFA where available, and discuss this incident only through channels your security team has approved for customer or employee communications.
Additional protective reminder: verify sender domains carefully, prefer passkeys or phishing-resistant MFA where available, and discuss this incident only through channels your security team has approved for customer or employee communications.
Additional protective reminder: verify sender domains carefully, prefer passkeys or phishing-resistant MFA where available, and discuss this incident only through channels your security team has approved for customer or employee communications.
Additional protective reminder: verify sender domains carefully, prefer passkeys or phishing-resistant MFA where available, and discuss this incident only through channels your security team has approved for customer or employee communications.
Additional protective reminder: verify sender domains carefully, prefer passkeys or phishing-resistant MFA where available, and discuss this incident only through channels your security team has approved for customer or employee communications.
Additional protective reminder: verify sender domains carefully, prefer passkeys or phishing-resistant MFA where available, and discuss this incident only through channels your security team has approved for customer or employee communications.
Additional protective reminder: verify sender domains carefully, prefer passkeys or phishing-resistant MFA where available, and discuss this incident only through channels your security team has approved for customer or employee communications.
Additional protective reminder: verify sender domains carefully, prefer passkeys or phishing-resistant MFA where available, and discuss this incident only through channels your security team has approved for customer or employee communications.