Kick, the video livestreaming platform, was listed on the mogilevich ransomware group’s leak site on March 01, 2024. The group claims it successfully breached Kick’s systems and exfiltrated 75GB of internal files containing information on streamers, users, the affiliate program, and logs. The listing states the data is also for sale and sets a public extortion deadline of March 10, 2024. Anyone whose username, email, payment details, or streaming logs touched Kick may now face heightened risk of identity theft or targeted harassment.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Kick
Get alerted the next time Kick files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Kick’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details from the Leak Site
The mogilevich leak site entry, archived via ransomware.live, states that the actors “successfully breached kick’s system.” It lists the compromised material as streamers/users, affiliate program and logs data and specifies an exfiltrated volume of 75GB. The disclosure does not quantify the exact number of affected individuals, nor does it itemize every file type beyond the broad categories above. It explicitly notes that the data “is also for sale” and gives interested parties until 3.10.24 to contact the group. These statements come directly from the primary listing; no independent verification of the data sample has been published by Kick at the time of writing.
Why This Matters for You and Your Family
If you or anyone in your household has streamed, chatted, subscribed, or used the affiliate program on Kick, your information may be sitting inside the 75 GB archive now circulating among criminals. Even basic details such as usernames, linked emails, or payment logs can be combined with other breaches to build a profile that leads to account takeovers, phishing, or swatting attempts. Children or teens who use the platform under a family account are equally exposed, because gaming and livestreaming credentials frequently reuse the same passwords or recovery emails that protect school accounts and family devices.
The Doxxing and Identity-Chain Risk
Ransomware groups rarely stop at simple credential lists. Once internal logs and affiliate records leave a company’s control, threat actors and opportunistic buyers can map usernames to real-world identities, wallet addresses, streaming schedules, and chat histories. That information fuels doxxing chains: a leaked email leads to a password reset on another service, which yields a phone number, which appears in a separate breach, and the cycle accelerates. Public reporting on similar incidents shows that livestreaming platforms are high-value targets precisely because their users often maintain persistent online personas that cross over into gaming accounts, Discord servers, and social media. A single 75 GB package can therefore become the starting point for sustained harassment or financial fraud against you or your children.