Supply chain β›“ Supply Chain

StreamElements Gooten Merchandise Operations Vendor Breach

πŸ“… 2025-02-15 🏒 Gooten (merchandise/print-on-demand fulfillment)
Primary Source β†—

Incident Details

StreamElements, a platform for live streaming tools and creator merchandise, disclosed in March 2025 that a third-party vendor breach had exposed customer data. The breach originated at Gooten, StreamElements’ merchandise fulfillment partner used to handle print-on-demand and merchandise shipping for content creators. Exposed data included creator and fan names, home addresses, phone numbers, and email addresses. StreamElements notified affected users and has since moved to alternative merchandise fulfillment providers. The incident highlighted the risk exposure of content creator platforms that pass fan shipping addresses to fulfillment vendors.

Technical Details

Initial Attack Vector
Gooten, a merchandise fulfillment and print-on-demand vendor used by StreamElements for its creator merchandise programs, was compromised, exposing StreamElements content creator customer data
Vendor / Product
Gooten (merchandise/print-on-demand fulfillment)
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2025-02-15 Breach occurred
  2. 2025-03-20 Publicly disclosed
  3. 2025-03-20 Customers notified