Supply chain
β Supply Chain
StreamElements Gooten Merchandise Operations Vendor Breach
Primary Source βIncident Details
StreamElements, a platform for live streaming tools and creator merchandise, disclosed in March 2025 that a third-party vendor breach had exposed customer data. The breach originated at Gooten, StreamElements’ merchandise fulfillment partner used to handle print-on-demand and merchandise shipping for content creators. Exposed data included creator and fan names, home addresses, phone numbers, and email addresses. StreamElements notified affected users and has since moved to alternative merchandise fulfillment providers. The incident highlighted the risk exposure of content creator platforms that pass fan shipping addresses to fulfillment vendors.
Technical Details
- Initial Attack Vector
- Gooten, a merchandise fulfillment and print-on-demand vendor used by StreamElements for its creator merchandise programs, was compromised, exposing StreamElements content creator customer data
- Vendor / Product
- Gooten (merchandise/print-on-demand fulfillment)
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2025-02-15 Breach occurred
- 2025-03-20 Publicly disclosed
- 2025-03-20 Customers notified