The torrent appeared on 4chan on 6 October 2021: roughly 125 gigabytes of Twitch's internal life, posted anonymously and labelled part one. Inside sat source code for twitch.tv and its console and mobile clients, internal security tools, an unreleased Amazon game-store project codenamed Vapor, and — the part that mattered to everyone outside the security industry — records of what Twitch had paid its creators since August 2019. The poster asked for nothing. The stated aim was to "foster more disruption and competition in the online video streaming space", and the accompanying text made clear this was punishment, not commerce. Twitch confirmed the same day that a breach had taken place.
The payout files did the travelling. Within hours they had been parsed into league tables, and streaming had its first public rich list: Critical Role, the Dungeons & Dragons show, at the top with about $9.6 million across the period, and the streamer xQc listed at $8.4 million. Several creators checked their own rows and said the figures matched. Every number deserves its caveats — these are gross payouts from subscriptions, adverts and bits, taken from stolen files rather than audited accounts, and they exclude the sponsorships and donations that for many streamers are worth more than the platform itself pays. None of that slowed the sport. The most-read document from one of the largest corporate leaks on record was, in effect, a salary spreadsheet.
Twitch's explanation, when it came, was almost apologetic in its smallness: an error in a server configuration change had exposed data to the internet, and a malicious third party had reached it. The dates matter here, so this archive sets them out. Disclosure was involuntary and instantaneous — the 4chan post itself. Discovery, for Twitch as for everyone else, happened the same day. How long the misconfigured server had stood open before someone walked through it, the company has never publicly said. On 7 October it reset every account's stream key as a precaution; on 15 October it said its investigation showed passwords had not been exposed, and that Twitch does not store full card numbers. No extortion demand preceded the leak, and nothing was offered for sale afterwards.
The label said part one. Part two never arrived — no second torrent, no arrest, no attribution beyond an anonymous handle, and five years on, whoever briefly held Twitch's entire ledger has never surfaced. That silence is what keeps the story strange. This archive is otherwise a catalogue of leverage: encryption, deadlines, negotiation portals. Here was a mega-breach with no ransom note, whose most-discussed casualty was salary privacy. Its longest effect was probably cultural. Creator earnings became something discussed in the open, because for one week in October 2021 they simply were public, and Twitch's later fights with streamers over revenue splits played out in front of an audience that had already seen the books.
REvil restored from backups. So did the FBI.
REvil's public face, a forum persona called 0_neday, posted on 17 October that someone had hijacked the gang's Tor sites using the group's own private keys, and that the operation was shutting down. The explanation arrived four days later, when Reuters — citing three private-sector experts working with US agencies, and one former official — reported a multi-government operation involving the FBI, Cyber Command and the Secret Service alongside allied countries. The mechanism was the elegant part. After the Kaseya attack in July, REvil had gone dark; in September it rebuilt its infrastructure from backups. But law enforcement was already inside, and the backups came up compromised — the servers the gang trusted were servers the governments controlled. Researchers at Group-IB noted the symmetry: corrupting backups is a ransomware technique, used this time against ransomware. The attribution remains reported rather than officially confirmed, a distinction this archive records. In January 2022, Russia's FSB raided fourteen alleged members at Washington's request — weeks before the invasion of Ukraine ended such cooperation, possibly for good.
Cyberattack 64411
On 26 October, Iran's subsidised-fuel system failed nationwide. Drivers inserting government fuel cards at the country's roughly 4,300 stations were met not with petrol but with a message on the pump screens — cyberattack 64411 — the number of a public helpline run from the supreme leader's office. Hijacked motorway billboards in Tehran and Isfahan addressed Khamenei by name and asked where the fuel was. The head of Iran's civil defence organisation, Gholamreza Jalali, blamed the United States and Israel; President Ebrahim Raisi said the attack was designed to make people angry by creating disorder and disruption. A group calling itself Gonjeshke Darande — Predatory Sparrow — claimed the operation, linking it to the July attack on Iran's railways that had displayed the same telephone number. Reconnecting every pump took days of station-by-station work. At the time the group was an unknown quantity; it did not stay one. The name returns in this archive: steel plants in 2022, the petrol network again in December 2023, a bank and a cryptocurrency exchange in 2025.
Acer India: a claim, and — unusually — a confirmation
On 13 October, a group calling itself Desorden posted on a hacking forum that it had taken roughly 60 gigabytes from the servers of Acer India's after-sales service operation, attaching samples of customer records and company documents. The claimed haul — the 60-gigabyte figure, and its record counts — comes from the attackers, and no independent forensics were ever published. What makes the incident stand out is what happened next. Acer confirmed it the same week, describing an isolated attack on its local after-sales systems in India, saying the affected data was customer-service information rather than financial details, and that CERT-In had been notified. An analysis of the posted samples put the freshest records at early October: attack, claim and confirmation inside a fortnight. Days later the same group demonstrated access to an Acer server in Taiwan, which the company also acknowledged.
The confirmation is the point. India's 2021 had been a year of large claimed breaches answered with denial, silence or months of delay — airline passengers, pizza orders, payment-app customers — so a multinational replying to a forum post within days, on the record, with a regulator informed, was the exception that mapped the rule. It was also Acer's second incident of the year, after a ransomware gang had demanded $50 million from it in March. From 2026, the missing furniture is obvious: India in October 2021 had no data-protection statute and no breach-notification deadline. CERT-In's six-hour reporting rule was six months away, and the DPDP Act would not pass for nearly two years. Confirmation was a courtesy, not an obligation — which is exactly why it was rare.
The scale race reaches 530 billion
On 11 October, Microsoft and NVIDIA announced Megatron-Turing NLG, a language model of 530 billion parameters, three times the size of GPT-3 and then the largest dense model ever trained — the work of 560 DGX A100 servers running in parallel. The companies presented it as a research milestone rather than a product, and a milestone it stayed: within a year the field had concluded that the giants of this era were undertrained for their size, and the race moved from parameter counts to data, and then to products. Eight days later Google announced the Pixel 6, the first phone built around Tensor, a chip of Google's own design that favours machine-learning work over raw speed — live translation, on-device transcription and photograph editing that removes passers-by, all running on the handset rather than a server. A phone sold on what its neural hardware could do was a novelty in 2021; five years on, it is simply how phones are sold.
The decryptor that stayed secret
The month's most instructive disclosure concerned something that had already stopped working. On 24 October it emerged that Emsisoft had spent months quietly decrypting victims of BlackMatter, the operation widely regarded as DarkSide's rebrand, after its researchers found a critical flaw in the gang's encryption. Rather than publish — which would have prompted a fix within hours — the firm worked through law enforcement agencies, CERTs and incident-response companies to reach victims privately, recovering files encrypted between mid-July and late September without a ransom changing hands. The gang spotted and patched the flaw at the end of September; only once the window had closed did anyone speak. The quiet campaign bracketed a loud one: on 18 October, CISA, the FBI and the NSA issued a joint advisory on BlackMatter intrusions at US critical-infrastructure firms, food and agriculture among them. On 1 November the gang declared itself closed, citing pressure from the authorities — and within weeks researchers were tracing its tools and personnel to a Rust-built successor, BlackCat, proof the shutdown was a change of name, not of people.
⏳ Time capsule — October 2021
- William Shatner flew to the edge of space aboard Blue Origin's New Shepard on 13 October — at 90, the oldest person yet to fly.
- Dune, Denis Villeneuve's long-awaited adaptation, opened in US cinemas and on HBO Max simultaneously on 22 October.
- Pakistan beat India by ten wickets at the T20 World Cup in Dubai on 24 October — their first win over India at a World Cup, at the thirteenth attempt.
- Mark Zuckerberg announced on 28 October that Facebook's parent company would now be called Meta, betting the firm's future on the metaverse.
The month the books opened
Each thread runs forward into editions this archive has already restored. The REvil operation set the template — get inside quietly, take the infrastructure later — refined against Hive in January 2023, when the FBI turned out to have spent six months reading the gang's mail, and against LockBit in 2024's Operation Cronos. REvil itself ended with those January 2022 FSB raids, the last act of US-Russian cyber cooperation before the invasion of Ukraine closed the door. Predatory Sparrow kept its name and its taste for infrastructure: steel plants in 2022, Iran's petrol network again in December 2023, Bank Sepah and the Nobitex cryptocurrency exchange in June 2025 — each in its own edition of these pages.
Twitch rebuilt, reset its keys and moved on; the leak's real legacy was a norm shift, with creator earnings discussed more openly ever since, because the numbers had been public once. Seen from five years out, the month has a single pattern. A platform's ledger, a gang's servers, a government's petrol pumps — all run on the assumption that the inside was inside, and October 2021 spent four weeks disproving it. The Vault continues backwards from here, and the further back it goes, the clearer the finding becomes: nothing in these pages was ever as private as its owners believed.