Breach, Data Security, Application security

Massive TikTok breach claimed to compromise 428M users

TikTok app logo on the screen and a finger about to touch it.

TikTok was alleged by newly emergent threat actor "Often9" to have had 428 million unique user records stolen through the exploitation of an internal API vulnerability, Hackread reports.

Included in the stolen dataset were individuals' email addresses, mobile numbers, TikTok user IDs, usernames, nicknames, biographies, avatar URLs, profile links, account flags, and other metrics, according to Often9. "Normally, TikTok doesn't provide any public API to access private data like emails or phone numbers. But a while ago, due to a vulnerability in one of their internal APIs, it was possible to extract this data," Often9 claimed. While there has been some skepticism regarding the legitimacy of the dataset, which included numerous empty or generic email and phone number fields, most of the exposed data analyzed by Hackread was noted to have been observed in less than two other breaches. TikTok, which had 2 billion records claimed to have been stolen almost three years ago, has already launched a probe into the latest purported data breach.

An In-Depth Guide to Application Security

Get essential knowledge and practical strategies to fortify your applications.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds