TikTok was alleged by newly emergent threat actor "Often9" to have had 428 million unique user records stolen through the exploitation of an internal API vulnerability, Hackread reports. Included in the stolen dataset were individuals' email addresses, mobile numbers, TikTok user IDs, usernames, nicknames, biographies, avatar URLs, profile links, account flags, and other metrics, according to Often9. "Normally, TikTok doesn't provide any public API to access private data like emails or phone numbers. But a while ago, due to a vulnerability in one of their internal APIs, it was possible to extract this data," Often9 claimed. While there has been some skepticism regarding the legitimacy of the dataset, which included numerous empty or generic email and phone number fields, most of the exposed data analyzed by Hackread was noted to have been observed in less than two other breaches. TikTok, which had 2 billion records claimed to have been stolen almost three years ago, has already launched a probe into the latest purported data breach.
Breach, Data Security, Application security
Massive TikTok breach claimed to compromise 428M users

(Adobe Stock)
An In-Depth Guide to Application Security
Get essential knowledge and practical strategies to fortify your applications.
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds