TikTok hack: Have billions of user records been exposed?

TikTok logo
(Image credit: ByteDance)

TikTok has denied claims that hackers have managed to steal more than two billion sensitive database records, including user data and platform source code.

Rumors of a breach originated with a post to an online hacking forum, in which a user called AgainstTheWest claimed to have exploited a TikTok server vulnerability to gain access to gigabytes of data.

However, TikTok says it has found “no evidence of a security breach” and that the records have been scraped from public sources. Analysis of the leaked files by cybersecurity experts appears to corroborate this version of the story.

TikTok scrutiny

Owned and operated by Chinese company ByteDance, TikTok has been under the spotlight since it rose to prominence in western markets back in 2019. Today, the short-form video platform commands more attention per user than Facebook and Instagram combined and the app has been downloaded more frequently than any other in each of the past five quarters.

In 2020, ex-US President Donald Trump moved to ban the platform, which he perceived as a threat to national security. Although the ban never came to pass, in an effort to allay privacy and security concerns, ByteDance agreed to move data related to US-based TikTok users to servers operated by Oracle.

The US software company is also in the process of auditing the platform’s recommendation algorithms, to ensure they are not being manipulated for political purposes by the Chinese Communist Party (CCP), which has traditionally exercised a significant level of control over corporations based in China.

Irrespective of these safety mechanisms, rumors of a large-scale data breach will heighten the focus once again on the platform’s data management practices.

But TikTok claims the data published online was not exposed as a result of a weakness in its security posture, and nor does it relate to source code actively deployed in the platform’s backend.

“We have confirmed that the data samples in question are all publicly accessible and are not due to any compromise of TikTok Systems, networks, or databases,” said the firm, in a statement.

“We do not believe users need to take any proactive actions, and we remain committed to the safety and security of our global community.”

Via The Independent, The Verge

Joel Khalili
News and Features Editor

Joel Khalili is the News and Features Editor at TechRadar Pro, covering cybersecurity, data privacy, cloud, AI, blockchain, internet infrastructure, 5G, data storage and computing. He's responsible for curating our news content, as well as commissioning and producing features on the technologies that are transforming the way the world does business.

Read more
The TikTok logo appears on a smartphone screen with the United States flag in the background
Forget the US TikTok ban – what we need is better social media and privacy laws
DeepSeek
DeepSeek accused of sharing users' data with TikTok's ByteDance in another blow around privacy concerns
Cartoon Phishing
One of the largest data leaks ever sees info on 1.5 billion people leaked online
China flag and EU flag on cloudy sky. Waving in the sky
TikTok among six tech firms under fire for sending Europeans' personal data to China
SearchGPT OpenAI
Hackers offer 20 million OpenAI credentials for sale, but it says there's no evidence of a breach
Participants hold up signs in support of TikTok at a news conference outside the U.S. Capitol Building on March 12, 2024 in Washington, DC.
US TikTok ban: the clock is ticking for Americans' digital freedoms
Latest in Security
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
A worrying Apple Password App vulnerability reportedly left users exposed for months
DeepSeek
Fake DeepSeek installers are infecting your device with dangerous malware
AI tools.
Not even fairy tales are safe - researchers weaponise bedtime stories to jailbreak AI chatbots and create malware
Data leak
Top California sperm bank suffers embarrassing leak
An Android phone being held in the hand
These malicious Android apps were installed over 60 million times - here's how to stay safe
ransomware avast
Billions of credentials were stolen from businesses around the world in 2024
Latest in News
Stability AI 3D Video
Stability AI’s new virtual camera turns any image into a cool 3D video and I’m blown away by how good it is
The Google Wallet app with a mode for kids shown on-screen.
Google Wallet’s new kid-friendly payment system is a win for parents
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
A worrying Apple Password App vulnerability reportedly left users exposed for months
Vertere DG-X turntable on a pink/white TechRadar background
Vertere's elite DG X turntable is modular, expensive, and hugely desirable
Google Pixel 9a
Google is delaying the Pixel 9a to fix a mystery “component quality issue”
The bottom left corner of an Android phone, showing the Phone, Messages, Google icons and Google Search bar
Google Messages remote delete will soon save you from texting embarrassment – and here's how it works