TikTok reportedly suffers data breach
However, one researcher inspected some of the files and found it included publicly accessible data which could have been put together without a breach


TikTok has reportedly suffered a data breach which includes 790GB of user information, although the claims have been found to be inconclusive.
The video platform’s users have been recommended to change their password and enable two-factor authentication by BeeHive CyberSecurity, the researchers who discovered the leak.
Researchers have shared screenshots of the files on Twitter, which include “record_paypal_order” or “tiktok_author_stats”. One researcher, AgainstTheWest, found that the company stored all its internal backend source code on one Alibaba Cloud instance using a weak password.
The researcher also claimed to have discovered 790GB of user information tables from the database, with current user entries at 2.05 billion, they revealed on a database forum.
“Considering the entries are from all over the world, it is unlikely we will sell or release this,” posted AgainstTheWest. “Lastly, this data contains a lot of under-aged people. Releasing such information, along with the data that is being stored without the user's knowledge is so dire that we think it could spark something dangerous.”
However, web security consultant Troy Hunt inspected some of the files and found that it was all publicly accessible data so could have been constructed without a data breach
“This is so far pretty inconclusive; some data matches production info, albeit publicly accessible info,” Hunt wrote on Twitter. “Some data is junk, but it could be non-production or test data. It's a bit of a mixed bag so far.”
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
“TikTok prioritizes the privacy and security of our users’ data," a TikTok spokesperson told IT Pro. "Our security team investigated these claims and found no evidence of a security breach."
This comes after the head of the FCC called on Apple and Google to remove the platform from their app stores over its pattern of surreptitious data practices in June 2022. Commissioner Brendan Carr said that TikTok is available to millions of US citizens and it collects vast troves of sensitive data about them. He underlined that its own by ByteDance, which is “beholden” to the Communist Party of China and required to comply with the government’s surveillance demands.
Zach Marzouk is a former ITPro, CloudPro, and ChannelPro staff writer, covering topics like security, privacy, worker rights, and startups, primarily in the Asia Pacific and the US regions. Zach joined ITPro in 2017 where he was introduced to the world of B2B technology as a junior staff writer, before he returned to Argentina in 2018, working in communications and as a copywriter. In 2021, he made his way back to ITPro as a staff writer during the pandemic, before joining the world of freelance in 2022.
-
Neural interfaces promise to make all tech accessible – it’s not that simple
Column Better consideration of ethics and practical implementation are needed if disabled people are to benefit from neural interfaces
By John Loeppky
-
Solution Brief: Find Known and Unknown Threats Faster
Download Now
By ITPro
-
Latitude Financial's data policies questioned after more than 14 million records stolen
News Some of the data is from at least 2005 and includes customers’ name, address, and date of birth
By Zach Marzouk
-
Latitude hack now under state investigation as customers struggle to protect their accounts
News The cyber attack has affected around 330,000 customers, although the company has said this is likely to increase
By Zach Marzouk
-
IDCARE: Meet the cyber security charity shaping Australia and New Zealand's data breach response
Case Studies IDCARE is recruiting a reserve army to turbocharge the fightback against cyber crime not just in the region, but in the interests of victims all over the world
By Zach Marzouk
-
Australia commits to establishing second national cyber security agency
News The country is still aiming to be the most cyber-secure country in the world by 2030
By Zach Marzouk
-
Medibank bleeds $26 million in cyber costs following hack
News The company believes this figure could rise to $45 million for the 2023 financial year
By Zach Marzouk
-
TikTok's two new European data centres to address data protection concerns
News The company is under pressure to prove its user data isn’t being accessed by the Chinese state
By Zach Marzouk
-
Cyber attack on Australia’s TPG Telecom affects 15,000 customers
News It is the third cyber attack on a major Australian telco since October
By Zach Marzouk
-
Telstra blames IT blunder for leak of 130,000 customer records
News Australia’s biggest telco said that the error was due to a mismanagement of databases and not a cyber attack
By Zach Marzouk