{"id":3037,"date":"2025-05-31T07:59:22","date_gmt":"2025-05-31T07:59:22","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=3037"},"modified":"2025-05-31T07:59:23","modified_gmt":"2025-05-31T07:59:23","slug":"risk-actor-claims-tiktok-breach-places-428-million-information-up-for-sale","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=3037","title":{"rendered":"Risk Actor Claims TikTok Breach, Places 428 Million Information Up for Sale"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p>A newly emerged menace actor, going by the alias \u201cOften9,\u201d has posted on a distinguished cybercrime and database buying and selling discussion board, claiming to own 428 million distinctive TikTok person data. The submit is titled \u201cTikTok 2025 Breach \u2013 428M Distinctive Traces.\u201d<\/p>\n<p>The vendor\u2019s submit, which appeared on the discussion board yesterday (Could 29, 2025), guarantees a dataset containing detailed person data comparable to:<\/p>\n<ul class=\"wp-block-list is-style-cnvs-list-styled-positive\">\n<li>E-mail addresses<\/li>\n<li>Cell phone numbers<\/li>\n<li>Biography, avatar URLs, and profile hyperlinks<\/li>\n<li>TikTok person IDs, usernames, and nicknames<\/li>\n<li>Account flags like private_account, secret, verified, and ttSeller standing.<\/li>\n<li>Publicly seen metrics comparable to follower counts, following counts, like counts, video counts, digg counts, and pal counts.<\/li>\n<\/ul>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large is-resized\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/hackread.com\/wp-content\/uploads\/2025\/05\/threat-actor-tiktok-breach-428-million-records-sale-1.png\"><img loading=\"lazy\" decoding=\"async\" width=\"711\" height=\"1024\" src=\"https:\/\/hackread.com\/wp-content\/uploads\/2025\/05\/threat-actor-tiktok-breach-428-million-records-sale-1-711x1024.png\" alt=\"Threat Actor Claims TikTok Breach, Puts 428 Million Records Up for Sale\" class=\"wp-image-130642\" style=\"width:638px;height:auto\" srcset=\"https:\/\/hackread.com\/wp-content\/uploads\/2025\/05\/threat-actor-tiktok-breach-428-million-records-sale-1-711x1024.png 711w, https:\/\/hackread.com\/wp-content\/uploads\/2025\/05\/threat-actor-tiktok-breach-428-million-records-sale-1-208x300.png 208w, https:\/\/hackread.com\/wp-content\/uploads\/2025\/05\/threat-actor-tiktok-breach-428-million-records-sale-1-768x1107.png 768w, https:\/\/hackread.com\/wp-content\/uploads\/2025\/05\/threat-actor-tiktok-breach-428-million-records-sale-1-1066x1536.png 1066w, https:\/\/hackread.com\/wp-content\/uploads\/2025\/05\/threat-actor-tiktok-breach-428-million-records-sale-1-1421x2048.png 1421w, https:\/\/hackread.com\/wp-content\/uploads\/2025\/05\/threat-actor-tiktok-breach-428-million-records-sale-1-380x548.png 380w, https:\/\/hackread.com\/wp-content\/uploads\/2025\/05\/threat-actor-tiktok-breach-428-million-records-sale-1-800x1153.png 800w, https:\/\/hackread.com\/wp-content\/uploads\/2025\/05\/threat-actor-tiktok-breach-428-million-records-sale-1-1160x1672.png 1160w, https:\/\/hackread.com\/wp-content\/uploads\/2025\/05\/threat-actor-tiktok-breach-428-million-records-sale-1.png 1682w\" sizes=\"auto, (max-width: 711px) 100vw, 711px\"\/><\/a><figcaption class=\"wp-element-caption\">Screenshot of the Often9\u2019s submit (Picture credit score: Hackread.com)<\/figcaption><\/figure>\n<\/div>\n<p>The inclusion of private fields comparable to e-mail addresses, cell phone numbers, and inner account flags will not be one thing that may be casually scraped from TikTok\u2019s public-facing web site or cellular app. If these particulars are verified by TikTok to be correct and up to date, it suggests entry to both inner TikTok programs or an uncovered <strong><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/hackread.com\/american-express-cardholders-third-party-data-breach\/\" data-type=\"post\" data-id=\"113923\" target=\"_blank\" rel=\"noreferrer noopener\">third-party database<\/a><\/strong>.<\/p>\n<h3 id=\"threat-actor-explains-how-the-alleged-tiktok-breach-happened\" class=\"wp-block-heading\"><strong>Risk Actor Explains How the Alleged TikTok Breach Occurred<\/strong><\/h3>\n<p>Somebody on the discussion board requested the hacker how the information was extracted, whether or not it was simply scraping or one thing extra. In response, the hacker defined how they allegedly managed to extract the information.<\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"is-style-cnvs-paragraph-callout\" style=\"font-style:normal;font-weight:300\"><em>\u201cUsually, TikTok doesn\u2019t present any public API to entry personal knowledge like emails or cellphone numbers. However some time in the past, resulting from a vulnerability in one in all their inner APIs, it was attainable to extract this knowledge. We found and abused that API earlier than it was patched, which allowed us to gather this dataset. So technically sure, it appears to be like like scraping, but it surely was executed by an exploitable endpoint, not easy public crawling. So briefly: it\u2019s scraped by way of API, however as a result of it leveraged a flaw to entry knowledge that wasn\u2019t meant to be public, It\u2019s a breach.\u201d<\/em><\/p>\n<p><cite>Often9<\/cite><\/p><\/blockquote>\n<p>What does Often9\u2019s reply imply? The menace says that beneath regular circumstances, TikTok doesn\u2019t present any public software (API) that lets somebody entry personal particulars like emails or cellphone numbers. However sooner or later, they discovered a vulnerability in one in all TikTok\u2019s inner APIs.<\/p>\n<p>This flaw allowed them to drag out personal person knowledge that was not meant to be accessible. They used (and abused) this vulnerability earlier than TikTok fastened it, letting them gather a big dataset. <\/p>\n<p>Whereas this course of may seem like \u201c<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/hackread.com\/data-scraping-firm-leaks-instagram-tiktok-youtube-records\/\" target=\"_blank\" data-type=\"post\" data-id=\"80394\" rel=\"noreferrer noopener\"><strong>scraping<\/strong><\/a>\u201d (which normally means gathering public knowledge utilizing automated instruments), on this case, it was extra critical as a result of it concerned exploiting an inner system that uncovered personal data<\/p>\n<p>Including to the load of the declare, the menace actor is keen to work by a intermediary, a standard strategy on prison boards when large-scale knowledge gross sales require third-party verification to construct purchaser belief.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/hackread.com\/wp-content\/uploads\/2025\/05\/threat-actor-tiktok-breach-428-million-records-sale-2.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"281\" src=\"https:\/\/hackread.com\/wp-content\/uploads\/2025\/05\/threat-actor-tiktok-breach-428-million-records-sale-2-1024x281.jpg\" alt=\"Threat Actor Claims TikTok Breach, Puts 428 Million Records Up for Sale\" class=\"wp-image-130643\" srcset=\"https:\/\/hackread.com\/wp-content\/uploads\/2025\/05\/threat-actor-tiktok-breach-428-million-records-sale-2-1024x281.jpg 1024w, https:\/\/hackread.com\/wp-content\/uploads\/2025\/05\/threat-actor-tiktok-breach-428-million-records-sale-2-300x82.jpg 300w, https:\/\/hackread.com\/wp-content\/uploads\/2025\/05\/threat-actor-tiktok-breach-428-million-records-sale-2-768x211.jpg 768w, https:\/\/hackread.com\/wp-content\/uploads\/2025\/05\/threat-actor-tiktok-breach-428-million-records-sale-2-1536x421.jpg 1536w, https:\/\/hackread.com\/wp-content\/uploads\/2025\/05\/threat-actor-tiktok-breach-428-million-records-sale-2-380x104.jpg 380w, https:\/\/hackread.com\/wp-content\/uploads\/2025\/05\/threat-actor-tiktok-breach-428-million-records-sale-2-800x219.jpg 800w, https:\/\/hackread.com\/wp-content\/uploads\/2025\/05\/threat-actor-tiktok-breach-428-million-records-sale-2-1160x318.jpg 1160w, https:\/\/hackread.com\/wp-content\/uploads\/2025\/05\/threat-actor-tiktok-breach-428-million-records-sale-2.jpg 1881w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\"\/><\/a><figcaption class=\"wp-element-caption\">Pattern knowledge screenshot (Picture credit score: Hackread.com)<\/figcaption><\/figure>\n<\/div>\n<h3 id=\"but-heres-why-skepticism-is-warranted\" class=\"wp-block-heading\"><strong>However Right here\u2019s Why Skepticism Is Warranted<\/strong><\/h3>\n<p>Regardless of the attention-grabbing gross sales pitch from the menace actor, a number of purple flags solid doubt on the validity of the declare. Importantly, a major variety of pattern entries present empty or generic fields for emails and cellphone numbers, elevating the likelihood that this dataset was put collectively from <strong><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/hackread.com\/scraped-clubhouse-database-leaked-online\/\" target=\"_blank\" data-type=\"post\" data-id=\"85228\" rel=\"noreferrer noopener\">scraped public profiles<\/a><\/strong> and organised utilizing previous breach knowledge or guesswork.<\/p>\n<p>The menace actor is a brand new account on the discussion board, having joined solely days in the past, with no status, neither constructive nor unfavourable. Within the cybercrime world, status is forex; main breach sellers sometimes have years of verified historical past or previous profitable gross sales.<\/p>\n<p>The discussion board itself has a current historical past of inflated or false breach claims. Notably, the identical platform was used final week to advertise a so-called \u201c1.2 billion Fb person\u201d knowledge sale, which was later uncovered as faux in an <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/hackread.com\/threat-actor-selling-1-2-billion-facebook-records\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>unique Hackread.com investigation<\/strong><\/a>, resulting in the vendor\u2019s ban.<\/p>\n<p>A more in-depth have a look at the pattern knowledge reveals that many fields, person IDs, usernames, profile hyperlinks, and follower metrics, are publicly accessible and might be obtained by large-scale scraping operations. Whereas scraping at scale can nonetheless pose dangers (like phishing or spam campaigns), it doesn&#8217;t equate to a breach of inner programs.<\/p>\n<h3 id=\"cross-checking-email-addresses-with-haveibeenpwned\" class=\"wp-block-heading\"><strong>Cross-Checking E-mail Addresses with HaveIBeenPwned<\/strong><\/h3>\n<p>Hackread.com additionally cross-checked the e-mail addresses within the pattern knowledge towards data on HaveIBeenPwned, and most have been present in fewer than two earlier knowledge breaches. That is alarming and provides some legitimacy to the individuality of the information. Nonetheless, a 1,200-line pattern from a supposedly 428 million file breach will not be sufficient to ascertain legitimacy.<\/p>\n<p>For now, this declare ought to be handled with warning. As tempting because the gross sales numbers could also be, reputationless sellers on cybercrime boards typically exaggerate or fabricate to make a fast revenue or entice consideration.<\/p>\n<h3 id=\"not-the-first-time\" class=\"wp-block-heading\"><strong>Not The First Time<\/strong><\/h3>\n<p>This isn&#8217;t the primary time a menace actor has claimed to breach TikTok\u2019s knowledge. In September 2022, a hacker claimed to have <strong><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/hackread.com\/tiktok-data-breach-hackers-million-records\/\" target=\"_blank\" rel=\"noreferrer noopener\">acquired 2 billion TikTok data<\/a><\/strong>, together with inner statistics, supply code, 790 GB of person knowledge, and extra, a declare that was later denied by the corporate.<\/p>\n<p>Hackread.com has reached out to TikTok and might affirm that the social media large is investigating the alleged breach.<\/p>\n<p>\n\t\t\t<\/div>\n<p><template id="Ohu1kFBqUWpjrZswgJOW"></template><\/script><br \/>\n<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A newly emerged menace actor, going by the alias \u201cOften9,\u201d has posted on a distinguished cybercrime and database buying and selling discussion board, claiming to own 428 million distinctive TikTok person data. The submit is titled \u201cTikTok 2025 Breach \u2013 428M Distinctive Traces.\u201d The vendor\u2019s submit, which appeared on the discussion board yesterday (Could 29, [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":3039,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[2911,641,640,1636,426,2561,2912,461,107],"class_list":["post-3037","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-actor","tag-breach","tag-claims","tag-million","tag-puts","tag-records","tag-sale","tag-threat","tag-tiktok"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/3037","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3037"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/3037\/revisions"}],"predecessor-version":[{"id":3038,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/3037\/revisions\/3038"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/3039"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3037"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3037"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3037"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-06-15 10:47:26 UTC -->