TikTok 2.4B Breach Claim Class Action
A class action says a June 2026 breach exposed 2.4 billion TikTok users. TikTok denies any compromise, researchers found no markers tying the data to TikTok, and the samples look like repackaged infostealer logs. The claim is shaky - the complaint's negligence checklist still matters to defenders.
California-based consumer Sean Mortazi brought a class action complaint against TikTok Inc. in the U.S. District Court for the Central District of California on 11 June 2026. He claimed that a breach of user data exposed the personal data of over 2.4 billion users globally. At first glance, that would be among the biggest breaches in history. However, TikTok disputes this, stating there is no evidence of any system compromise, and researchers analysing the data think there may not have been a TikTok breach at all.
Mortazi's claim comes from a post on a high-profile leak forum, published the same date the complaint was filed, offering what the author claimed were 2.4 billion TikTok records, with some sample data provided. Exposed fields mentioned in the complaint include names, usernames, email addresses, phone numbers, dates of birth, gender, preferred languages and location data - all of which, the lawsuit alleges, TikTok stored unencrypted while failing to implement the basic security measures that could have prevented such an attack.
However, the technical review shows the story appears much different. Researchers from Cybernews analysed samples of the data and did not find any distinctive identifiers linking the records specifically to TikTok, and believe the data was obtained through infostealer malware - i.e. stolen from compromised devices and sold to potential buyers as if it belonged to TikTok. Additionally, Cybernews could not verify whether the dataset contained billions of records. A second post appeared on the forum at almost the same time, claiming approximately 3,000 lines of TikTok usernames and email addresses along with plaintext passwords. This type of formatting is commonly seen in logs produced by infostealers - and such logs typically contain valid login credentials for services that have never experienced a breach, because the compromise occurred on the end user's own device.
Additionally, we see a pattern emerging here. This is at least the fourth unverified TikTok mega-claim in four years. In September 2022, a threat actor claimed 2.05 billion TikTok and WeChat records; Troy Hunt's analysis concluded the claimant had combined publicly accessible and junk data and characterised the evidence as inconclusive, while TikTok attributed the samples to third-party sources and stated there was no compromise. In April 2025, a group calling itself R00TK1T claimed about 927,000 TikTok passwords, and TikTok questioned those claims. In May 2025, another seller offered 428 million records based primarily on fields that can easily be scraped. Importantly, the April 2025 incident the new complaint cites as proof TikTok was on notice that its systems were a target is itself one of these unverified claims.

The complaint itself is significant despite this. The plaintiff has submitted a 44-page complaint containing ten counts, including negligence and negligence per se, breach of implied contract built on TikTok's privacy policy statement "Your privacy is a top priority at TikTok", invasion of privacy under California common law and the state constitution, unjust enrichment, and violations of several California statutes including the California Consumer Privacy Act, the California Customer Records Act and the California Unfair Competition Law. The alleged failures read like an auditor's worst nightmare: no encryption of user data, no multifactor authentication, internal access far broader than users needed to perform their tasks, no working intrusion detection, poor network monitoring, and nothing in place to flag large volumes of data leaving TikTok's servers. According to the complaint, TikTok earned roughly $50 billion in profit in 2025 alone and should therefore have allocated sufficient resources to protecting users' sensitive information. The plaintiff seeks monetary damages, injunctive relief requiring stronger security controls at TikTok, and a declaratory judgment that TikTok violated its legal duties to users, on behalf of a nationwide US class and a California subclass. There is currently no settlement, no claims process and no money available, and none of these allegations has yet been proven in court.
Bottom Line
At this point, based on what has been publicly disclosed, this appears to represent infostealer logs and scraped data wearing a generic TikTok label rather than an actual 2.4 billion-user breach of TikTok systems. The company has issued a specific denial of any compromise; Cybernews investigators found no unique identifiers within the samples indicating the data came exclusively from TikTok; and it is economically beneficial for individuals selling stolen credentials to package them under an attractive brand-name label. Treat the reported total as unsubstantiated.
This does not mean the exposure is merely theoretical. Whether or not the platform was breached is irrelevant: infostealer-harvested credentials function because the extraction took place on each individual user's device. Enforce multifactor authentication, phishing-resistant where feasible, continuously monitor stealer-log marketplaces for your organisation's domains, and understand that the types of user data represented in these datasets - emails, phone numbers, dates of birth and location data - will continue to fuel phishing and social engineering campaigns against your users.
Finally: read through the complaint's failed-security list twice. Encryption at rest, multifactor authentication, least-privilege access, working intrusion detection, egress monitoring - that list is what plaintiffs' firms now treat as the reasonable-security baseline, and this case demonstrates that a forum post containing sample records is enough to put a company in front of a judge. Benchmark your organisation against it, keep forensic capability ready to verify or kill a claim quickly, and respond with specifics - TikTok's precise, evidence-based denials are the only reason this one remains contested.