Internet15.06.2026

Questions about alleged TikTok breach that exposed the private data of 2.4 billion people

A threat actor has claimed to have breached TikTok’s systems and is selling alleged private user data, including emails, usernames, and phone numbers of more than 2.4 billion TikTok users.

“Hello. On 5 June 2026, we leaked the TikTok data — 2.4 billion user records, including email addresses and phone numbers. Total records: 2,461,892,091,” they said.

They also shared a sample of the leaked data, which appeared to also include gender and preferred language information for each user.

It should be noted that the breach is unconfirmed, and some people have accused the purported hacker behind it of trying to scam potential buyers.

This is because the forum post included a link to a paid Telegram channel for buyers to download the database. To subscribe, users must pay 10,000 stars, or approximately R4,400, per month.

MyBroadband asked TikTok about the alleged breach and if any South African users were impacted, but it hadn’t provided feedback by the time of publication.

While the alleged TikTok breach remains unconfirmed, MyBroadband has observed a new trend following claimed data breaches, where companies rubbish them as containing fake data samples.

Cybernews researchers said they believe the alleged TikTok data likely came from infostealers, or spyware designed to quietly infiltrate devices, harvest information, and exfiltrate it to remote servers.

They said the samples lacked specific flags to indicate that the data belonged exclusively to TikTok users. Instead, it could be stolen data with TikTok’s name attached as “bait”.

The team warned that if the leak is confirmed, malicious actors could exploit the data in various ways, such as phishing and vishing attacks.

Cybersecurity expert Boikokobetso Makhetloane, who goes by Mr Fingerz online, spoke to Cape Talk about the alleged breach and warned that it would likely result in many account takeovers if legitimate.

“They are going to take these passwords and usernames and sell them on the dark web, so other people can buy them and use them as well,” he said.

“There’s going to be a lot of account takeovers because a lot of people don’t have certain safety features on their accounts.”

Scammers advertised fake hacks on South African companies

DatingBuzz users that were allegedly impacted through a claimed breach

Several scammers have claimed responsibility for breaching various South African businesses in recent months. However, these appeared to be attempts to scam dark web users into paying for data.

These have included claims of breaches of a dating website, South African network operator Telkom, and “Wanderers.co.za”.

DatingBuzz is one of South Africa’s oldest and most popular online dating sites, and its operator recently denied claims that it had been breached and that customer records were exposed.

This followed a threat actor advertising data allegedly containing over 670,000 records from DatingBuzz.co.za users on a deep web hacker forum.

They set a price of R19,479 for the data and said it included full names, email addresses, account passwords, and user chats.

Duncan Forrest, founder and CTO of DatingLab, the UK-based software company operating DatingBuzz’s platform, told MyBroadband that it hadn’t experienced any breaches in recent months.

“We’re not aware of any breaches, and no one has contacted us directly to try to ransom our data or sell it back to us,” Forrest said.

He explained that there were field names contained in the sample data which DatingLab did not use, and which included data points the company didn’t keep.

“For example, none of our sites accepts profile videos, so none of our databases contains anything related to them,” Forrest said.

Forrest said that, on closer inspection of the post, he was “inclined to write this off as another fake post” because there was no verifiable data.

Another scammer claimed to have breached Wanderers.co.za, the site for the Wanderers’ Stadium. However, the provided data sample appeared to belong to the Wanderers Club.

In the end, it turned out the threat actor hadn’t breached either entity’s systems and was running a scam.

Another threat actor, in May 2026, claimed to have accessed Telkom systems and exfiltrated customer data. The actor was advertising data purportedly from Telkom on the deep web.

However, Telkom said there was no evidence to suggest its systems had been breached, but said it remained vigilant and would continue investigating such claims.

“Telkom employs robust, multi-layered cybersecurity measures and continuous monitoring to safeguard customer information and protect against malicious activity,” it said.

Show comments

Latest news

More news

Trending news

Sign up to the MyBroadband newsletter