The leak was first uncovered by a researcher named AgainstTheWest, who found that TikTok had stored all its internal backend source code on an Alibaba Cloud server protected by a weak password. The data collected reportedly includes 790 GB of user information from a database covering TikTok’s 2.05 billion users worldwide.

AgainstTheWest said the data includes users from around the world, including many underage accounts. Exposing this kind of information without users’ knowledge is serious and could lead to dangerous consequences.
Security researchers at BeeHive CyberSecurity advised TikTok users to change their passwords and enable two-factor authentication. They also shared screenshots of files on Twitter, including names like “record_paypal_order” and “tiktok_author_stats.”
However, security expert Troy Hunt examined some of the leaked files and found that all the data was publicly accessible. This suggests it might have been compiled rather than coming from an actual data breach. Hunt noted that some of the data appeared to be junk or test data, calling it basically “a mixed bag.”
Responding to the incident, a TikTok spokesperson emphasized that “TikTok prioritizes user privacy and data security.”
Earlier in June 2022, the FCC chair urged Apple and Google to remove TikTok from their app stores over concerns about how TikTok stores user data. With millions of US users, TikTok collects a lot of sensitive information, and the FCC warned that TikTok’s parent company ByteDance could be compelled to share data with the Chinese government if requested.