TL;DR
- On June 11, 2026, cybercriminals reportedly stole the private data of over 2.4 billion TikTok users worldwide, an amount the complaint says impacts “nearly all TikTok users.”
- The stolen records included names, usernames, email addresses, phone numbers, dates of birth, gender, language, and location data. The complaint alleges this data was stored unencrypted.
- A California resident, Sean Mortazi, filed a federal class action (Case No. 2:26-cv-06371) accusing TikTok of ignoring basic, expected security standards while profiting off the exact data it failed to protect.
- TikTok’s public Privacy Notices claim “Your privacy is a top priority” while the complaint alleges the company left billions of user records exposed and detectable exfiltration went unstopped.
- TikTok’s parent ByteDance was reportedly on track for roughly $50 billion in profit in 2025, revenue built largely on harvesting the same user data now sitting on the Dark Web.
The Non-Financial Ledger
The data that leaked cannot be canceled or reissued. You can close a stolen credit card. You cannot close your date of birth, your real name, or the phone number tied to every account you own. The complaint states this information is “impossible to close and difficult, if not impossible, to change,” which means the harm follows victims for the rest of their lives.
The complaint describes the emotional weight of this in plain terms: anxiety, panic, fear, frustration, and even intense anger are common responses to a cyberattack. It compares the experience to being robbed, except the thief keeps a copy of you and can sell it again and again. The knowledge that your information sits “out in the open, available for sale and exploitation at any time in the future” is itself described as real harm.
Some of the people caught in this breach are minor children and young adults who have not even established credit yet. They now inherit a lifetime of vigilance they never agreed to, forced to watch their financial lives for fraud that may not surface for years.
Legal Receipts
“Your privacy is a top priority at TikTok. Whether we’re introducing new features or building on the products you love, we continuously incorporate our privacy principles throughout our product lifecycle.”
- This is TikTok’s own public Privacy Notice language, quoted in the complaint. It establishes the promise against which the alleged failure is measured.
- The complaint alleges the company left user data unencrypted and failed to detect the exfiltration of billions of records, contradicting the “top priority” claim.
“We use reasonable measures to help protect information from loss, theft, misuse, unauthorized access, disclosure, alteration, or destruction.”
- Pulled directly from TikTok’s Privacy Policy. It is a specific commitment to protect against exactly the outcome that allegedly occurred.
- The complaint argues these “reasonable measures” were absent, pointing to a lack of encryption, monitoring, and multi-factor authentication.
“Given that the threat actors successfully implemented malware and exfiltrated the Private Information of billions of individuals to third-party networks, Defendant therefore did not have systems in place to detect or prevent the Data Breach.”
- This is the complaint’s core factual accusation: the sheer scale of the theft is treated as proof that monitoring systems either failed or did not exist.
- It frames the breach as a detection failure, not just an unlucky attack, meaning red flags that should have triggered alarms were allegedly ignored or never built.
Public Deception
The complaint documents a direct gap between what TikTok told users about privacy and what it alleges actually happened to their data.
- TikTok publicly stated privacy is “a top priority” and that it “continuously incorporate[s] our privacy principles.” The complaint alleges billions of records were left in an unencrypted database with no system able to stop the theft.
- TikTok’s Privacy Policy promised “reasonable measures” against loss, theft, and unauthorized access. The complaint alleges the company failed to implement encryption, strong passwords, and multi-factor authentication.
- TikTok claimed “strong protections are in place to help keep people safe.” The complaint alleges a separate breach of nearly one million user passwords occurred around April 2025, putting the company on clear notice its records were being targeted.
Profit-Maximization at All Costs
The complaint frames the breach as the predictable cost of a business model that treats user data as the product while allegedly underinvesting in protecting it.
- ByteDance, TikTok’s parent, was reportedly on track for approximately $50 billion in profit in 2025, according to the complaint.
- The complaint states TikTok’s revenue is “largely based on advertisements generated by tracking, collecting, and utilizing its users’ Private Information,” the same data now leaked.
- TikTok ad revenue was projected to potentially top $32 billion, per a source cited in the complaint, underscoring how central data harvesting is to the balance sheet.
- The complaint alleges TikTok skipped basic, low-cost safeguards like encryption and multi-factor authentication that would have rendered the stolen data “worthless” to thieves.
- It argues the company profited from the data at both ends: monetizing it to make money, then failing to spend on the security that would protect it.
How Capitalism Exploits Delay: Time as a Corporate Weapon
The complaint alleges TikTok knew of the breach but had not notified affected users, a delay that itself compounds the harm.
- Under California’s Customer Records Act, disclosure must be made “in the most expedient time possible and without unreasonable delay.” The complaint alleges TikTok knew an unauthorized person acquired unencrypted data but “has yet to notify them.”
- The complaint argues this delay prevents victims “from taking appropriate measures to protect themselves against harm,” causing “incrementally increased damages.”
- Stolen data can sit for a year or more before being used. The complaint cites law enforcement noting fraud may continue “for years” after data is posted, meaning delay in notice widens the window of exposure.
- On average it takes roughly three months for a victim to discover their identity was stolen, and some victims take up to three years to find out, per sources cited in the complaint.
Supply Chain Complicity
The complaint repeatedly extends TikTok’s duty to its vendors, alleging the company failed to secure or require security not just from itself but from third parties handling user data.
- The complaint alleges TikTok failed to implement “employee and vendor training” and failed to require verification protocols for third parties accessing sensitive systems.
- It alleges TikTok failed “to require the same” industry-standard cybersecurity measures “from their vendor,” pointing to a possible weak link outside TikTok’s direct walls.
- The complaint references verifying “that third-party service providers have implemented reasonable security measures” as an FTC-recommended step it alleges TikTok did not meet.
- Downstream, the billions of ordinary users are the exposed party: they handed over data with no visibility into who else could touch it or how it was protected.
Legal Minimalism: The Letter but Not the Spirit
The complaint argues TikTok posted the right privacy language while allegedly ignoring the substance those words were meant to guarantee.
- The FTC Act (15 U.S.C. ยง 45) treats failure to maintain reasonable data security as an “unfair practice.” The complaint alleges TikTok published privacy commitments while failing the underlying security obligations those commitments imply.
- The complaint points to the Gramm-Leach-Bliley Act (15 U.S.C. ยงยง 6801 et seq.) and FTC guidance as frameworks TikTok allegedly acknowledged in policy but did not follow in practice.
- TikTok’s Privacy Policy “touts how Defendant purports to protect sensitive Private Information,” which the complaint uses to show the company understood its duty and still allegedly fell short of it.
Regulatory Gray Zones
The complaint highlights the industry standards that exist but which no single mandatory rule forced TikTok to fully adopt before the breach.
- The complaint invokes the NIST Cybersecurity Framework and the Center for Internet Security’s Critical Security Controls as “established frameworks for reasonable cybersecurity readiness,” which are guidance rather than binding statutes.
- It cites CISA’s “Shields Up” recommendations, including multi-factor authentication and network monitoring, as standards TikTok allegedly failed to meet without a specific law compelling each one.
- The complaint leans on FTC enforcement precedent (FTC v. Wyndham Worldwide Corp.) to argue lax security is legally actionable, filling the gap left by the absence of a single comprehensive federal data security statute.
Societal Impact Mapping
The complaint maps harm across the public and the economy, describing a breach whose scale touches nearly every user of one of the world’s largest apps.
Public Health
- The complaint documents the psychological toll of data breaches, describing “anxiety, panic, fear, and frustration, even intense anger” as common responses.
- It warns stolen data can be used to “get medications or medical procedures” fraudulently in a victim’s name, corrupting their medical records.
- Victims face indefinite stress from knowing their information is permanently exposed and cannot be recovered or changed.
Economic Inequality
- The complaint states the risk of “account takeovers, scam attempts, or attempted account takeovers rises 88%” for breach victims.
- Victims must spend out-of-pocket on credit monitoring, fraud prevention tools, and mitigation, costs shifted onto individuals who did nothing wrong.
- Identity theft resolution is slow and unequal: 76% of victims needed more than a month to resolve issues, and 48% still had not resolved them after a year, per the ITRC data cited.
- Minor children and young adults, who often lack credit monitoring, are exposed before they can even defend themselves.
- “Fullz” packages let criminals combine the stolen data with other sources, commanding up to $100 per record on the Dark Web, monetizing victims repeatedly.
Who Pays? Following the Cost
The complaint describes a clean one-way transfer: TikTok profited from the data, and users absorb the cost of protecting themselves after it was allegedly left exposed.
- The originating party, TikTok, retained the profit and benefit from harvesting user data while allegedly declining to spend on the security to protect it.
- The cost lands on billions of users who must now devote “time, money, and energy” to monitoring accounts, changing credentials, and screening for phishing.
- Victims bear the expense of “credit monitoring, mitigation efforts, and fraud prevention tools,” an ongoing tax with no set end date.
- The complaint notes even reimbursed victims are not made whole due to the “significant time and effort associated with seeking reimbursement.”
The “Cost of a Life” Metric
The complaint sets a corporate profit figure against the human scale of the breach.
This Is the System Working as Intended
The complaint’s facts describe a structure where harvesting data is enormously profitable and protecting it is treated as optional until a lawsuit forces the question.
- The complaint alleges TikTok collects data precisely because it is valuable, then failed to fund the “basic and expected industry standard” measures that would protect it, showing the incentive to collect outran the incentive to secure.
- It documents a reported ~1 million password breach around April 2025 that “put Defendant on notice,” yet the far larger breach followed, suggesting prior warnings did not change behavior.
- The complaint notes data breaches “are preventable” and that most result from “lax security and the failure to create or enforce appropriate security policies,” framing the outcome as a choice, not an accident.
- With no single comprehensive federal data security law, the complaint must stitch together the FTC Act, GLBA, and voluntary NIST and CIS frameworks, exposing how the current system leaves enforcement to after-the-fact litigation.
What a Legitimate Fix Looks Like
The core structural failure this case exposes is a company allegedly profiting from mass data collection while treating basic protection as discretionary. The following are editorial recommendations grounded in the documented failures alleged in the complaint.
Regulatory Track
- The FTC should require encryption of sensitive personal data at rest and in transit as a baseline enforceable standard, directly addressing the complaint’s allegation that data was stored unencrypted.
- Regulators should mandate real-time exfiltration monitoring with automatic alerts on large data transfers, the exact control the complaint alleges was missing when billions of records left the network undetected.
- As a general industry standard drawn from FTC guidance, regulators should require verified third-party vendor audits, since the complaint alleges TikTok failed to require security from its vendors.
Legislative Track
- Legislators should pass a comprehensive federal data security law so accountability does not depend on stitching together the FTC Act, GLBA, and voluntary frameworks after a breach already occurred.
- Breach notification timelines should carry mandatory deadlines and penalties for delay, addressing the complaint’s allegation that TikTok knew of the breach yet had not notified affected users.
- Lawmakers should strengthen California’s CCPA and Customer Records Act enforcement to include automatic statutory damages for storing unencrypted personal data that is later breached.
Corporate Governance Track
- TikTok should be required to fund and maintain multi-factor authentication and least-privilege access controls, the specific safeguards the complaint alleges were absent.
- Executive compensation should be tied to documented security investment and audit results, so protecting user data becomes a board-level priority rather than an afterthought.
- The company should implement mandatory employee and vendor security training with verification protocols, directly targeting the training gaps the complaint identifies.
What Now?
Direct your energy toward the entity named in the complaint, TikTok Inc., a California corporation with its principal place of business in Culver City, and toward the regulators empowered to hold it accountable.
- Watchlist: The FTC, which the complaint says treats failure to secure data as an “unfair practice” under Section 5 and has brought enforcement actions for exactly this conduct.
- Watchlist: The California Attorney General and state privacy regulators enforcing the CCPA (Cal. Civ. Code ยงยง 1798.100 et seq.) and the Customer Records Act.
- Protect yourself: Place a fraud alert or credit freeze with the three credit bureaus and review your credit reports, the steps the FTC recommends after a breach.
- Organize locally: Support digital rights and consumer privacy groups pushing for a comprehensive federal data protection law and mandatory breach notification.
- Act collectively: If your data was in a TikTok account, watch for class notice in Case No. 2:26-cv-06371 and understand your right to participate in collective relief.
The source document for this investigation is attached below.
Explore by category
Product Safety Violations
When companies sell dangerous goods, consumers pay the price.
View Cases →Financial Fraud & Corruption
Lies, scams, and executive impunity that distort markets.
View Cases →


