June–July 2026: TikTok faces a proposed class action alleging a June 2026 data breach exposed private information for more than 2.4 billion users, while independent researchers caution the parallel forum leak claim may be repackaged infostealer logs rather than a confirmed server compromise—TikTok has not publicly confirmed either narrative at catalog time.
The class action: Mortazi v. TikTok
Filed June 11, 2026 in the U.S. District Court for the Central District of California (Mortazi v. TikTok Inc., 2:26-cv-06371), the 44-page complaint alleges TikTok failed to implement reasonable cybersecurity, allowing malware exfiltration from an internal database reported compromised around June 11. Alleged exposed fields include names, usernames, emails, phones, dates of birth, gender, language, and location data stored without encryption, per ClassAction.org.
The forum claim—and infostealer skepticism
The same day, a forum actor advertised 2.4 billion TikTok records. Cybernews analyzed 10 samples and concluded:
- No exclusive TikTok markers tie samples to a TikTok server dump
- Data likely harvested via infostealer malware on infected devices, then rebranded
- Headline 2.4B count unverified—appealing marketing for criminals
Why both stories matter legally and practically
Plaintiffs can proceed on negligence theories even when criminal forum math is inflated—but users should not assume every TikTok account was centrally breached without company attestation. The dual narrative is common in 2026 mega-platform incidents: litigation cites internal compromise; researchers see infostealer compost piles labeled with famous logos.
Action items for TikTok users
- Enable MFA and use a unique password.
- Skeptical of SMS/email codes or "account verification" messages.
- Do not download alleged leak archives.
- Monitor ClassAction.org for court-approved notice if the case progresses—no signup required for initial filings.
Canonical record: TikTok 2.4B claim 2026 (unverified).