Social Networks

Former ByteDance executive alleges TikTok of wrongful conduct

A former ByteDance executive revealed that the China government has access to TikTok data, including data stored in the United.

Yintao Yu, the head of engineering for ByteDance’s U.S. operations from August 2017 to November 2018, revealed that the Chinese government has access to all TikTok data, including information stored in the United. He explained that the government can turn off the Chinese version of ByteDance’s apps.

The man claims he was fired for revealing the ‘wrongful conduct’ of the company conduct while working for it.

Yu explained that the government of Beijing used TikTok as a ‘propaganda tool’ promoting content promoting “core communist values.” He states, for example, that TikTok demoted content that users published to express their support for the protests in Hong Kong

The former employee also accused ByteDance to have stolen content from other social network platforms, including Instagram and Snapchat.

“Yu said ByteDance developed software that would scrape user content from competitors’ websites without permission.” reported the Associated Press. “He alleges the company would then repost the content on its own websites – including TikTok – to attract more engagement from users.”

The allegations were made in a complaint by the former executive, as part of a termination lawsuit filed in May in San Francisco Superior Court.

Yu also alleges BitTok used a network of fake accounts to boost its engagement metrics.

The man is asking to be compensated for the damages caused by the unfair dismissal and to receive the lost earnings for some 220,000 ByteDance shares that were not accrued at the time of the dismissal.

ByteDance has yet to comment on the allegations.

In March 2023, Canada announced the ban of the popular Chinese video-sharing app from the mobile devices of its employees over security concerns.

The US first warned of the alleged link between the Chinese company and the Communist Party, accusing TikTok of collecting and sharing data for Chinese intelligence. At the end of February, the European Union banned the popular Chinese video-sharing app TikTok from the mobile devices of its employees over security concerns. 

A similar move was adopted by the US Government that banned the use of TikTok on all government devices by the end of February 2023 due to national security concerns related to TikTok’s ties to China

In January 2020, the US Army banned the use of the popular TikTok app on mobile phones used by its personnel for security reasons.

In November 2022, the short-form video-sharing service updated its privacy policy for European Economic Area (“EEA”), the UK, and Switzerland and confirmed that its users’ data can be accessed by its personnel, including Chinese employees.

European user data could be also accessed by TikTok staff in Brazil, Canada and Israel as well as the US and Singapore, where user data is currently stored.

In December, TikTok parent company ByteDance revealed that several employees accessed the TikTok data of two journalists to investigate leaks of company information to the media. 

According to an email from ByteDance’s general counsel Erich Andersen which was seen by the AFP news agency, the Chinese company was attempting to discover who shared company information with a Financial Times reporter and a former BuzzFeed journalist.

The company fired an undisclosed number of employees who were involved in the data leak because they violated the company’s Code of Conduct, but it did not reveal their names.

In an attempt to discover the location of the unfaithful employees, the Chinese personnel analyzed their IP addresses, but this method was approximate.

We are in the final!

Please vote for Security Affairs (https://securityaffairs.com/) as the best European Cybersecurity Blogger Awards 2022 – VOTE FOR YOUR WINNERS
Vote for me in the sections where is reported Securityaffairs or my name Pierluigi Paganini

Please nominate Security Affairs as your favorite blog.

Nominate Pierluigi Paganini and Security Affairs here here: https://docs.google.com/forms/d/e/1FAIpQLSepvnj8b7QzMdLh7vWEDQDqohjBUsHyn3x3xRdYGCetwVy2DA/viewform

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, TikTok)

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

MITRE revealed that nation-state actors breached its systems via Ivanti zero-days

The MITRE Corporation revealed that a nation-state actor compromised its systems in January 2024 by…

4 hours ago

FBI chief says China is preparing to attack US critical infrastructure

China-linked threat actors are preparing cyber attacks against U.S. critical infrastructure warned FBI Director Christopher…

16 hours ago

United Nations Development Programme (UNDP) investigates data breach

The United Nations Development Programme (UNDP) has initiated an investigation into an alleged ransomware attack…

19 hours ago

FIN7 targeted a large U.S. carmaker with phishing attacks

BlackBerry reported that the financially motivated group FIN7 targeted the IT department of a large…

1 day ago

Law enforcement operation dismantled phishing-as-a-service platform LabHost

An international law enforcement operation led to the disruption of the prominent phishing-as-a-service platform LabHost.…

1 day ago

Previously unknown Kapeka backdoor linked to Russian Sandworm APT

Russia-linked APT Sandworm employed a previously undocumented backdoor called Kapeka in attacks against Eastern Europe since…

2 days ago

This website uses cookies.