Visualização normal

Antes de ontemCybersecurity News

TikTok Agrees to $400M Settlement Over Children’s Privacy

25 de Agosto de 2026, 14:41

TikTok and ByteDance agree to pay up to $400 million to settle US allegations involving children’s data, parental consent and account deletion.

The post TikTok Agrees to $400M Settlement Over Children’s Privacy appeared first on TechRepublic.

  • ✇Security Affairs
  • TikTok Settles U.S. Child Privacy Case for $400 Million Pierluigi Paganini
    TikTok will pay $400 million to settle U.S. claims that it violated child privacy laws by collecting data from users under 13. The U.S. Department of Justice announced that TikTok will pay $400 million to settle a 2024 lawsuit over children’s privacy. “Today, the Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated entities (TikTok) resolving litigation concerning compliance with the Children’s Online Privacy Protection Act and its implementing
     

TikTok Settles U.S. Child Privacy Case for $400 Million

24 de Agosto de 2026, 04:23

TikTok will pay $400 million to settle U.S. claims that it violated child privacy laws by collecting data from users under 13.

The U.S. Department of Justice announced that TikTok will pay $400 million to settle a 2024 lawsuit over children’s privacy.

“Today, the Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated entities (TikTok) resolving litigation concerning compliance with the Children’s Online Privacy Protection Act and its implementing regulations (COPPA).” reads the press release published by DoJ. “Under the settlement, TikTok will pay $300 million immediately and an additional $100 million upon entry of an order vacating a prior consent decree entered against TikTok’s predecessor, Musical.ly. The settlement represents one of the largest recoveries ever obtained in a COPPA case.”

TikTok will pay $300 million immediately and another $100 million after a court order removes an earlier consent decree involving Musical.ly. The 2024 case, brought by the DoJ and FTC, accused TikTok of knowingly allowing children under 13 to create accounts and illegally collecting data from children using Kids Mode.

Since the Justice Department filed its lawsuit against TikTok in 2024, the company has made major changes to its ownership, management, compliance, and privacy practices. It has also introduced stronger safeguards for younger users, improved age controls, and expanded parental oversight.

The DOJ said these measures have advanced the goals of its case and strengthened protections for millions of U.S. families. The settlement reflects a focus on practical results, securing a significant recovery while recognizing TikTok’s compliance improvements. The case was filed in California and handled by the DOJ’s Civil Division following a referral from the FTC.

“This settlement is a major victory for American children and parents,” said Associate Attorney General Stanley E. Woodward Jr. “The Department’s priority is ensuring that children are protected online and that companies entrusted with their personal information meet their legal obligations. This resolution secures a substantial recovery while reinforcing the protections that families expect and deserve.”

TikTok has faced regulatory scrutiny over children’s privacy before. In September 2023, Ireland’s Data Protection Commission fined the company €345 million for breaching the GDPR through its handling of children’s personal data.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, privacy)

The Cyber Express Weekly Roundup: TikTok Age Verification Probe, Healthcare Data Breach, Qantas Ruling, and Major Cyberattacks

weekly round

This week’s cybersecurity roundup highlights growing concerns around online child safety, healthcare data protection, supply chain risks, and cyber threats affecting organizations worldwide. From regulatory scrutiny of digital platforms to large-scale vulnerabilities and operational disruptions, recent incidents show how cyber risks continue expanding across industries.  The key theme in this weekly roundup is the increasing pressure on organizations to strengthen security, improve data protection measures, and adapt to rapidly changing threat environments. Regulators, businesses, and cybersecurity teams are facing challenges ranging from social engineering attacks and malware incidents to vulnerabilities affecting widely used enterprise technologies. 

The Cyber Express Weekly Roundup 

UK Investigates TikTok Age Verification Compliance 

The UK communications regulator Ofcom has launched an investigation into TikTok’s age verification system, examining whether the platform is meeting its child safety obligations under the Online Safety Act. The probe comes as the UK government prepares stricter social media restrictions for users under 16, with enhanced age assurance requirements expected to take effect by Spring 2027. Read more… 

Partnered Health Cyberattack Exposes Australian Patient Data 

Healthcare provider Partnered Health has suffered a cyberattack that exposed sensitive patient information from 21 clinics across Australia. The compromised data reportedly includes personal details, Medicare information, health insurance records, and medical documents. Authorities and the company continue investigating the incident to determine the full scope of the breach and whether additional information was affected. Read more… 

Qantas Data Breach Cleared After Privacy Review 

Australia’s privacy regulator has concluded its review of the 2025 Qantas data breach, finding no evidence that the airline failed to take reasonable measures to protect customer information. The incident affected approximately 5.67 million records after attackers used social engineering techniques to compromise a contact center employee. Read more… 

Nichirei Cyberattack Disrupts KFC Japan Supply Chain 

Japanese frozen food and logistics company Nichirei experienced a cyberattack that disrupted deliveries to KFC Japan after unauthorized access impacted its systems. The company isolated affected infrastructure, suspended certain logistics operations, and began recovery efforts with external cybersecurity specialists while investigating the incident. Read more… 

Microsoft Patch Tuesday Addresses 622 Security Flaws 

Microsoft’s July 2026 Patch Tuesday update fixed 622 vulnerabilities across its product ecosystem, making it the company’s largest security release to date. The update included patches for two actively exploited zero-day vulnerabilities, CVE-2026-56164 and CVE-2026-56155, affecting Microsoft SharePoint Server and Active Directory Federation Services. Read more… 

Nihon Kotsu Cyberattack Disrupts Japan Taxi Operations 

Japan’s largest taxi operator, Nihon Kotsu, suffered a malware-related cyberattack that forced the company to shut down parts of its IT infrastructure. The incident, detected on July 11, 2026, affected taxi dispatch services and internal systems as the company worked to contain the attack and investigate potential data exposure. Read more… 

Weekly Cybersecurity Takeaway 

This week’s cybersecurity developments highlight the growing complexity of modern cyber threats, with attacks and security challenges affecting technology platforms, healthcare providers, logistics companies, transportation services, and enterprise software environments. From regulatory action on digital safety to actively exploited vulnerabilities and supply chain disruptions, organizations are facing increased pressure to strengthen resilience and respond faster to emerging risks. 
  • ✇Firewall Daily – The Cyber Express
  • TikTok Age Verification Under Investigation as UK Tightens Child Safety Rules Samiksha Jain
    The UK's communications regulator has launched a formal investigation into TikTok age verification, raising questions over whether the platform is adequately protecting children online under the country's Online Safety Act. The move comes as Britain prepares to introduce a social media ban for under-16s, with regulators warning that current age assurance methods used by some platforms may not be sufficient to prevent children from accessing harmful content. The investigation follows the publica
     

TikTok Age Verification Under Investigation as UK Tightens Child Safety Rules

TikTok age verification

The UK's communications regulator has launched a formal investigation into TikTok age verification, raising questions over whether the platform is adequately protecting children online under the country's Online Safety Act. The move comes as Britain prepares to introduce a social media ban for under-16s, with regulators warning that current age assurance methods used by some platforms may not be sufficient to prevent children from accessing harmful content.

The investigation follows the publication of a new Ofcom report that found age checks are becoming more common across online services, but significant gaps remain, particularly on social media platforms and some pornography websites.

Ofcom Questions TikTok Age Verification Method

According to Ofcom, some social media companies rely primarily on age inference methods to identify child users. These systems estimate a user's age based on their online behavior rather than verifying it directly.

The regulator said it has "serious doubts" about whether these methods are capable of meeting the standards required under the Online Safety Act. Ofcom believes some companies may be failing to correctly identify a significant number of children, potentially exposing them to harmful content, including pornography, self-harm, and suicide-related material.

As a result, Ofcom has launched a formal investigation into whether TikTok is complying with its legal duties to protect children from harmful content.

The regulator also warned that age inference alone will not be considered sufficient for enforcing the government's planned restrictions on social media use by children under 16. Platforms using such methods have been urged to adopt more effective age assurance technologies or provide compelling evidence demonstrating their effectiveness.

Age Checks Increase Across Online Services

The report found significant progress in the adoption of age checks since the Online Safety Act's child protection duties came into force in July 2025.

Between July 2025 and January 2026, the proportion of children encountering highly effective age checks increased from 25% to 43%.

Ofcom said more than 69 million age checks were completed across a sample of 32 UK services during the second half of 2025, representing a 23-fold increase compared to the previous six months.

The regulator also reported that all of the UK's top 10 pornography websites and most of the top 100 now have age verification measures in place.

Among children aged 8 to 14 who attempted to access pornography, only 8% visited such services. Half of those children reached only websites with age checks, while nearly 87% of their visits lasted less than 30 seconds, suggesting age verification discouraged continued access.

Search Engines Also Face Scrutiny

Despite the wider rollout of age assurance, Ofcom found that children can still easily discover pornography websites without age checks through Google Search and Bing.

Its analysis found that 33% of first-page Google search results and 54% of Bing results directed users to pornography websites lacking age verification or equivalent protections.

Following discussions with the regulator, Google and Bing have agreed to work with Ofcom on practical measures to reduce the visibility of such websites in search results.

Meanwhile, Ofcom continues enforcement against adult services that fail to comply with the law. The regulator has opened 23 investigations involving 88 adult service providers, with many either introducing age assurance or blocking UK users after enforcement action.

UK Moves Toward Social Media Ban for Under-16s

The investigation comes as the UK government advances plans to introduce a social media ban for under-16s, modeled on Australia's approach.

Under the proposal, platforms including TikTok, Snapchat, Instagram, Facebook, YouTube, and X would be prohibited from offering social media services to users under 16. Messaging services such as WhatsApp and Signal are not expected to be included.

The government also plans to introduce additional protections, including restrictions on livestreaming and communication with strangers for children under 16 across social media and certain gaming platforms. Similar safeguards would apply by default to users aged 16 and 17 to avoid what officials describe as a "cliff-edge" at age 16.

The proposed measures are expected to be presented to Parliament before the end of the year, with implementation targeted for Spring 2027.

Ofcom said it will submit a rapid assessment to Parliament by the end of October outlining what constitutes highly effective age assurance for verifying whether someone is over 16, helping shape future enforcement of the planned restrictions.

Scammers Use TikTok and Instagram Reels to Spread Vidar Infostealer

ReversingLabs reveals how hackers exploit social media engagement metrics to deliver Vidar infostealer malware to thousands of unsuspecting users.

💾

  • ✇Security Boulevard
  • TikTok Says No to End-to-End Encryption: Here’s Why That’s a Big Deal Tom Eston
    In a move that bucks the entire industry trend, TikTok has confirmed it will not implement end-to-end encryption (E2EE) for direct messages on its platform — arguing that E2EE would make users less safe. We break down what’s really going on: the child safety argument, the privacy counterargument, the geopolitical questions surrounding ByteDance, and what […] The post TikTok Says No to End-to-End Encryption: Here’s Why That’s a Big Deal appeared first on Shared Security Podcast. The post TikTok S
     

TikTok Says No to End-to-End Encryption: Here’s Why That’s a Big Deal

9 de Março de 2026, 01:00

In a move that bucks the entire industry trend, TikTok has confirmed it will not implement end-to-end encryption (E2EE) for direct messages on its platform — arguing that E2EE would make users less safe. We break down what’s really going on: the child safety argument, the privacy counterargument, the geopolitical questions surrounding ByteDance, and what […]

The post TikTok Says No to End-to-End Encryption: Here’s Why That’s a Big Deal appeared first on Shared Security Podcast.

The post TikTok Says No to End-to-End Encryption: Here’s Why That’s a Big Deal appeared first on Security Boulevard.

💾

  • ✇Security Boulevard
  • TikTok’s New U.S. Deal and Privacy Policy: What Users Don’t Understand Tom Eston
    TikTok has shifted to a majority-American entity, TikTok USDS Joint Venture, LLC, to comply with U.S. national security requirements and avoid a ban. This week we discuss why a recent privacy policy update went viral—especially language about sensitive data like immigration status and precise location—and argue much of it reflects longstanding practices and required California […] The post TikTok’s New U.S. Deal and Privacy Policy: What Users Don’t Understand appeared first on Shared Security Po
     
❌
❌