Platform · Messaging and social communication · Social platform ecosystem · China
Instant messaging platform by Tencent.
The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.
A 2020 dataset of approximately 719.8 million Tencent QQ-linked records (about 668 million distinct QQ email addresses and ~719.5 million email/phone combinations) circulated online and has been associated with the "Mother of All Breaches" (MOAB) aggregation. Exposed data links phone numbers to QQ IDs and QQ Mail addresses. Tencent denied a breach of its systems (both for this and a separate 2024 ~1.4B-record claim), describing the data as recycled/manipulated. It is best characterized as a scraped/compiled dataset of disputed origin.
Full threat analysis, exploitation vectors, and principal guidance below.
10 additional sections · verified field analysis · defensive doctrine
719.8M records analyzed
Tencent QQ is one of China's largest instant-messaging and social platforms (operated by Tencent), with QQ IDs, QQ Mail, and phone-linked accounts used by hundreds of millions of people.
Large messaging and social ecosystems collect user identity, phone numbers, contact graphs, messages, device data, payment-adjacent records, and activity logs across communication services.
A 2020 dataset of ~719.8M QQ-linked records (roughly 668M distinct QQ email addresses and ~719.5M email/phone combinations) circulated and has been associated with the "Mother of All Breaches" (MOAB) compilation. A separate 2024 claim of ~1.4B Tencent records later surfaced; Tencent denied both, characterizing the data as recycled/manipulated rather than a new breach.
The linkage of hundreds of millions of phone numbers to QQ IDs and QQ Mail addresses enables mass phishing/smishing, SIM-swap targeting, and cross-platform account enrichment. Because Tencent disputes a system breach, the dataset is best understood as a scraped/compiled corpus (part of larger aggregations such as MOAB) rather than a confirmed QQ exfiltration.
• Mass phishing and smishing using phone + QQ ID + email | • SIM-swap and account-takeover targeting | • Cross-platform enrichment linking QQ identity to phone/email
A social-platform breach: profile and contact-graph data supports impersonation, enrichment and social engineering. For a high-profile principal the main risk is credible impersonation and enrichment of existing exposure.
Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.
Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.
Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.
Request Consultation