A threat actor group called N0n claims to have stolen TapClicks’ source code and a customer marketing database, including password hashes and ad-platform credentials. TapClicks has not publicly confirmed the breach. Anyone with a TapClicks account or connected advertising credentials should change passwords immediately and monitor accounts for suspicious activity.
| Company | TapClicks |
|---|---|
| Industry | Other Commercial |
| Data Types Exposed | Platform Source Code, Production Architecture Details, Client Lists, User Account Password Hashes, Ad-Platform Connection Credentials, Advertising Platform Datasets |
| People Affected | Not Publicly Disclosed |
| Attack Method | Extortion/Data Theft |
| Regulators Notified | Not Publicly Disclosed |
Were you affected by this breach?
You may be owed compensation.
Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.
Check if you qualify — free reviewWhat Happened in the TapClicks Data Breach?
A threat actor group calling itself N0n has claimed responsibility for a data theft incident involving TapClicks, a marketing analytics and SaaS platform used by businesses across the United States. The group listed the alleged stolen data on a dark web leak site, setting a deadline for payment before threatening to release the material publicly. As of this writing, TapClicks has not publicly confirmed the incident.
According to the claim, the attackers say they obtained the platform’s complete source code, including more than 97,000 commits with full development history. They also claim to have accessed the company’s multi-tenant instance management system, which reportedly includes production architecture details. In addition, the group says it holds a customer’s full marketing database, containing hundreds of advertising platform datasets.
Because this is currently an unconfirmed claim, the exact discovery date of any intrusion has not been publicly disclosed. It also remains unclear how the attackers may have gained access to TapClicks systems. No forensic investigation details, timeline, or root-cause findings have been released publicly at this stage.
Given the sensitivity of the alleged data, including password hashes and platform credentials, the situation warrants close attention. Affected businesses and individuals should watch for official communication from TapClicks. Meanwhile, it is reasonable to treat the exposure risk as serious until more information becomes available.
Who was affected?
The population affected by this claimed TapClicks data breach has not been publicly disclosed in terms of an exact number. Based on the nature of the alleged stolen data, however, both TapClicks’ business customers and their end users could be affected. This includes companies that used the platform to manage advertising campaigns.
Because TapClicks operates as a multi-tenant SaaS platform, a single customer database breach can ripple outward. For example, client lists and user accounts tied to one customer’s marketing operations may include data belonging to that customer’s own clients. As a result, the true scope of individuals impacted could extend well beyond TapClicks’ direct customer base.
The geographic scope also remains unclear beyond the confirmed US connection. Since TapClicks serves marketing teams and agencies, affected individuals could include marketing professionals, agency employees, and consumers whose data flows through connected advertising platforms. Until TapClicks or the threat actors release more specifics, the full breadth of affected parties cannot be confirmed.
What Information Was Potentially Exposed?
The threat actor group’s claim describes several categories of sensitive information. This includes both platform-level technical data and customer-facing personal and business information. Below is a summary of what the group says it obtained.
- Complete platform source code with commit history
- Production architecture and instance management details
- Advertising platform datasets tied to a customer’s marketing operations
- Client lists
- User accounts, including password hashes
- Ad-platform connection credentials
If accurate, this combination of data creates meaningful risk. Password hashes, even when not immediately readable, can sometimes be cracked using automated tools, especially if weak or reused passwords were involved. This means affected users could face account takeover attempts, not just on TapClicks but on any other service where they reused the same password.
In addition, ad-platform connection credentials could allow unauthorized parties to access connected advertising accounts. This could lead to fraudulent ad spending, data manipulation, or further compromise of connected marketing systems. Client lists and business data, meanwhile, could be used for targeted phishing campaigns against real companies and their employees.
What is the company doing?
Because this incident stems from a claim made by the N0n group rather than a confirmed statement from TapClicks, there is no publicly disclosed information about a company investigation. TapClicks has not issued a public statement confirming the breach, and it has not described any remediation or notification steps at this time.
As a result, it is not possible to report on specific protective measures, credit monitoring offers, or password reset actions from TapClicks related to this event. If TapClicks confirms the incident and releases response details, affected individuals should look for direct communication through official channels. Until then, caution is warranted for anyone with a TapClicks account or connected advertising credentials.
What Should Affected Individuals Do?
Change Your Passwords Immediately
If you have a TapClicks account, change your password right away. Choose a strong, unique password that you have not used on any other site. This is especially important because the claimed data includes password hashes, which attackers can sometimes crack over time.
In addition, if you reused your TapClicks password anywhere else, change those passwords too. Password reuse is one of the most common ways a single breach turns into multiple account compromises. Consider using a password manager to keep track of unique passwords going forward.
Review Connected Advertising Platform Accounts
Because the claim mentions ad-platform connection credentials, review any advertising accounts linked to TapClicks. Look for unauthorized changes, unusual ad spending, or unfamiliar login activity. If you notice anything suspicious, disconnect the integration and change your credentials immediately.
Furthermore, enable multi-factor authentication on all connected advertising and marketing accounts where possible. This adds an extra layer of protection even if a password becomes compromised. Regularly auditing third-party app permissions can also help limit future exposure.
Monitor Your Credit Report and Watch for Phishing
Even though this incident centers on business and platform data, affected employees or clients whose information appears in the exposed client lists should monitor their credit reports. You can request free credit reports from the three major bureaus to check for unfamiliar accounts or inquiries. Doing this regularly helps catch identity theft early.
In addition, stay alert for phishing emails referencing TapClicks, your employer, or advertising platforms you use. Attackers often use stolen client lists and business details to craft convincing, targeted messages. Never click links or provide credentials in response to unexpected emails, and verify requests through official channels first.
Consider a Fraud Alert if Personal Data Is Involved
If you later learn that your personal information, such as your name paired with account details, was part of the exposed customer database, consider placing a fraud alert with a credit bureau. This makes it harder for identity thieves to open new accounts in your name. Fraud alerts are free and typically last one year.
Alternatively, a credit freeze offers stronger protection by restricting access to your credit file entirely. Because this incident’s full scope remains unclear, taking a precautionary step like this can provide peace of mind. If you are unsure about your rights or potential compensation, consulting a data breach attorney for a free case evaluation may help clarify your options.
Get a Free Case Review
Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.
Related Data Breaches
- Pentagon Defense Manpower Data Center (DMDC) Data Breach Exposes Social Security Numbers and Military Personnel Records
- Crossett Home Data Breach Exposes Company and Employee Data Claimed by Termite Group
- Gallagher Transport International Inc. Data Breach Exposes Social Security Numbers and Government ID Numbers
