Tokee, a messaging app developed by Deucetek, exposed data tied to about 1.2 million users after an unsecured MongoDB database was left publicly accessible online. Researchers found personal account metadata including names, phone numbers, avatars, device tokens, user IDs, timestamps, last-seen activity, and account status, creating significant privacy, security, and potential regulatory risks for affected users.
While chat logs were reportedly encrypted and not exposed in plaintext, the leaked metadata still increased the risk of phishing, impersonation, and other targeted abuse. Deucetek secured the database after the exposure was reported, and there was no evidence cited of malicious access or the data being posted on dark web forums, but users were urged to remain alert for scams posing as Tokee or Deucetek.

See attribution, scope, and your downstream exposure.
2 events from the most recent confirmed update back to the earliest known activity.
After the exposure was identified by Cybernews researchers, Deucetek reportedly secured the MongoDB database. Reports said there was no evidence of malicious access or that the data had been posted on the dark web, though users were warned about phishing risks.
An unsecured MongoDB database tied to Deucetek's Tokee messaging app was publicly accessible, exposing data on about 1.2 million users. The exposed records included names, phone numbers, avatars, device tokens, user IDs, timestamps, last-seen activity, and account status, while chat logs were reportedly encrypted.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcetechradar.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.