Phishing Attack Targets TikTok for Business Accounts
A new phishing campaign is targeting TikTok for Business accounts, aiming to exploit their credibility for nefarious activities like ad fraud and malware distribution. The attack, identified by Push Security, involves malicious pages disguised as legitimate TikTok and Google Careers sites, prompting users to enter business email information.
Victims who fall for the ruse are directed to fake login pages that capture their credentials, even bypassing two-factor authentication protections. This poses a significant risk, as many business accounts link to Google single sign-on, potentially compromising multiple accounts at once.
Affected users are primarily businesses leveraging TikTok for advertising. To protect against such attacks, users should be cautious of suspicious links, verify domains before entering credentials, and consider using passkeys for added security.
Risk Level: High
Stay vigilant to safeguard your online presence.
Source: View Original Report
