惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
云风的 BLOG
云风的 BLOG
IT之家
IT之家
C
Check Point Blog
T
The Blog of Author Tim Ferriss
S
SegmentFault 最新的问题
人人都是产品经理
人人都是产品经理
H
Hackread – Cybersecurity News, Data Breaches, AI and More
美团技术团队
M
MIT News - Artificial intelligence
Jina AI
Jina AI
Blog — PlanetScale
Blog — PlanetScale
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Microsoft Security Blog
Microsoft Security Blog
G
Google Developers Blog
F
Fortinet All Blogs
V
Visual Studio Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
T
Tailwind CSS Blog
Hugging Face - Blog
Hugging Face - Blog
MyScale Blog
MyScale Blog
爱范儿
爱范儿
The Cloudflare Blog
博客园 - 三生石上(FineUI控件)

Consumer Insights

The ransomware negotiator who was working for the other side After years on the run, alleged Ryuk ransomware operator pleads guilty INTERPOL crackdown shows scammers shifting to social media Meta lets strangers remix your public Instagram photos with AI—here’s how to opt out Invited to a "job interview" with Netflix or OpenAI? Beware! Your Google password could be at risk Two arrested over credit card phishing - as the Netherlands is named Europe's worst for payment fraud India pauses WhatsApp username feature over security concerns Alleged teen ransomware hustler faces US charges after arrest in Finland WhatsApp usernames explained: how to reserve yours and stay safe Scammers race to cash in on Venezuelan earthquake disaster USB drives carrying China-linked malware infected Japanese military networks for nearly a year WhatsApp tests new safety prompt before you chat with strangers Social media is worth celebrating. It's also worth protecting. Polish police dismantle SIM-swap gang accused of crypto theft Operation Endgame deals fresh blow to StealC and Amadey malware networks Hacker hijacks Brazil's national alert system, sending "misanthropy" to millions of phones Cybercrime now rivals traditional crime across parts of Asia Apple's Hide My Email tweak leaves privacy fans fuming Americans lost $3.5 billion to imposter scams last year — and the scams are getting harder to spot Scammers have killed the physical Steam Gift cards Crypto investment scam sends couriers to collect victims' cash, FBI warns Maine forced to take down data breach portal after fake notices filed with authorities Privacy own-goal: World Cup blunder leaks Lionel Messi's passport details Why schools remain one of cybercriminals' favourite targets WhatsApp detects new spyware activity from Israel’s NSO Group despite court order Got a LinkedIn message from a recruiter? It might be Chinese intelligence, warn FBI and MI5 Europol cracks down on illegal streaming globally Hackers didn't hack Instagram; they just asked Meta AI FBI Warns Fans About FIFA Scams Ahead of 2026 World Cup Virtual knife, real lawsuit: Counter-Strike skin dispute ends in court
TikTok Business phishing campaign targets advertisers
Vlad CONSTANTINESCU · 2026-03-27 · via Consumer Insights

Attackers are using evasive phishing infrastructure to hijack TikTok for Business accounts and, in some cases, linked Google logins.

A high-value target for cybercriminals

Security researchers are tracking a phishing campaign aimed at the TikTok for Business niche, a niche target valued because compromised advertiser accounts can be used for malvertising, ad fraud, and the spread of malicious content at scale. Push Security says the activity resembles a campaign it documented in late 2025 that went after Google ad-related accounts, suggesting threat actors are refining a proven playbook rather than inventing a new one from scratch.

Much like aged Instagram accounts, business-facing TikTok accounts carry more reach and credibility than ordinary profiles. A stolen account can become an instant launchpad for scam ads, fraudulent promotions or malicious redirects.

Evasion built into the phishing chain

According to campaign reporting, the attack chain uses a legitimate Google Storage URL as part of the redirect flow before presenting a Cloudflare Turnstile check designed to frustrate automated analysis. The phishing domains were reportedly registered on March 24, 2026 and the pages impersonate TikTok for Business and Google Careers scheduling flows to avoid suspicion.

In recent phishing scenarios, attackers increasingly hide behind trusted cloud infrastructure and anti-bot mechanisms to keep scanners, sandboxes and researchers from detecting the payload immediately.

Why 2FA may not be enough

The greatest danger is the use of an adversary-in-the-middle, or AiTM, phishing setup. Because the fake page acts as a live proxy between victim and legitimate service, it can capture credentials and session cookies in real time, allowing account takeover even when traditional two-factor authentication (2FA) is enabled.

Security researchers also warned that users who sign in to TikTok with Google SSO (single sign-on) could effectively hand over access to both ecosystems in one hit. The safest advice remains to distrust unsolicited invites, inspect domains carefully and move high-value accounts to phishing-resistant authentication where possible.

Added protection is crucial

Users worried about fake TikTok for Business invites can add a simple verification step before clicking or logging in. Bitdefender Scamio can help assess suspicious messages, links, screenshots or email text, making it easier to spot a phishing attempt before credentials are exposed.

For broader protection, Bitdefender Ultimate Security adds an extra layer of security by helping block malicious links and detect suspicious activity on the device. In phishing campaigns designed to steal access to business accounts, that extra protection can make the difference between safety and complete account takeovers.