logo

TikTok for Business Under Siege: New Phishing Campaign Exploits “Login with Google”

ID: 269c9d69-8cd5-5dd6-be02-ca18d818391f

STIX ID: report--269c9d69-8cd5-5dd6-be02-ca18d818391f

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-04-03

Date Updated: 2026-04-23

Author: Ddos

...
...

Researchers at Push Security uncovered an active AITM phishing campaign targeting TikTok for Business accounts that uses convincing cloned pages, Cloudflare Turnstile checks, and a reverse-proxy phishing kit to capture credentials and active session tokens — including via a modified “Log in with Google” flow — enabling takeover of ad accounts for malware distribution, crypto scams, and data theft. The report notes a cluster of related domains registered in a short window (March 24, 2026) and highlights the risk of SSO compromise spreading across corporate applications.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.