TikTok for Business accounts targeted by phishing campaign: Here’s how to stay safe


  • Push Security uncovers phishing campaign targeting TikTok Business accounts
  • Attackers use Google Storage Links and AITM kits to steal credentials, cookies, and MFA codes.
  • Compromised accounts exploited for fraudulent advertising campaigns and information distribution via fake TikTok content

If your business runs a TikTok account, be careful: hackers are going after your login details with a sophisticated phishing attack.

A new report from Push Security describes a campaign that most likely begins with a phishing email. Although unconfirmed, Push found a malicious link that routes victims through a legitimate Google Storage URL to appear trustworthy, before redirecting them to one of nearly a dozen malicious landing pages, all registered with the same questionable registrar (Nicenic International Group, which was reportedly commonly used for mass phishing domain registration).

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top