{"id":228238,"date":"2026-03-27T11:23:00","date_gmt":"2026-03-27T15:23:00","guid":{"rendered":"https:\/\/news-you-need.com\/index.php\/2026\/03\/27\/new-aitm-phishing-wave-hijacks-tiktok-business-accounts\/"},"modified":"2026-03-27T13:55:14","modified_gmt":"2026-03-27T17:55:14","slug":"new-aitm-phishing-wave-hijacks-tiktok-business-accounts","status":"publish","type":"post","link":"https:\/\/news-you-need.com\/index.php\/2026\/03\/27\/new-aitm-phishing-wave-hijacks-tiktok-business-accounts\/","title":{"rendered":"New AITM phishing wave hijacks TikTok Business accounts"},"content":{"rendered":"<p><a href=\"https:\/\/securityaffairs.com\/190058\/security\/new-aitm-phishing-wave-hijacks-tiktok-business-accounts.html?amp\">New AITM phishing wave hijacks TikTok Business accounts<\/a><\/p>\n<p><a href=\"https:\/\/securityaffairs.com\/190058\/security\/new-aitm-phishing-wave-hijacks-tiktok-business-accounts.html?amp\">https:\/\/securityaffairs.com\/190058\/security\/new-aitm-phishing-wave-hijacks-tiktok-business-accounts.html?amp<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-03-27 11:23:00<\/a><\/p>\n<p>Source Domain: <a href=\"securityaffairs.com\">securityaffairs.com<\/a><\/p>\n<p><h2>New AITM phishing wave hijacks TikTok Business accounts<\/h2>\n<\/p>\n<p>\t\t\t\t\t\t\t<span> Pierluigi Paganini<\/span><br \/>\n\t\t\t\t\t\t\t<span><img decoding=\"async\" src=\"https:\/\/securityaffairs.com\/wp-content\/themes\/security_affairs\/images\/clock-icon.svg\" alt=\"\"\/> March 27, 2026<\/span><\/p>\n<p>\t\t\t\t\t\t<img decoding=\"async\" class=\"img-fluid mb-4\" src=\"https:\/\/i0.wp.com\/securityaffairs.com\/wp-content\/uploads\/2026\/03\/image-86.png?fit=1999%2C1127&#038;ssl=1\" alt=\"\"\/><\/p>\n<h2 class=\"wp-block-heading\">A new AITM phishing campaign targets TikTok Business accounts to hijack them for malvertising, continuing tactics seen in earlier Google-themed scams.<\/h2>\n<p>Push Security researchers uncovered a new wave of AITM phishing pages targeting TikTok for Business accounts, aiming to hijack them for malvertising. The campaign includes TikTok and Google-themed fake pages, showing links to previous operations. Once compromised, accounts are used to run malicious ads, steal credentials, spread malware, and conduct ad fraud, diverting company advertising budgets for profit.<\/p>\n<p>Attackers used newly registered domains created within seconds and hosted behind Cloudflare. The pages follow a common naming pattern and redirect victims from legitimate services before loading fake TikTok for Business or Google \u201cSchedule a call\u201d pages. <\/p>\n<p><img data-recalc-dims=\"1\" fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"621\" src=\"https:\/\/i0.wp.com\/securityaffairs.com\/wp-content\/uploads\/2026\/03\/image-85.png?resize=1024%2C621&#038;ssl=1\" alt=\"\" class=\"wp-image-190060\" srcset=\"https:\/\/i0.wp.com\/securityaffairs.com\/wp-content\/uploads\/2026\/03\/image-85.png?resize=1024%2C621&#038;ssl=1 1024w, https:\/\/i0.wp.com\/securityaffairs.com\/wp-content\/uploads\/2026\/03\/image-85.png?resize=300%2C182&#038;ssl=1 300w, https:\/\/i0.wp.com\/securityaffairs.com\/wp-content\/uploads\/2026\/03\/image-85.png?resize=768%2C466&#038;ssl=1 768w, https:\/\/i0.wp.com\/securityaffairs.com\/wp-content\/uploads\/2026\/03\/image-85.png?resize=1536%2C932&#038;ssl=1 1536w, https:\/\/i0.wp.com\/securityaffairs.com\/wp-content\/uploads\/2026\/03\/image-85.png?w=1999&#038;ssl=1 1999w\" sizes=\"(max-width: 1000px) 100vw, 1000px\"\/><\/p>\n<p>Users are asked to fill in basic details, then shown a malicious login page powered by an AITM phishing kit. The campaign uses bot protection to evade detection and likely spreads via targeted emails, similar to past operations. <\/p>\n<p>\u201cWhen the link is first clicked, the page is silently redirected from a legitimate Google Storage site before loading the page.\u201d reads the report published by Push Security. \u201cA Cloudflare Turnstile check is used to prevent security bots from analyzing the page, before loading either a TikTok or Google themed page. Progressing through the forms ultimately serves up an AITM phishing page.\u201d<\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" width=\"1024\" height=\"577\" src=\"https:\/\/i0.wp.com\/securityaffairs.com\/wp-content\/uploads\/2026\/03\/image-86.png?resize=1024%2C577&#038;ssl=1\" alt=\"\" class=\"wp-image-190062\" srcset=\"https:\/\/i0.wp.com\/securityaffairs.com\/wp-content\/uploads\/2026\/03\/image-86.png?resize=1024%2C577&#038;ssl=1 1024w, https:\/\/i0.wp.com\/securityaffairs.com\/wp-content\/uploads\/2026\/03\/image-86.png?resize=300%2C169&#038;ssl=1 300w, https:\/\/i0.wp.com\/securityaffairs.com\/wp-content\/uploads\/2026\/03\/image-86.png?resize=768%2C433&#038;ssl=1 768w, https:\/\/i0.wp.com\/securityaffairs.com\/wp-content\/uploads\/2026\/03\/image-86.png?resize=1536%2C866&#038;ssl=1 1536w, https:\/\/i0.wp.com\/securityaffairs.com\/wp-content\/uploads\/2026\/03\/image-86.png?w=1999&#038;ssl=1 1999w\" sizes=\"(max-width: 1000px) 100vw, 1000px\"\/><\/p>\n<p>By combining trusted branding, redirects, and layered deception, attackers increase success rates and harvest credentials for further abuse, including account takeover and fraud.<\/p>\n<p>While phishing campaigns usually mimic platforms like Google or Microsoft, targeting TikTok is becoming more common. <\/p>\n<p>The platform has long been used to spread malicious links and&#8230;<\/p>\n<p><a href=\"https:\/\/securityaffairs.com\/190058\/security\/new-aitm-phishing-wave-hijacks-tiktok-business-accounts.html?amp\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New AITM phishing wave hijacks TikTok Business accounts https:\/\/securityaffairs.com\/190058\/security\/new-aitm-phishing-wave-hijacks-tiktok-business-accounts.html?amp Publish Date: 2026-03-27 11:23:00 Source Domain:&#8230;<\/p>\n","protected":false},"author":1,"featured_media":228239,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/securityaffairs.com\/wp-content\/uploads\/2026\/03\/image-86.png","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[32,25],"class_list":["post-228238","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-malware","tag-phishing"],"_links":{"self":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/228238"}],"collection":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=228238"}],"version-history":[{"count":1,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/228238\/revisions"}],"predecessor-version":[{"id":228240,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/228238\/revisions\/228240"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/228239"}],"wp:attachment":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=228238"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=228238"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=228238"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}