TikTok influencers are being targeted by this dangerous new phishing threat

TikTok
(Image credit: Future)

Cybersecurity researchers have chanced upon a new phishing campaign that targets high-profile content creators on TikTok in order to wrest control of their account for nefarious purposes.

Discovered by Abnormal Security, the scam involves two ploys. In one the scammers impersonate TikTok employees, and threaten the recipient with imminent account deletion due to an alleged violation of the platform's terms.

In the other scam, the attackers bait the TikTok users with the offer of a Verified badge, which brings with it additional credibility and increased exposure.

TechRadar needs you!

We're looking at how our readers use VPNs with streaming sites like Netflix so we can improve our content and offer better advice. This survey won't take more than 60 seconds of your time, and we'd hugely appreciate if you'd share your experiences with us.

>> Click here to start the survey in a new window <<

Takeover or extortion?

According to Abnormal, irrespective of the bait, the scammers invite recipients to click a link to proceed further. 

The link redirects them to a WhatsApp chat room, where the scammer, impersonating as a TikTok employee, asks the content creators for details to log into their account, including the one-time password (OTP) to bypass the platform’s multi-factor authentication (MFA).

In their breakdown of the scam, Abnormal notes that they’ve spotted two activity peaks while monitoring the distribution of emails in this campaign, one on October 2, 2021, and the other on November 1, 2021.

Since the researchers could get the scammer to take over their account, they are unclear as to the end goal of the scammers. Based on similar phishing campaigns on other social networking platforms, the researchers believe that the attackers could perhaps take over the account to force the owners to pay a ransom. 

“Social media platforms explicitly state in their terms of service that they bear no responsibility for any data loss and advise users to store all account material externally….And so even if the ransom payment is paid, there may be no regaining access to your social media accounts—costing those who depend on it for their income to lose their entire livelihood in one swoop,” warns Abnormals’ Threat Intelligence Analyst, Rachelle Chouinard.

Make sure you protect yourself online with these best identity theft protection services and use these best security keys to add another layer to safeguard your accounts

Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
Smartphone with new logo X twitter app background. Application twitter old blue bird change X black and white new.
Phishing campaign targets prominent X users, accounts at risk
A TV remote pointing at YouTube logo
YouTube warns of phishing video using its CEO as bait
Someone checking their credit card details online.
Hackers use CAPTCHA scam in PDF files on Webflow CDN to get past security systems
QR Code
Hackers are targeting Signal with new QR code-linked cyberattack
Fraude en ligne phishing
Google Search ads are being hacked to steal account info
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
These fake GitHub "security alerts" could actually let hackers hijack your account
Latest in Security
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Latest in News
Samsung HW-Q990D soundbar with Halloween theme over the top
Samsung promises to repair soundbars bricked by its disastrous software update for free – but it'll probably involve shipping
Google Gemini AI
Gmail is adding a new Gemini AI tool to help smarten up your work emails
DJI Mavic 3 Pro
More DJI Mavic 4 Pro leaks seemingly reveal launch date, price and key features of the triple camera drone – here's what to expect
Android 16 logo on a phone
Here's how Android 16 will upgrade the screen unlocking process on your Pixel
Man sitting on sofa, drinking coffee, looking at phone in surprise
Thousands of coffee lovers warned to stop using their espresso machines immediately after reports of burns and lacerations
Visual Intelligence identifying a dog
AirPods with cameras for Visual Intelligence could be one of the best personal safety features Apple has ever planned – here's why