HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Phishing Campaign Targets TikTok for Business Accounts, Bypassing 2FA via Google SSO

Threat actors are using Cloudflare‑protected phishing pages to steal TikTok for Business credentials, capturing session cookies and bypassing two‑factor authentication through Google single sign‑on, exposing advertisers to ad fraud and credential reuse.

LiveThreat™ Intelligence · 📅 March 27, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
bleepingcomputer.com

Phishing Campaign Targets TikTok for Business Accounts, Bypassing 2FA via Google SSO

What Happened — Threat actors launched a phishing operation that lures TikTok for Business users to Cloudflare‑protected pages masquerading as TikTok and Google Careers “Schedule a Call” forms. The pages capture credentials and session cookies, allowing account takeover even when two‑factor authentication is enabled via Google SSO.

Why It Matters for TPRM

  • Compromised business accounts can be weaponized for ad fraud, malvertising, and credential harvesting across multiple platforms.
  • The technique evades automated bot detection, increasing the likelihood of successful credential capture.
  • Shared Google SSO means a single breach can cascade to other SaaS services used by the same organization.

Who Is Affected — Social media advertising platforms, digital marketing agencies, and any enterprise using TikTok for Business or Google SSO for authentication.

Recommended Actions

  • Review all TikTok for Business vendor contracts and confirm phishing‑resilience controls.
  • Enforce passkey or hardware‑based MFA and monitor for anomalous login activity.
  • Educate users on verifying URLs and avoiding unsolicited “schedule a call” links.

Technical Notes — Attack vector: phishing with Cloudflare Turnstile bot checks, malicious pages hosted on Google Storage buckets, credential harvesting via reverse‑proxy login pages. No CVE referenced. Data types: login credentials, session tokens. Source: https://www.bleepingcomputer.com/news/security/tiktok-for-business-accounts-targeted-in-new-phishing-campaign/

📰 Original Source
https://www.bleepingcomputer.com/news/security/tiktok-for-business-accounts-targeted-in-new-phishing-campaign/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your SOC 2 posture defensible.

See where you'd stand with Verisq AI Trust Operations →