TikTok Phishing Threatens to Delete Influencers’ Accounts

TikTok Phishing Threatens to Delete Influencers’ Accounts

Researchers have observed a new phishing campaign primarily targeting high-profile TikTok accounts belonging to influencers, brand consultants, production studios, and influencers’ managers.

Abnormal Security researchers who spotted the attacks, observed two activity peaks while observing the distribution of emails in this particular campaign, on October 2, 2021, and on November 1, 2021, so a new round will likely start in a couple of weeks.

You’ve got mail!

In some cases seen by Abnormal Security, the actors impersonate TikTok employees, threatening the recipient with imminent account deletion due to an alleged violation of the platform’s terms.

Also Read: 6 Types Of Document Shredder Machine Singapore Services

Phishing message alerting the recipient of a violation
Source: Abnormal Security

Another theme used in the emails is offering a ‘Verified’ badge that adds credibility and authenticity to the account.

TikTok ‘Verified’ badges give weight to the content posted by verified accounts and signal the platform’s algorithms to ramp up the exposure rates of posts from these accounts.

Using this bait for phishing is very effective as many people would be thrilled to receive an email offering them the chance to get a verification badge.

Also Read: 10 Principles On How To Build A Good Governance Model

Email offering a verification badge to the user
Source: Abnormal Security

In both cases, the attackers provide their targets with a way to verify their accounts by clicking an embedded link.

However, they are instead redirected to a WhatsApp chat room where they’re welcomed by a scammer pretending to be a TikTok employee awaits.

The scammer asks for their email address, phone number, and one-time code required to bypass multi-factor authentication and reset the account’s password.

Scammer discussing with the victim on WhatsApp
Source: Abnormal Security

Account takeover or extortion?

It is unclear what the phishing actors aim for in this campaign, but it could be either an attempt to take over the targets’ accounts or to extort the account owners and force them to pay a ransom for giving them back control.

TikTok’s terms of service make it clear that if an account, especially one with many followers, violates its services, it will be permanently suspended or terminated.

This means that the actors can easily threaten to post something inappropriate, resulting in the deletion of a profile that its owner may have spent a lot of time and money to bring to its current form.

If you own and/or manage valuable social media accounts, make sure to backup all your content and data somewhere safe.

Also, you should always secure your account with two-factor authentication (2FA) or 2-step verification, as TikTok calls it, ideally with a hardware security key.

If you can only use the less secure SMS-based 2FA option, pick up a private number you’ve shared with nobody and use it only for this purpose.

Privacy Ninja

Recent Posts

Role of Enhanced Access Controls in Safeguarding Personal Data in Telecommunications

Role of Enhanced Access Controls in Safeguarding Personal Data in Telecommunications that every Organisation in…

1 week ago

Role of Effective Incident Response Procedures in Strengthening Data Security

Effective Incident Response Procedures in Strengthening Data Security that every Organisation in Singapore should know…

2 weeks ago

Strengthening Your Cyber Defenses: The Crucial Role of Regular Vulnerability Scanning

Crucial Role of Regular Vulnerability Scanning that every Organisation in Singapore should know. Strengthening Your…

2 weeks ago

Enhancing Data Security with Multi-Factor Authentication

Enhancing Data Security with Multi-Factor Authentication that every Organisation in Singapore should know. Enhancing Data…

3 weeks ago

A Strong Password Policy: Your Organization’s First Line of Defense Against Data Breaches

Strong Password Policy as a first line of defense against data breaches for Organisations in…

3 weeks ago

Enhancing Website Security: The Importance of Efficient Access Controls

Importance of Efficient Access Controls that every Organisation in Singapore should take note of. Enhancing…

4 weeks ago