← Back
PhishingMalwarebytes Labs·2 hours ago

TikTok phishing: How to spot fake login and verification pages

Scammers are leveraging fake TikTok login pages and fraudulent verification alerts to deceive users into revealing their account credentials. Security professionals should be aware of this phishing campaign targeting TikTok users, as attackers use convincing replicas of official login and verification interfaces to compromise accounts.

Read full article at Malwarebytes Labs

Related Articles

PhishingHelp Net Security·38 minutes ago

ShinyHunters taunts ReliaQuest after its own employee falls for social engineering attack

ReliaQuest confirmed that one of its employees fell victim to a social engineering attack that provided attackers with a password and temporary access to the company's identity system. Extortion group ShinyHunters subsequently posted screenshots on its leak site, claiming responsibility and taunting the cybersecurity firm over the breach. The incident followed an earlier exchange between ShinyHunters and ReliaQuest's threat research team on social media.

PhishingMalwarebytes Labs·19 hours ago

Fake Microsoft security scans trick victims into uninstalling their antivirus

Attackers are deploying counterfeit Microsoft security scanners that fabricate threats and convince users to disable their legitimate antivirus software, leaving systems vulnerable to further compromise. Once victims uninstall their protections, the scammers redirect them into refund fraud schemes, exploiting the deception to extract payment.

PhishingInfosecurity Magazine·21 hours ago

Doubloon Dredger Abuses Notion to Harvest Authentication Tokens

Threat actor Doubloon Dredger is leveraging Notion, a legitimate productivity platform, alongside malicious PDFs to conduct authentication token harvesting attacks targeting Microsoft credentials. This technique exploits user trust in commonly-used services to compromise account access and enable lateral movement within targeted organizations.

PhishingHelp Net Security·1 day ago

Fake bank websites play dead to evade security scanners

Fortra's threat intelligence team has identified a phishing technique called Chameleon SEO Poisoning that leverages manipulated search results and cloaked fake banking websites to harvest credentials while remaining invisible to security scanners. The attackers optimize these pages for high-intent keywords mimicking legitimate banking portals and reported a 40% increase in cases during Q2 2026. The websites employ evasion tactics to detect and avoid security tools, making this approach particularly difficult for traditional detection methods.