Attackers use trusted domains as waypoints in phishing campaigns
Attackers are increasingly abusing platforms such as TikTok to deliver phishing. Rather than sending users straight to a malicious site, they embed redirect links inside legitimate domains so the initial URL looks safe. The technique exploits trust in familiar names: the victim sees a domain they recognise, clicks, and is silently redirected to a credential-harvesting page mimicking a corporate login portal. In many cases the user is then forwarded to the real service, so suspicion never arises after the credentials have already been taken.
What this means for your organisation
Advice about checking the domain before clicking loses its value when the visible domain genuinely is legitimate. Many technical filters fail for the same reason: they assess the first link, not where it ends up. In practice this means stolen credentials should be assumed, and the defence has to rest on what credentials alone are worth.
Berigo recommends
- Introduce phishing-resistant authentication, such as passkeys or hardware keys, on your most important services.
- Monitor logins from unfamiliar devices and unusual locations, and let that trigger action.
- Provide a fast, simple channel for reporting suspicious links, with no fear of being wrong.
- Shift training away from domain recognition and towards what to do once you have clicked.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch