? Back to Blog

How AitM Attacks Are Evolving — And How to Protect Your Business Data

FileShot Team · 2026-03-28

In early 2026, cybersecurity researchers uncovered a troubling new campaign targeting TikTok for Business accounts using Adversary-in-the-Middle (AitM) phishing attacks. These attacks, detailed in a report by Push Security, exploit Cloudflare’s Turnstile CAPTCHA system to bypass traditional anti-bot protections—allowing attackers to intercept credentials and session cookies in real time. While TikTok was the immediate victim, the implications stretch far beyond one platform. This campaign is a wake-up call for any business handling sensitive data, customer information, or digital assets.

What Is AitM Phishing?

Unlike standard phishing, where attackers trick users into entering credentials on fake login pages, AitM phishing introduces a live proxy between the user and the legitimate service. When a victim visits a phishing page, they’re not just entering data into a static form—they’re interacting with the real website through an invisible relay controlled by the attacker.

Here’s how it typically works:

  • The victim clicks on a malicious link, often disguised as a login prompt for a service like TikTok, Google, or Microsoft.
  • They’re taken to a phishing page that mirrors the real login interface—but every keystroke and session token is captured.
  • The phishing server forwards the data to the actual service, logs in on the victim’s behalf, and relays the session back to the victim.
  • The attacker now has full access to the session, including two-factor authentication (2FA) tokens, cookies, and account permissions—often without triggering alerts.

Because the victim successfully logs in and sees the real website, they rarely suspect foul play. Meanwhile, the attacker gains persistent access, enabling long-term espionage, data theft, or account takeover.

Why Business Accounts Are Prime Targets

Business accounts on platforms like TikTok, Facebook, or LinkedIn offer attackers far more than personal profiles. These accounts often have:

  • Access to ad budgets and payment methods
  • Verified status and established credibility
  • Large follower bases ripe for malvertising
  • Integration with third-party analytics and CRM tools

Once compromised, these accounts can be used to launch coordinated scams, distribute malware-laced videos, or redirect traffic to phishing sites. In some cases, attackers sell access to hijacked business accounts on underground forums, creating a thriving black market for digital influence.

The recent TikTok campaign is particularly alarming because it bypassed Cloudflare Turnstile—a modern CAPTCHA alternative designed to stop bots. Attackers used automated headless browsers and IP rotation to appear as legitimate traffic, slipping past detection systems that rely on behavioral analysis.

The Limits of Traditional Security Measures

Many organizations mistakenly believe that 2FA makes them immune to phishing. But AitM attacks prove otherwise. Since the attacker logs in with the user—forwarding 2FA prompts in real time—even SMS, authenticator apps, or hardware tokens can be compromised.

Additionally, standard antivirus tools and firewalls offer little protection. The phishing page may not contain malware; it’s simply a proxy. And because the user reaches the real service, browser security warnings rarely trigger.

Even vigilant employees can fall victim. A convincing email from “TikTok Support” asking to “reverify your business profile” is enough to initiate the chain of compromise—especially if the link appears to use HTTPS and displays a legitimate-looking CAPTCHA.

The Bigger Picture: Data in Transit Is at Risk

The rise of AitM attacks underscores a broader truth: any data transmitted over the internet is vulnerable if not properly secured. Whether it’s login credentials, financial records, or internal communications, intercepted data can be weaponized.

This is where secure, end-to-end encrypted platforms become essential. Unlike traditional cloud services, where files are stored on servers that the provider can access, end-to-end encryption ensures that only the sender and recipient hold the decryption keys.

For example, FileShot uses end-to-end encryption so your files can't be accessed even by our servers. When you upload a file, it’s encrypted locally on your device before it ever reaches the network. This means that even if an attacker intercepts the transmission—or compromises the service provider—they can’t read the contents.

In the context of AitM attacks, this layer of protection is invaluable. If you’re sharing sensitive documents, marketing plans, or account credentials (even temporarily), using an encrypted channel minimizes the fallout if one party’s session is compromised.

How to Protect Your Business

No single tool can eliminate the risk of AitM phishing, but a layered defense strategy can dramatically reduce your exposure. Consider the following:

  • Implement phishing-resistant MFA: Use FIDO2 security keys or passkeys instead of SMS or TOTP apps. These are far more resistant to real-time interception.
  • Train employees regularly: Simulate phishing attempts and educate teams on the signs of AitM attacks, such as unexpected CAPTCHA challenges or unusual login prompts.
  • Use zero-trust access models: Verify every request, even from inside the network. Tools like device posture checks and conditional access policies can block suspicious logins.
  • Limit third-party access: Revoke unused integrations and monitor API permissions on social media and cloud platforms.
  • Encrypt sensitive data at rest and in transit: Whether you're sharing a business proposal or a financial report, always use encrypted channels. FileShot ensures that your shared files remain private—no matter where they travel.

Building a Culture of Secure Sharing

Security isn’t just about technology—it’s about behavior. The moment an employee shares a sensitive file over an unencrypted email or chat app, they create a potential entry point for attackers.

Organizations must shift toward a culture where secure sharing is the default. That means making encrypted tools easy to use, widely available, and integrated into daily workflows. When sharing a file feels as simple as clicking a button—and you know it’s protected from prying eyes—security becomes seamless, not burdensome.

Platforms like FileShot are designed with this principle in mind. No sign-up is required to receive files, and every transfer is encrypted by default. There’s no temptation to “just email it quickly” because the secure option is faster and more reliable.

As AitM attacks grow more sophisticated, businesses can’t afford to rely on outdated defenses. The TikTok campaign is just one example of how attackers are evolving. The real solution lies in proactive protection: encrypting data, hardening authentication, and fostering a security-aware culture. Because in today’s digital landscape, every file shared, every login attempted, and every message sent could be the next target.

Join the affiliate program and earn 50%. No approvals, no waitlists.