How to Avoid Account Takeover (ATO) Scams

Account Management

What is an Account Takeover (ATO) Scam?

An Account Takeover (ATO) scam occurs when a bad actor fraudulently accesses and takes over your TikTok Shop account. Account Takeover scam can result in:
  • Loss of access to your TikTok Shop account. This means you will not be able to log in to manage your TikTok Shop, orders, and account balance.
  • Possible monetary loss should a bad actor gain control of your TikTok Shop Account Balance or bank account details. This includes transferring your TikTok Shop account balance to other bank accounts.

How Do Bad Actors Take Over Accounts?

The main tactic bad actors use in Account Takeover scams is to impersonate a trusted individual, such as a TikTok employee, account manager, shipping company employee, or third-party service provider, to contact TikTok Shop sellers. Alternatively, fraudsters may also pose as interested buyers who wish to make large orders from your shop.
These bad actors can reach out to you though online messaging platforms such as WhatsApp, Telegram, Messenger or our TikTok Shop Buyer Direct Message feature in order to retrieve sensitive information such as your log-in details or credentials.
Some common tactics bad actors use to retrieve your information are:
  1. Asking for your account details so that they can help you with account services, problems, or violations
  2. Asking for your account details in exchange for prizes or entry into lucky draws
  3. Asking for your banking or credit/debit card details to settle delivery/logistics problems with parcel delivery
  4. Asking you to fill up an online form with your account details for account verification purposes
  5. Asking you to install/download apps or APK files that are not found in official app stores
  6. Asking you to click on links or download attachments sent via chat messages
Once gathering the necessary details, bad actors can access and takeover your TikTok Shop account

Spotting an Account Takeover (ATO) Scam

Red Flags

Sellers are asked to stay vigilant and to look out for the following common red flags:
  • Receiving messages from unknown contacts who get in touch off-platform outside of our TikTok App
  • Receiving messages that are purportedly from TikTok, logistics/shipping companies, service providers, or buyers interested in bulk ordering
  • Being asked to communicate off the TikTok Shop Platform
  • Receiving messages requesting you to download files or click on suspicious links
  • Receiving warnings from your phone when you try to download files or clicking on a link
  • Receiving email notifications from TikTok Shop for account balance withdrawals or the new addition of bank accounts to your shop/account that you did not initiate
  • Messages asking for your bank account or credit/debit card details
  • Messages asking for your TikTok Shop account log-in details, OTP, or credentials
Important Note! TikTok Shop and any representative from TikTok (such as a TikTok account manager) will never request your log-in details or OTP codes.

Examples of an Account Takeover (ATO) Scam

Possible scenarios of Account Takeover (ATO) scams are included below.
Scam Type (non-exhaustive)Example
Logistics/ Shipping/ Delivery Partner impersonation
  • The bad actor poses as a delivery/logistics partner and tricks the victim into downloading a malicious APK file or attachment by sending a message with an attachment named 'Package'.
  • The bad actor pretends to be from a shipping or logistics company and tricks victims into giving their bank account details to pay for fake delivery fees or shipping issues. Once they have the necessary details, the scammer hacks into their account and steals money.
Buyer or Customer Impersonation
  • A bad actor pretends to be a buyer and reaches out to the seller via the TikTok Shop Buyer Messages feature and asks them to communicate outside or off our platform. The bad actor sends a malicious phishing file/form or link via WhatsApp, Telegram, or other messaging app(s) requesting the seller's account details.
TikTok Shop Account Manager Impersonation
  • The bad actor pretends to be a TikTok Shop account manager and contacts a seller via the TikTok Shop Buyer Messages feature. They falsely offer to assist with account/shop violations and request login credentials and OTP. The bad actor then takes over the seller's TikTok Shop account.

Ways to Protect Your Account on TikTok Shop

To prevent an account takeover from happening, users are encouraged to take the following steps to keep their account secure:
image
Learn more about account protection by visiting our TikTok Shop Academy (UK, Singapore, Philippines, Indonesia, Thailand, Malaysia, Vietnam). Cross-border sellers can learn more about account protection here.

What To Do If Your Account is Compromised

If you are unable to sign into your TikTok Shop account or can no longer access the registered email or mobile phone number, please get in touch with our Seller Support for assistance.
As a precaution, your account will be frozen to prevent further compromised access. You will then be asked to upload documents to verify account ownership. Upon verification of your documents, our team will reach out to notify you about the next steps to regain access to your account.
For more information, please refer to our TikTok Shop Unauthorised Account Control Guidelines (UK, Singapore, Philippines, Indonesia, Thailand, Malaysia, Vietnam, Cross-border).