X account users warned of fake login notification phishing scam

X account users warned of fake login notification phishing scam

8 reported

A new phishing scam is targeting X (formerly Twitter) account holders with fake emails that mimic legitimate login notifications, according to a report from The Guardian. The fraudulent emails claim to alert users about a login from a new device and location, urging them to click links to protect their account. While the advice in the email mirrors real security steps from X, the links lead to fake websites designed to steal passwords or grant scammers direct access. Cybersecurity expert Jake Moore of ESET warns that once criminals gain access, they often use accounts for crypto scams, phishing, and misinformation. The fake emails are nearly identical to real X notifications but lack the user’s account handle and are vague about the login location. X states it only sends emails from @X.com or @e.X.com and will never request passwords via email, direct message, or reply.

What’s reported

The scam involves fake emails that appear to be login notifications from X, including the X logo, formatting, colors, and correct grammar.
The emails do not include the user’s X account handle and are vague about the login location.
Clicking links in the email leads to fake websites designed to steal passwords or authorize a scammer’s app under the guise of a “security audit” or “troubleshooting.”
Jake Moore, global cybersecurity adviser at ESET, says scammers want the user’s X username and password or to trick them into approving a malicious link.
Once criminals have access, they will likely use the account for crypto scams, phishing attacks, and misinformation campaigns.
X says it only sends emails from @X.com or @e.X.com and will never request passwords by email, direct message, or reply.
If a user entered their password or a one-time passcode on a suspicious site, they should change their password immediately and enable two-factor authentication.
X may reset passwords of accounts it believes may have been hacked and will send a secure link via email to select a new password.

Key figures

Jake Moore, global cybersecurity adviser at ESET

Sources: The Guardian

You may also like...

Leave a Reply

Your email address will not be published. Required fields are marked *