TL;DR
Scammers send near-perfect fake X login alerts to steal passwords. Hijacked accounts are used for crypto scams and phishing. X says it only emails from @X.com or @e.X.com.
The emails copy X's logo, formatting, and copy exactly. The two giveaways are the sender address and where the links actually go. X says it never asks for passwords by email.
Scammers send near-perfect fake X login alerts to steal passwords. Hijacked accounts are used for crypto scams and phishing. X says it only emails from @X.com or @e.X.com.
Scammers are sending phishing emails that are near-exact replicas of X’s legitimate login notifications, warning recipients of a login “from a new device” in a location they have never been. The emails include X’s logo, correct formatting, proper grammar, and the same colour scheme as real alerts. They ask the recipient to click a link to change their password or review app access. Both links lead to fake sites designed to steal credentials or authorise a malicious app that gives attackers direct access to the account without needing a password.
“Scammers want your X username and password, or to trick you into approving a malicious link that gives them access to your account without needing your password,” said Jake Moore, a global cybersecurity adviser at ESET. Once criminals have access, they use the account for crypto scams, phishing attacks, and misinformation campaigns. Roughly 57,000 people fell victim to crypto phishing scams on X last year, losing a collective $47 million. Phishing infrastructure is scaling across platforms, with over 4,300 fake FIFA domains and credential-harvesting operations running simultaneously during the World Cup.
The two biggest tells are the sender address and where the links actually go. X says it only sends emails from @X.com or @e.X.com, never includes attachments, and never asks for passwords by email, direct message, or reply. The fake emails do not include the recipient’s X handle and are vague on the login location. If you clicked a link but only opened the page, Moore says you are probably fine. If you entered your password or a one-time code without checking the URL, change your password immediately and enable two-factor authentication.
The scam exploits a design pattern that X itself created: legitimate login alerts that train users to click links in emails about security. Every platform that sends “was this you?” notifications is building the muscle memory that phishing exploits. Deepfake-enabled fraud has risen 3,000% since 2023, and AI tools make it trivial to generate pixel-perfect email templates at scale. The advice from Moore is old but still the only thing that works: do not click the links. Open the app directly. If there is a real security issue, you will see it there.
Get the most important tech news in your inbox each week.