Scammers target X accounts with fake login alerts to steal passwords
Scammers target X accounts with fake login alerts

Fraudsters are sending fake emails mimicking X (formerly Twitter) login alerts to trick users into revealing their passwords or granting direct account access. These emails claim a login from a new device, such as a Firefox Desktop on Mac in Arizona, while the user lives in London. The goal is to steal credentials for further fraud, including crypto scams, phishing attacks, and misinformation campaigns.

How the scam works

The fake email closely resembles legitimate X login notifications, featuring the X logo, correct formatting, and proper grammar. It urges recipients to click a link to change their password or review app access, but these links lead to malicious websites designed to capture passwords or authorize a scammer's app. Jake Moore, global cybersecurity adviser at ESET, explains: "Scammers want your X username and password, or to trick you into approving a malicious link that gives them access to your account without needing your password."

Spotting the difference

Key giveaways include the email not including the user's X handle and being vague about the login location. Moore notes: "The two biggest giveaways are the email address it comes from, and where the links actually take you." X states it only sends emails from @X.com or @e.X.com, never requests passwords via email, and never sends attachments. Clicking a link leads to a fake site that may prompt a "security audit" or "troubleshooting" tool to authorize app access.

Wide Pickt banner — collaborative shopping lists app for Telegram, phone mockup with grocery list

What to do if you receive a suspicious email

"If you ever receive an email like this, it is very normal, but remember not to panic, and don't click the links to divulge any personal data. Instead, open the genuine app, and if there really is a security issue, you'll see it there," Moore advises. Check email headers and URL links to confirm they are from the X.com domain. Report fraudulent emails using your email provider's spam and phishing tools.

If you clicked a link

If you only opened the page, you are likely safe. However, if you entered your password or a one-time passcode, change your password immediately and ensure two-factor authentication is enabled. If you suspect your account is compromised, follow X's help guide. X may reset passwords of hacked accounts and send a secure link via email to select a new password.

Pickt after-article banner — collaborative shopping lists app with family illustration