Scammers target X users with convincing fake login emails
Deceptive security emails target account holders to gain unauthorized access for fraudulent activities
Cybercriminals are targeting X users with deceptive phishing emails that mimic official security alerts to steal account credentials and compromise profiles. The fraudulent emails replicate the platform's official branding, colour schemes, formatting, and grammar, making them appear identical to genuine notifications regarding unauthorised login attempts.
Global cybersecurity adviser at ESET Jake Moore warned that attackers aim to acquire usernames and passwords or trick individuals into approving malicious links that grant account access without needing credentials. Once hackers gain control of a profile, they typically utilise the hijacked account to perpetrate cryptocurrency fraud, execute secondary phishing attacks, or spread false information to carry out additional scams.
The malicious messages mirror legitimate security advice, instructing recipients to change passwords, log out of active sessions, and review connected applications. However, while the instructions reflect real safety protocols, the embedded links direct victims to malicious websites designed to harvest sensitive data.
Moore explained that the primary indicators of the scam involve checking the sender's email address and verifying the destination of embedded links. X confirmed that official communications originate exclusively from @X.com or @e.X.com addresses, contain no attachments, and never request passwords through email, direct messages, or public replies.
Security experts advise individuals who receive suspicious login alerts to refrain from clicking any links and instead open the official X application directly to check for legitimate account notifications. Users should verify sender addresses and inspect link destinations before interacting with content. Anyone who inadvertently enters credentials or one-time codes on unknown websites must reset their passwords immediately and ensure two-factor authentication remains active across their accounts to prevent unauthorised access.
