Fake X login alerts steal account credentials
Technology
Archived — This article has been archived. The information may be outdated.

Fake X login alerts steal account credentials

The Next Web··22 Jul

Scammers are sending near-exact replicas of X's legitimate new-device login notification emails, cybersecurity adviser Jake Moore of ESET said. The messages copy X's logo, formatting and colour scheme, then link to fake sites that harvest passwords or authorise malicious apps. Roughly 57,000 people lost USD 47 million to crypto phishing scams on X last year.

Prism

What It Means For You

  • If you use X, check sender addresses before clicking login alerts; real emails come only from @X.com or @e.X.com.
  • Hijacked accounts often promote crypto scams; roughly 57,000 users lost USD 47 million to crypto phishing on X last year.
  • Open the X app directly instead of email links if you suspect a security notification is fake.

What's Happening

  • Scammers are sending near-perfect replicas of X's legitimate new-device login notification emails, security advisers reported.
  • Fake links harvest passwords or trick users into approving malicious apps that access accounts without passwords.
  • ESET adviser Jake Moore said the emails mimic X's logo, grammar and colour scheme down to pixel-level detail.

Regulation vs Reality

  • Legitimate security alerts train users to click email links, which phishers now exploit at scale across platforms.
  • Deepfake-enabled fraud has risen sharply since 2023 as AI tools make convincing templates easier to generate.
  • X states it never sends attachments or asks for passwords by email, direct message or reply.
all-news

More in Technology