Key Takeaways
- Scammers send fake login alerts mimicking real X notifications.
- Links in these emails lead to fraudulent pages, risking account theft.
- Users advised to verify sender and link destinations before clicking.
A new scam targeting users of the social media platform X involves sending fake login alert emails that closely mimic genuine security notifications. These deceptive messages warn recipients that their accounts have been accessed from unfamiliar devices or locations, prompting them to change passwords and review connected applications.
The emails are designed to appear legitimate, using the official X logo, similar formatting, matching colors, and clean spelling and grammar. However, they contain subtle clues that can help users identify them as fraudulent. For instance, some fake emails may not include the user’s X handle or use vague location details.
Jake Moore, a global cybersecurity adviser at ESET, explains that scammers aim to either obtain the user’s X username and password directly or gain approval for malicious links that can access the account without needing the password. The advice given in these emails is often legitimate; however, the links provided do not lead to X but instead direct users to fraudulent pages.
X has issued a statement clarifying its email practices. It confirms that it only sends emails from @X.com or @e.X.com domains and will never include attachments or ask for passwords via email, direct message, or reply. Users are advised to check both the sender address and the link destination before clicking anything.
To avoid falling victim to this scam, users should open the official X app or type in X.com directly into their browser rather than following links from suspicious emails. On desktop, hovering over a link can reveal its true destination; on mobile, avoiding tapping suspicious links is recommended. Users should also verify security alerts inside the genuine app.
If an account is compromised, attackers may use it for further fraudulent activities such as crypto scams, phishing attacks, misinformation campaigns, or attempting to trick followers. They might also try connecting malicious third-party apps to the account, allowing them to maintain access even after the user changes their password.
In response to this scam, users are advised not to panic and should verify any security alerts inside the official app rather than clicking on suspicious links. If a user only opened a suspicious page but did not enter any details, they are likely safe. However, if sensitive information was entered, such as a password or one-time code, it is crucial to change the password immediately and enable two-factor authentication for added security.
Scammers want either the user’s X username and password or approval for a malicious link that can access the account without needing the password.
Jake Moore, Global cybersecurity adviser at ESET





