LIVE Watch Now Punjabi News Channel from Pakistan
Breaking
Pakistan loses USD2 billion annually to post-harvest crop lossesExperts warn of dire climate impact on Sindh’s coastal communitiesPakistan Extends Airspace Closure for Indian AircraftPRA pledges support to travel agents in tax issuesPakistan and China to Explore Joint Venture in Baby Diaper ManufacturingPunjab’s Flooding Exposes Critical Infrastructure FailuresSapphire Fibres Joins Bid for FESCO PrivatisationCTPL Launches Campaign for Mandatory Side-View MirrorsGovernment and Industry Disagree on New Vehicle Tariff PolicyHBL Expands Services in Sindh with Prestige Lounges and Trade CentersSafe Ways to Watch a Solar EclipseNaqvi Sets September 30 Deadline for Islamabad Safe City ExpansionPIA Boosts Flights for Students, Expatriates Returning to ChinaCommissioner Launches MTP Campaign and District Accounts OfficeGovernment Streamlines Approval for Small Rooftop Solar SystemsSindh Labs Declare Five IV Sets SubstandardPTA Introduces New eSIM Pricing Policy Effective Mid-AugustMedico-legal board reconstituted for exhumation of Mir Raza Ali’s bodyGovernment Aims to Overhaul Gas Sector with New Pricing ModelSBP Tightens Rules for Prize Bond ReportingPakistan loses USD2 billion annually to post-harvest crop lossesExperts warn of dire climate impact on Sindh’s coastal communitiesPakistan Extends Airspace Closure for Indian AircraftPRA pledges support to travel agents in tax issuesPakistan and China to Explore Joint Venture in Baby Diaper ManufacturingPunjab’s Flooding Exposes Critical Infrastructure FailuresSapphire Fibres Joins Bid for FESCO PrivatisationCTPL Launches Campaign for Mandatory Side-View MirrorsGovernment and Industry Disagree on New Vehicle Tariff PolicyHBL Expands Services in Sindh with Prestige Lounges and Trade CentersSafe Ways to Watch a Solar EclipseNaqvi Sets September 30 Deadline for Islamabad Safe City ExpansionPIA Boosts Flights for Students, Expatriates Returning to ChinaCommissioner Launches MTP Campaign and District Accounts OfficeGovernment Streamlines Approval for Small Rooftop Solar SystemsSindh Labs Declare Five IV Sets SubstandardPTA Introduces New eSIM Pricing Policy Effective Mid-AugustMedico-legal board reconstituted for exhumation of Mir Raza Ali’s bodyGovernment Aims to Overhaul Gas Sector with New Pricing ModelSBP Tightens Rules for Prize Bond Reporting
◕ SundialUpdated 2 days ago
Technology

Fake X Login Alerts Steal User Credentials

Scammers send fake login alerts mimicking real X notifications, leading users to fraudulent pages. Verify sender and link destinations before clicking.

Add Sun News on Google News
Fake X Login Alerts Steal User Credentials

Key Takeaways

  • Scammers send fake login alerts mimicking real X notifications.
  • Links in these emails lead to fraudulent pages, risking account theft.
  • Users advised to verify sender and link destinations before clicking.

A new scam targeting users of the social media platform X involves sending fake login alert emails that closely mimic genuine security notifications. These deceptive messages warn recipients that their accounts have been accessed from unfamiliar devices or locations, prompting them to change passwords and review connected applications.

The emails are designed to appear legitimate, using the official X logo, similar formatting, matching colors, and clean spelling and grammar. However, they contain subtle clues that can help users identify them as fraudulent. For instance, some fake emails may not include the user’s X handle or use vague location details.

Jake Moore, a global cybersecurity adviser at ESET, explains that scammers aim to either obtain the user’s X username and password directly or gain approval for malicious links that can access the account without needing the password. The advice given in these emails is often legitimate; however, the links provided do not lead to X but instead direct users to fraudulent pages.

AdvertisementFollow Sun NewsWatch Live

X has issued a statement clarifying its email practices. It confirms that it only sends emails from @X.com or @e.X.com domains and will never include attachments or ask for passwords via email, direct message, or reply. Users are advised to check both the sender address and the link destination before clicking anything.

To avoid falling victim to this scam, users should open the official X app or type in X.com directly into their browser rather than following links from suspicious emails. On desktop, hovering over a link can reveal its true destination; on mobile, avoiding tapping suspicious links is recommended. Users should also verify security alerts inside the genuine app.

If an account is compromised, attackers may use it for further fraudulent activities such as crypto scams, phishing attacks, misinformation campaigns, or attempting to trick followers. They might also try connecting malicious third-party apps to the account, allowing them to maintain access even after the user changes their password.

In response to this scam, users are advised not to panic and should verify any security alerts inside the official app rather than clicking on suspicious links. If a user only opened a suspicious page but did not enter any details, they are likely safe. However, if sensitive information was entered, such as a password or one-time code, it is crucial to change the password immediately and enable two-factor authentication for added security.

Scammers want either the user’s X username and password or approval for a malicious link that can access the account without needing the password.

Jake Moore, Global cybersecurity adviser at ESET