Fraudsters Target X Accounts with Fake Login Alerts: How to Spot Scams
Fraudsters Target X Accounts with Fake Login Alerts

Scammers are sending fake emails impersonating X (formerly Twitter) login notifications to trick users into revealing their passwords or granting account access. These emails claim a new device login from a distant location, such as Arizona for a London user, and urge recipients to click links to secure their account. However, the links lead to fraudulent sites designed to steal credentials or authorize malicious apps.

How the Scam Works

The fake emails closely mimic legitimate X login alerts, featuring the X logo, correct formatting, and proper grammar. They typically state: "We noticed a login to your account from a new device. Was this you?" and include steps to change the password or review app access. While the advice mirrors X's genuine security guidance, the links are fake.

According to Jake Moore, global cybersecurity adviser at ESET, "Scammers want your X username and password, or to trick you into approving a malicious link that gives them access to your account without needing your password." Once compromised, accounts are often used for crypto scams, phishing attacks, or misinformation campaigns.

Wide Pickt banner — collaborative shopping lists app for Telegram, phone mockup with grocery list

Spotting the Telltale Signs

Key differences between real and fake emails include: the sender's email address (legitimate emails come from @X.com or @e.X.com, not other domains), the absence of your X account handle in the message, and vague location details. Moore notes, "The two biggest giveaways are the email address it comes from, and where the links actually take you." Hovering over links reveals deceptive URLs, often mimicking X but redirecting to phishing sites.

X states it will never send attachments or request passwords via email, direct message, or reply. Clicking a link may lead to a fake login page or prompt to authorize a third-party app under the guise of a "security audit" or "troubleshooting" tool.

What to Do If You Receive a Suspicious Email

Moore advises: "If you ever receive an email like this, it is very normal, but remember not to panic, and don't click the links to divulge any personal data. Instead, open the genuine app, and if there really is a security issue, you'll see it there." Check email headers and URL links to verify they come from the X.com domain. Report fraudulent emails using your email provider's spam and phishing tools.

If you clicked a link but only opened the page, you are likely safe. However, if you entered your password or a one-time passcode, change your password immediately and ensure two-factor authentication is enabled. If you suspect your account is compromised, follow X's help guide. X may reset passwords for suspected hacked accounts and send a secure link via email to set a new password.

Pickt after-article banner — collaborative shopping lists app with family illustration