Cybercriminals are sending fake security emails that look almost exactly like official login alerts from X (formerly Twitter). These emails are designed to trick users into revealing their account details, allowing scammers to steal their X accounts.
Because these fake emails closely copy the design and style of real X notifications, many people may not realize they are scams. Cybersecurity experts are warning users to be extra careful and always verify security alerts before clicking any links.
The scam begins with an email that claims someone has logged into the user’s X account from a new device or an unfamiliar location.
For example, the email may say that someone signed into the account using Firefox on a Mac computer from Arizona, even though the actual account owner may live somewhere completely different, such as London or another country.
The message is designed to create fear and urgency.
It usually tells users that if they do not recognize the login, they should immediately change their password, review connected applications, and secure their account.
At first glance, the advice seems completely genuine because these are exactly the kinds of actions people should take if their account is truly at risk.
However, the biggest problem is not the advice itself.
The real danger lies in the links included inside the email.
Instead of directing users to the official X website, the links take them to fake websites created by scammers.
These fraudulent websites are made to look almost identical to the real X login page.
When users enter their username, password, or verification code, the information is sent directly to the scammers.
Once criminals obtain these login details, they can immediately take control of the victim’s account.
According to Jake Moore, Global Cybersecurity Adviser at ESET, the attackers are mainly trying to achieve one of two goals.
The first goal is to steal the user’s X username and password.
The second is to trick users into approving a malicious application or permission request that allows hackers to access the account even without knowing the password.
This second method can sometimes allow attackers to continue accessing the account even after the user changes their password.
One reason this scam is becoming more dangerous is because the fake emails are much more professional than older phishing attempts.
In the past, phishing emails often contained poor grammar, spelling mistakes, low-quality images, and strange formatting.
Today’s fake X emails are much harder to identify.
They include the official X logo, similar colors, matching layouts, and professionally written text.
Many users may believe the emails are genuine simply because they look authentic.
Despite their realistic appearance, there are still several warning signs that users should watch for.
Some fake emails do not include the user’s actual X username or account handle.
Others provide vague or unusual location information that may not make sense.
Cybersecurity experts say the most important thing to check is the sender’s email address.
Official emails from X are only sent from @X.com or @e.X.com email addresses.
If the sender’s address is different, contains extra words, unusual characters, or misspellings, the email is likely fake.
Another important step is checking where a link actually leads before clicking it.
On desktop computers, users can move the mouse pointer over a link without clicking it.
This usually shows the real website address at the bottom of the browser or email application.
If the link does not lead to the official X website, users should avoid clicking it.
On smartphones, hovering over links is not always possible.
Instead, experts recommend ignoring suspicious links completely and opening the official X app or typing X.com directly into the browser manually.
This ensures users are accessing the genuine website instead of a fake one.
X has also explained how it communicates with users.
According to the company, it never sends emails with file attachments.
It also never asks users to provide their password through email, direct messages, or replies.
If any email requests a password or asks users to verify their account through an unexpected link, it should be treated as suspicious.
The consequences of losing an X account can be serious.
Once scammers gain control of an account, they often use it to carry out additional fraud.
They may post fake cryptocurrency investment schemes, send phishing messages to followers, spread false information, or impersonate the account owner.
Friends, family members, customers, and followers may trust the hacked account and become victims themselves.
Attackers may also connect unauthorized third-party applications to the account.
These malicious apps can sometimes continue accessing the account even after the original password has been changed.
For this reason, simply changing the password may not always be enough.
Users should also review all connected applications and remove any they do not recognize.
Cybersecurity experts recommend several steps if someone receives a suspicious X login email.
The first and most important step is not to click any links inside the message.
Instead, users should open the official X application or manually visit X.com in their web browser.
From there, they can check their account security settings, recent login history, and connected applications.
This allows users to verify whether the security alert is genuine.
Jake Moore advises users not to panic when receiving unexpected login alerts.
Instead, they should always confirm the information directly inside the official X app or website before taking any action.
If someone only visited a suspicious website but did not enter their username, password, or verification code, they are generally considered to be safe.
However, if they entered any login information, immediate action is necessary.
Users should change their X password as quickly as possible.
They should also enable two-factor authentication (2FA), which adds an extra layer of security by requiring a verification code in addition to the password.
Finally, users should carefully review every third-party application connected to their X account and remove anything unfamiliar or suspicious.
Cybersecurity experts say phishing attacks are becoming more advanced every year.
Scammers are using professional-looking emails, realistic websites, and convincing messages to trick even experienced internet users.
The safest approach is to never trust unexpected login alerts sent by email without verifying them first.
Whenever users receive a message claiming someone has accessed their account, they should avoid clicking email links and instead check their account directly through the official X app or by typing X.com into their browser.
Following these simple precautions can greatly reduce the risk of losing access to an account and protect users from online fraud.


