Markets
BTC 76,366 USD +0.83%ETH 2,422 USD +0.82%SOL 98.89 USD +1.91%USD/EUR 0.8668 USD/GBP 0.7432 USD/JPY 155.05 BTC 76,366 USD +0.83%ETH 2,422 USD +0.82%SOL 98.89 USD +1.91%USD/EUR 0.8668 USD/GBP 0.7432 USD/JPY 155.05
Technology

Fake ‘new login’ alerts on X are a growing phishing scam targeting account holders

Arnaque sur X : le faux e-mail de « nouvelle connexion » qui vise à voler votre mot de passe

Fraudsters are sending emails disguised as security alerts from X, the platform formerly known as Twitter, warning users of a login from an unfamiliar device. The message asks recipients to confirm whether they recognise the login, then directs them to a fake page designed to steal their password, which is later used for crypto scams or further phishing attempts.

How does the scam work?

The email is crafted to look like a routine security notification, referencing a login location that is far from where the account holder actually lives, which is designed to trigger panic. It asks the reader to click a link to verify the activity or secure their account. That link leads not to X’s real site but to a convincing replica designed purely to harvest login credentials.

Once fraudsters obtain a username and password, they can hijack the account outright or use the stolen credentials to attempt access to other services, since many people reuse passwords across multiple platforms. Compromised accounts are frequently exploited to promote cryptocurrency scams to followers or to launch additional phishing campaigns.

Why are long-standing X accounts a target?

Accounts that have existed since the platform’s Twitter days often carry an established follower base and a degree of trust, making them especially valuable to criminals. A hijacked account with years of history and genuine followers can be used to spread scam links or fraudulent investment schemes with a veneer of credibility that a brand-new fake account would lack.

We noticed a login to your account from a new device. Was this you?

How can users protect themselves?

Security specialists recommend never clicking links embedded in unsolicited emails claiming to be from X or any other platform. Instead, users should log in directly through the official app or website to check account activity, enable two-factor authentication, and use a unique, strong password not shared with other accounts. Anyone who suspects they have entered credentials on a fake page should change their password immediately and review recent account activity for unauthorised changes.

Share with