Fraudsters send fake X login alerts to steal passwords
A surge in fraudulent emails targeting users of the social‑media platform now known as X has prompted security experts to warn that attackers are attempting to harvest passwords for subsequent crypto‑related scams and phishing campaigns. The messages, which mimic official notifications from the service, claim that a login was detected from an unfamiliar location and ask recipients to confirm whether the activity was legitimate. By prompting users to click a link or enter credentials, the scams aim to gain unauthorized access to accounts that have been in use for years, often dating back to the platform’s former identity as Twitter.
Cybersecurity analysts note that the deceptive alerts exploit the familiarity of X’s standard security communications, making them difficult for average users to distinguish from genuine messages. Experts advise users to verify any login notifications directly through the official X app or website, avoid following links embedded in unsolicited emails, and enable two‑factor authentication to add an extra layer of protection. Ongoing awareness campaigns by both the platform and independent security firms seek to reduce the success rate of these credential‑theft attempts and mitigate the broader risk of financial fraud linked to compromised social‑media accounts.