‘We noticed a login from a new device’: the message from fraudsters targeting your X account

by | Aug 1, 2026 | Financial

‘We noticed a login from a new device’: the message from fraudsters targeting your X account

Cybercriminals are conducting phishing campaigns targeting X users through fraudulent email notifications that mimic the platform’s legitimate security alerts. The deceptive messages claim to notify users of suspicious login attempts from unfamiliar locations and devices, prompting them to click links to reset passwords or review authorized applications.

The counterfeit emails closely replicate X’s authentic communications in appearance, including the company logo, formatting, colors, and professional copywriting. However, security experts note several distinguishing features that reveal their fraudulent nature. The emails typically fail to include the recipient’s X account handle and provide vague details about the supposed login location. Most critically, the sender email address and destination URLs differ from legitimate X domains. X confirms it only sends notifications from @X.com or @e.X.com email addresses and never requests passwords through email or direct messages.

When users click the malicious links, they are directed to fake websites designed either to capture login credentials or to trick them into authorizing a scammer’s application to access their account. These fraudulent sites often masquerade as security audit or troubleshooting tools. Once attackers gain control of a compromised account, they typically leverage it for additional fraudulent schemes including cryptocurrency scams, phishing operations, and misinformation distribution campaigns.

Cybersecurity professionals advise users encountering such emails to avoid clicking embedded links and instead access the authentic X application directly to verify whether a genuine security issue exists. Users should examine email sender addresses and link destinations to confirm they originate from X.com domains. Email providers offer built-in reporting mechanisms for suspected phishing messages. Those who have entered passwords or authentication codes into suspicious websites should immediately change their account password and ensure two-factor authentication is enabled. X states it may proactively reset passwords of accounts suspected of compromise and will send secure password reset links via verified email addresses.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI