
Fraudsters are conducting phishing campaigns targeting X account holders by sending emails that closely mimic legitimate login notifications from the platform. These fraudulent messages alert users to suspicious login activity from unfamiliar locations and devices, prompting recipients to reset their passwords or review connected applications through provided links.
The counterfeit emails replicate X’s official communications with authentic branding, correct formatting, proper grammar and appropriate terminology. However, several indicators can reveal their fraudulent nature, including the absence of the recipient’s account handle and vague geographical information about the alleged login activity. The most reliable verification methods involve checking the sender’s email address, which legitimate notifications come only from @X.com or @e.X.com domains, and verifying that any links direct to authentic X.com web addresses.
Once cybercriminals gain access to compromised accounts, they typically leverage them for additional fraudulent schemes, including cryptocurrency scams, phishing campaigns targeting the account holder’s contacts, and the spread of misleading information. Attackers may also use stolen accounts to solicit authorization for malicious applications that grant direct access without requiring password credentials.
Security experts recommend verifying suspicious login alerts through the official X application rather than clicking email links. Users should examine email headers and URLs to confirm they originate from X.com domains and utilize email provider spam-reporting features for suspicious messages. Those who clicked links but only viewed pages without entering credentials face minimal risk, while anyone who provided passwords or one-time access codes should immediately change their password and enable two-factor authentication. X states it may proactively reset passwords for accounts suspected of compromise and will send secure password reset links via email to affected users.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI