Breaking
DEKrieg in Nahost: Irans Nachbarn suchen Alternativrouten zur Straße von HormusUSSupreme Court to Review Alaska Pilot's Claim Over Plane Seizure for BeerFRL'UE propose de suspendre les amendes sur les émissions de méthane pour les importateurs d'hydrocarburesUSAmerican Oystercatcher Population Recovers, Faces New Threats from Climate Change and ESA ChangesFRAndy Burnham nommé Premier ministre du Royaume-Uni par Charles IIICN中聯油脂七批原油苯並芘超標 食藥署將修法加強食安管理UKOfcom Launches Investigation into Married at First Sight UK Following Rape AllegationsRUДональд Трамп пригрозил Ирану жестким ответом за убийство американских солдатARالولايات المتحدة تعتزم إرسال طائرات مقاتلة إضافية إلى الشرق الأوسطINBangladesh Army Chief Visits Turkiye for Military Training and Hardware PartnershipsDEKrieg in Nahost: Irans Nachbarn suchen Alternativrouten zur Straße von HormusUSSupreme Court to Review Alaska Pilot's Claim Over Plane Seizure for BeerFRL'UE propose de suspendre les amendes sur les émissions de méthane pour les importateurs d'hydrocarburesUSAmerican Oystercatcher Population Recovers, Faces New Threats from Climate Change and ESA ChangesFRAndy Burnham nommé Premier ministre du Royaume-Uni par Charles IIICN中聯油脂七批原油苯並芘超標 食藥署將修法加強食安管理UKOfcom Launches Investigation into Married at First Sight UK Following Rape AllegationsRUДональд Трамп пригрозил Ирану жестким ответом за убийство американских солдатARالولايات المتحدة تعتزم إرسال طائرات مقاتلة إضافية إلى الشرق الأوسطINBangladesh Army Chief Visits Turkiye for Military Training and Hardware Partnerships
Newsgather
BackWarning: Fake X Login Emails Attempt to Steal Passwords
Warning: Fake X Login Emails Attempt to Steal Passwords
NEWS
Guardian Tech20 hours agoCrime3 min readUnited Kingdom

Warning: Fake X Login Emails Attempt to Steal Passwords

Quick Look

  • Scammers are sending sophisticated fake X (formerly Twitter) login notification emails that closely mimic legitimate alerts to trick users into revealing their passwords or granting malicious app access.
  • Cybersecurity experts advise users to avoid clicking links and instead check the official app for security issues.

AI-generated summary

Why It Matters

Fake X login notification emails are circulating, designed to steal user credentials or grant malicious app access by mimicking legitimate alerts.

Font size

You have had an X account for years, since it was known as Twitter. When an email arrives about a new login from a location nowhere near where you live, alarm bells begin to ring.

“We noticed a login to your account from a new device. Was this you?” the email asks.

The location is Arizona, but you live in London. The device is “Firefox Desktop on Mac”.

“If this wasn’t you,” the email continues, “complete these steps now to protect your account.”

The steps include clicking a link to change your password, which will end up with you “logged out of all your active X sessions except the one you’re using at this time” and to click another link to review the apps that have access to your account and revoke any that are unfamiliar.

The steps are legitimate advice from X, but the links to reset your password, or to review app access are not. The email is fake and attempting to trick you into giving scammers your password, or direct access to your X account.

“Scammers want your X username and password, or to trick you into approving a malicious link that gives them access to your account without needing your password,” says Jake Moore, a global cybersecurity adviser at ESET.

Once the criminals have access to your account they will more than likely use it to attempt to commit further fraud including crypto scams, phishing attacks and misinformation campaigns.

What it looks like

The fake emails are almost an exact replica of legitimate login notifications sent by X. They include the X logo, and the same formatting, colours and copy, with correct grammar and spelling.

Small telltale signs show the email is not legitimate, such as not including your X account handle, and being vague on the location of the login.

“The two biggest giveaways are the email address it comes from, and where the links actually take you,” says Moore.

The social media site says: “X will only send you emails from @X.com or @e.X.com… Please know that X will never send emails with attachments, or request your X password by email … and will never ask you to provide your password via email, direct message or reply.”

If you do click on a link in the email, you will be brought to a fake website designed to steal your password, or to authorise a scammer’s app to access your account directly, often under the guise of a tool for performing a “security audit” or “troubleshooting”.

What to do

“If you ever receive an email like this, it is very normal, but remember not to panic, and don’t click the links to divulge any personal data. Instead, open the genuine app, and if there really is a security issue, you’ll see it there,” Moore says.

Check the email headers and URL links to ensure they are from the X.com domain. You can report fraudulent emails to your email provider using the built-in spam and phishing tools.

“If you clicked on a link, and only opened the page, you’re probably fine,” Moore says. “But if you have ever entered your password, or a one-time passcode to a web address you didn’t check, change your password immediately and double-check you have two-factor authentication turned on.”

Open Questions

  • How many users have received these fake emails?
  • What specific methods do scammers use to obtain email addresses?
  • Are there any new variations of this scam emerging?

Related Topics

This article was originally published by Guardian Tech.

Related Stories

More on this topicx