London: Users of X are being warned about a convincing phishing scam in which cybercriminals send fake login alert emails that closely resemble genuine security notifications from the platform.
The fraudulent email claims that a new device has accessed the recipient’s X account from an unfamiliar location, prompting concern about unauthorized activity. It urges users to act immediately by clicking links to reset their password or review third-party app access to secure their account.
Although the advice in the email mirrors X’s official security recommendations, the embedded links redirect users to fraudulent websites designed to steal login credentials or trick them into granting malicious apps access to their accounts.
Once an account is compromised, criminals may use it to promote cryptocurrency scams, launch phishing campaigns, spread misinformation, or carry out other fraudulent activities.
The fake emails are highly convincing, featuring X’s branding, logo, formatting, and professional language. However, there are subtle warning signs. Scam emails often fail to include the recipient’s X username, provide only vague location details about the supposed login, and originate from suspicious email addresses.

X states that it only sends emails from X dot com and E dot X dot com, never includes attachments in security emails, and will never request passwords through email, direct messages, or replies.
Users who click on the fraudulent links may be directed to fake login pages or websites that claim to offer security audits or troubleshooting tools while secretly attempting to steal passwords or gain account permissions.
What to do?
Experts advise users not to panic if they receive such an email. Instead of clicking any links, they should open the official X app or website directly to check for genuine security notifications. Users are also encouraged to verify email headers, inspect URLs carefully, and report suspicious emails using their email provider’s phishing reporting tools.
Those who only opened a suspicious webpage without entering any information are unlikely to be affected. However, anyone who entered their password or one-time verification code should immediately change their password, enable two-factor authentication if it is not already active, and review their account for any unauthorized access.
If users believe their X account has been compromised, they should follow X’s official account recovery process. The platform may reset passwords for accounts suspected of being hacked and provide users with a secure email link to create a new password.

