New X phishing scam copies real login alerts down to the pixel to hijack accounts

Scammers are distributing highly convincing phishing emails that mimic X's official login alerts to steal user credentials. These attacks often lead to account hijacking for the purpose of spreading crypto scams and misinformation.
Why it matters
As phishing tactics become more sophisticated, users are increasingly vulnerable to account takeovers that can have significant financial and reputational consequences.
TL;DRScammers send near-perfect fake X login alerts to steal passwords. Hijacked accounts are used for crypto scams and phishing. X says it only emails from @X.com or @e.X.com.
Scammers are sending phishing emails that are near-exact replicas of X’s legitimate login notifications, warning recipients of a login “from a new device” in a location they have never been. The emails include X’s logo, correct formatting, proper grammar, and the same colour scheme as real alerts. They ask the recipient to click a link to change their password or review app access. Both links lead to fake sites designed to steal credentials or authorise a malicious app that gives attackers direct access to the account without needing a password.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in