Fraudsters are imitating official login warnings to steal passwords, seize established profiles and use their credibility to promote cryptocurrency fraud and further phishing campaigns.

An email arrives warning that somebody has accessed your X account from an unfamiliar computer in a distant city. The message appears urgent, professionally designed and reassuringly familiar.
“We noticed a login to your account from a new device. Was this you?” it asks.
The recipient is told that the suspicious access came from a location such as Arizona and involved a browser or computer they do not recognise. To prevent further damage, the email urges them to change their password immediately and review the applications connected to their account.
The security advice sounds legitimate. The links are not.
Fraudsters are increasingly copying genuine notifications from X, formerly Twitter, to trick users into surrendering their passwords or authorising malicious applications. Once an account has been compromised, criminals can exploit its followers, reputation and message history to conduct cryptocurrency scams, spread phishing links or target the owner’s contacts.
The campaign demonstrates how effectively criminals can weaponise a routine security warning. Rather than offering an implausible prize or investment opportunity, the message creates fear that a breach has already occurred and pressures the recipient to act before carefully inspecting the email.
The fake alerts closely resemble genuine communications from X, often reproducing the platform’s design, security language and account-protection instructions. Some advise users to reset their passwords, terminate existing sessions and revoke access from unfamiliar applications.
Those are all sensible precautions when performed through X’s official website or application. In the fraudulent emails, however, the buttons direct users to imitation login pages controlled by the attackers. Any username, email address or password entered there can be captured immediately.
Other versions of the attack may direct victims to a legitimate-looking authorisation page and ask them to approve a third-party application. Granting that access can allow criminals to read account information, publish posts or perform other actions without necessarily knowing the password.
This makes application-based attacks particularly dangerous. A victim may change their password and assume the problem has been resolved while the malicious service retains authorised access.
Cybersecurity specialists say one of the most important warning signs is the destination of the link. A button may display wording such as “secure your account” or “review activity,” while concealing a web address that has no connection to X.
Users can examine the destination by hovering over a link on a computer or pressing and holding it on a mobile device. Slightly altered spellings, unrelated domains, unusual subdomains and long strings of characters can all indicate an imitation website.
The sender’s address can offer another clue. Fraudulent emails may use an address designed to appear official at first glance, but closer inspection can reveal misspellings, additional words or a domain unrelated to the company being impersonated.
Some fake alerts also omit information that a genuine platform might normally include, such as the recipient’s account handle. Instead, they use vague greetings and generic descriptions of the supposed login.
Yet cybersecurity experts caution that grammatical errors and poor design are no longer reliable indicators of fraud. Modern phishing messages can be polished, personalised and almost indistinguishable from authentic corporate emails.
X advises users to remain suspicious of unexpected security communications. The company says it will never ask for an account password through email, a direct message or a reply, and that its emails do not contain attachments.
The safest response to an alarming notification is therefore not to use any link contained in the message. Users should open the official X application or type the platform’s address directly into their browser, then review their account activity and security settings independently.
This breaks the chain of manipulation. Even when an alert proves genuine, visiting the platform directly allows the user to take the same protective action without risking exposure to a counterfeit page.
The criminals’ objective frequently extends far beyond stealing one social-media profile. Established X accounts can be valuable because they may have years of activity, large audiences, verified identities or trusted relationships with other users.
After taking control, attackers may change the account’s recovery details and password, locking out the legitimate owner. They can then publish fraudulent investment advertisements, impersonate the victim or contact followers privately.
Cryptocurrency fraud is a common outcome. A hijacked account may promote fake token launches, investment schemes, wallet giveaways or claims that users can multiply their digital assets by sending funds to a specified address.
The credibility of the stolen profile is central to the deception. Followers may trust a fraudulent post because it appears to come from a journalist, business, celebrity, industry specialist or personal acquaintance they have followed for years.
High-profile accounts are particularly attractive targets. Security researchers have documented phishing campaigns aimed at political figures, journalists, technology companies, cryptocurrency organisations and owners of short or commercially desirable usernames. Hijacked accounts can then be repurposed for financial fraud, propaganda or additional credential theft.
Criminals may also use the compromised account to send phishing messages to other people. A malicious link arriving from a familiar colleague or friend can be far more persuasive than one sent by a stranger.
The result is a self-reinforcing chain of account theft. Each victim provides the attacker with a new trusted identity from which to approach the next group of targets.
Two-factor authentication can significantly reduce the danger, although the type of protection matters. Authentication applications and physical security keys are generally more resistant to interception than codes delivered through text messages.
A unique password is equally important. When users recycle the same credentials across several websites, a password stolen through a fake X page may also unlock their email, shopping accounts or financial services.
Password managers can help generate and store distinct credentials for each platform, limiting the consequences when one service is compromised.
Users should also examine the list of applications and active sessions connected to their X account. Any device, location or service they do not recognise should be removed, particularly after responding to a suspicious email.
Someone who has already entered credentials into a questionable site should change the password through the official platform immediately. They should terminate other sessions, revoke unfamiliar application permissions and confirm that the account’s email address and telephone number have not been altered.
Because email access is often used to reset social-media passwords, the associated email account should also be secured. Its password may need to be changed, and two-factor authentication should be enabled there as well.
Victims should inspect recent posts and direct messages for activity they did not author. Followers may need to be warned if phishing links, investment promotions or unusual requests were sent from the account.
Suspicious messages can also be reported to the relevant platform and national cybersecurity authorities. Britain’s National Cyber Security Centre advises users not to engage with phishing communications and provides channels for reporting fraudulent emails, texts and websites.
The broader lesson extends beyond X. Fake login alerts are used to impersonate banks, cloud providers, streaming services, online retailers and email companies. The format succeeds because it transforms an ordinary security feature into a source of panic.
A real warning and a fraudulent one may look almost identical. What matters is how the recipient responds.
By avoiding embedded links, entering the service through its official application and confirming the supposed activity independently, users can investigate a potential breach without handing control of their account to the person claiming to protect it.
The most convincing phishing campaigns do not ask victims to abandon caution. They imitate caution itself.
That is what makes the fake X login alert so effective: it persuades users that the quickest way to defend their account is to follow instructions written by the people trying to steal it.




