Sophisticated scam targets X users with emails that simulate login notifications
Criminals are sending misleading electronic messages, simulating legitimate notifications from platform X, with the aim of stealing credentials and hacking profiles. These fraudulent communications warn of a supposed access attempt on an unknown device, pressuring the receiver to take hasty action without first confirming the authenticity of the information.
Digital security experts warn that the addresses contained in these messages direct users to counterfeit websites, specifically designed to steal login information or give fraudsters control over the account.
How deceptive messages replicate X’s visual identity
Initially, the appearance of electronic messages conveys an impression of truthfulness. The text alleges unauthorized access to the account, coming from an unknown device and location, and asks the recipient whether such entry was made by him.

The email then suggests changing the password and checking the applications linked to the profile. While these recommendations are common to X protection guidelines, the trap lies in the hyperlinks, which lead to fake platforms designed to steal credentials or allow improper account access.
Learn more: Apple system update recovers passwords lost in network failures to prevent intrusions
“Fraudsters seek to obtain your X username and password, or attempt to manipulate the user into approving a harmful link that gives them account access without the need for a password,” explained Jake Moore, global cybersecurity consultant at ESET.
After being hacked, the profile can be used in a series of other illicit practices, including schemes related to cryptocurrencies, new phishing attacks and the dissemination of fake news, increasing the risks for the user and their network of contacts.
Recognizing the characteristics that indicate fraud
The email’s appearance is extremely similar to authentic X communications, replicating the logo, colors, formatting, and even writing style. This high visual fidelity is what makes it difficult for victims to detect fraud.
More on this story: Vast amount of email credentials, including Gmail and Outlook, compromised by infostealers
Even so, some specific signs help identify the attempted scam:
- The email message omits the X account username.
- The indication of the location where the alleged access occurred is generally imprecise.
- The sender’s domain does not match the official X email addresses.
- The hyperlinks present in the communication redirect to sites that do not belong to the X.com domain.
Platform X itself clarifies that its official electronic communications are issued exclusively through the @X.com or @e.X.com domains. The company also emphasizes that it never requires passwords via email, direct messages or responses, and that it does not include attachments in any correspondence related to account security.
On the same topic: Apple system update creates temporary vault to protect generated passwords from failure
What to do when you come across a suspicious notification?
Jake Moore advises remaining calm before any impulsive reaction. He advises: “If you receive an email of this nature, the priority is not to panic or interact with the links to enter personal information. Instead, access the platform’s official application, where any genuine security concerns will be properly displayed.”
Before clicking on any hyperlink, it is prudent to examine the message headers and confirm that the originating address belongs to the legitimate X.com domain. Additionally, spam and phishing reporting tools, available on most email services, can be used to report dubious messages.
X reiterates that it never requests passwords via email and that it does not attach files to messages that address the security of an account.
More on this story: Data from 183 million Gmail and Outlook accounts exposed in new massive password leak
What to do if you clicked on the malicious link
If the user just opened the fraudulent page, Moore indicates that, in general, there is little cause for alarm. However, if passwords or authentication codes were entered, the recommendation is to change them urgently, ensure that two-factor authentication is active and consult the X support guide. The platform highlights that accounts that show signs of compromise can have their passwords reset and receive a secure link via email to configure a new access credential.
















