Fake X Login Alerts Are Being Used to Steal Your Password

Criminals are sending convincing 'new device login' emails to X users, hoping to harvest account credentials for follow-on fraud including crypto scams and phishing attacks.

ThreatVectr Newsdesk· 3 min read
Photoreal news-editorial style, 16:9 framing, full-frame edge-to-edge composition
Share

Key points

  • Criminals are sending fake security alert emails to X (formerly Twitter) users, impersonating the platform's own login-warning messages.
  • The goal is credential theft, meaning stealing your username and password, which criminals then use to run scams from your account.
  • Stolen X accounts are being used to push cryptocurrency scams and phishing attacks, where fake messages trick your followers into handing over money or passwords.
  • There is no patch to apply here: this is a social-engineering attack, meaning it works by deceiving people rather than exploiting a software flaw.
  • Any X user who receives an unexpected login-alert email should treat it as suspicious until proven otherwise.

You get an email. It looks exactly like something X would send. "We noticed a login to your account from a new device. Was this you?" There is a button. You click it.

That click is what the criminals are counting on.

As The Guardian Technology reported, fraudsters are sending fake versions of X's genuine security-notification emails. The messages are convincing because they copy the real thing almost perfectly, right down to the wording and layout.

The link inside the email does not go to X. It goes to a fake login page, a site designed to look identical to X's real sign-in screen. When you type in your username and password, the criminals collect them silently, then redirect you to the real X site so you never notice anything went wrong.

So what do the criminals actually want your X account for?

They want an audience they didn't have to build. An established X account with real followers is a ready-made megaphone for scams.

The two most common plays are cryptocurrency fraud, where the hijacked account posts fake investment opportunities promising quick returns, and phishing, where it sends convincing-looking messages to your followers asking them to click links and hand over their own passwords. Your followers trust you. That trust is the product being sold.

The defence is straightforward. Do not click links inside login-alert emails. If you receive one, open a fresh browser tab, go directly to x.com by typing the address yourself, and check your account security settings from there. X, like most platforms, lets you review recent login activity and active sessions inside your account settings.

Turn on two-factor authentication, which means the site asks for a second proof of identity (usually a code sent to your phone) before letting anyone log in, even if they have your password. A stolen password alone becomes useless.

If you use the same password on X as on other sites, change all of them. A password manager, a free or cheap app that creates and stores strong unique passwords for every site, removes most of that risk entirely.

Check your sent messages and recent posts if you think your account was hit. Report anything suspicious to X directly through its help centre.

© 2026 Threat Vectr