A new online scam is targeting X users through fake security emails that closely imitate genuine login notifications from the social media platform. Cybercriminals are using realistic-looking messages to trick users into revealing their passwords or granting access to their accounts.
The fraudulent emails warn recipients that someone has accessed their X account from an unfamiliar device or location. In one reported example, the message claimed that a login occurred from Arizona using Firefox Desktop on a Mac, despite the account owner being based in London.
The fake security alert then instructs users to immediately change their password and review connected applications to protect their accounts. These recommendations appear convincing because they match the type of security advice that X itself provides when users experience suspicious account activity.
However, the links included in these scam emails do not lead to the official X platform. Instead, they redirect users to fake websites designed to capture login credentials, including usernames and passwords, or trick users into approving access requests that allow attackers to control their accounts.
Cybersecurity experts warn that these scams are becoming increasingly difficult to identify because criminals are copying the language, design, and formatting of legitimate security communications. By creating a sense of urgency, attackers encourage users to act quickly without verifying whether the email is authentic.
Jake Moore, Global Cybersecurity Adviser at ESET, explained that scammers typically aim to obtain users’ X login information or convince them to approve a malicious link that can provide account access without directly requiring a password.
Experts recommend that users avoid clicking security links received through unexpected emails. Instead, users should manually open the official X application or website and check account activity directly through security settings.
Enabling two-factor authentication (2FA) is another important step to improve account protection. This additional security layer can help prevent unauthorized access even if a password is exposed.
Users should also carefully examine email addresses, website URLs, and unusual wording before entering any personal information. Legitimate platforms generally do not ask users to provide passwords through email links.
The rise of fake login alerts highlights the growing threat of phishing attacks targeting social media accounts. As platforms become more important for personal communication, business activity, and digital identity, protecting account credentials has become increasingly essential.
Security specialists advise users to remain cautious whenever they receive unexpected account warnings and to verify alerts through official channels before taking action. A few seconds of checking can prevent long-term damage caused by stolen passwords and compromised accounts.




