
X users are facing a new phishing scam that copies the platform's real login alert emails down to the smallest pixel. The fake messages claim a login was attempted from a new device, pushing the recipient to click a link to secure their account.
Security researchers say the emails are nearly indistinguishable from genuine alerts sent by X. The scam leverages the same layout, colors, and wording used in official notifications, including the line 'We noticed a login from a new device.'
The phishing email arrives with a subject line that reads something like 'New login to your X account.' Inside, the body replicates X's standard alert format, complete with a button labeled 'Review activity' or 'Secure your account.'
Clicking that button does not lead to X. Instead, it takes the user to a fake login page designed to harvest their username, password, and two-factor authentication codes. Once the fraudsters have those details, they can hijack the account within minutes.
Security experts say the scammers are likely using automated tools that scrape X's official email templates and reproduce them with high fidelity. This makes the attack harder to detect for the average user.
X accounts are valuable targets. They can be used to spread misinformation, scam other users, or even access linked services. The platform has seen a rise in such attacks over the past year.
The scam is particularly effective because it preys on urgency. Users who see a login alert from an unfamiliar device may panic and click without checking the email's authenticity. The fake pages often ask for the same information that X would request, making them feel legitimate.
Cybersecurity firms report that the scam is being sent from compromised email accounts and spoofed domains that closely resemble X's official addresses. The difference is often a single character change, such as 'x-security.com' instead of 'x.com'.
X has not issued a public statement on the scam, but security researchers offer clear advice. Never click links in unexpected email alerts. Instead, open a new browser tab and go directly to X's website to check for notifications.
Users who have already clicked a suspicious link should change their X password immediately and revoke access to any third-party apps linked to the account. Running a security scan on the device is also recommended.
This scam is spreading globally, and experts expect more variants to appear. The best defense is skepticism: treat every unexpected alert as guilty until proven innocent.