โ† Home
Home โ€บ Technology
Technology

New X phishing scam copies real login alerts down to the pixel

๐Ÿ“… 2026-07-20 ๐Ÿ“‚ Technology Original source โ†—
New X phishing scam copies real login alerts down to the pixel
Representative image ยท Pexels (free license)
Key points

X users are facing a new phishing scam that copies the platform's real login alert emails down to the smallest pixel. The fake messages claim a login was attempted from a new device, pushing the recipient to click a link to secure their account.

Security researchers say the emails are nearly indistinguishable from genuine alerts sent by X. The scam leverages the same layout, colors, and wording used in official notifications, including the line 'We noticed a login from a new device.'

How the scam works

The phishing email arrives with a subject line that reads something like 'New login to your X account.' Inside, the body replicates X's standard alert format, complete with a button labeled 'Review activity' or 'Secure your account.'

Clicking that button does not lead to X. Instead, it takes the user to a fake login page designed to harvest their username, password, and two-factor authentication codes. Once the fraudsters have those details, they can hijack the account within minutes.

Security experts say the scammers are likely using automated tools that scrape X's official email templates and reproduce them with high fidelity. This makes the attack harder to detect for the average user.

Why it's dangerous

X accounts are valuable targets. They can be used to spread misinformation, scam other users, or even access linked services. The platform has seen a rise in such attacks over the past year.

The scam is particularly effective because it preys on urgency. Users who see a login alert from an unfamiliar device may panic and click without checking the email's authenticity. The fake pages often ask for the same information that X would request, making them feel legitimate.

Cybersecurity firms report that the scam is being sent from compromised email accounts and spoofed domains that closely resemble X's official addresses. The difference is often a single character change, such as 'x-security.com' instead of 'x.com'.

How to protect yourself

X has not issued a public statement on the scam, but security researchers offer clear advice. Never click links in unexpected email alerts. Instead, open a new browser tab and go directly to X's website to check for notifications.

Users who have already clicked a suspicious link should change their X password immediately and revoke access to any third-party apps linked to the account. Running a security scan on the device is also recommended.

This scam is spreading globally, and experts expect more variants to appear. The best defense is skepticism: treat every unexpected alert as guilty until proven innocent.

Verify this story
Reported by The Next Web. This article was written with AI assistance from publicly available reporting โ€” always cross-check important details with the original coverage.
This content is AI-assisted and published for information only. TIVRA News links every story to its original source above โ€” please verify dates, figures and statements there. See our Disclaimer and Editorial Policy.