The message is short and alarming. Someone has logged in to your X account from a device you do not recognize. Was this you? There is a link, and the link wants you to secure your account right now.
The alarm is the mechanism. A person who believes their account is being stolen at this moment does not stop to inspect a sender address.
How the attack works
The email or direct message reproduces the look of a genuine X security notice, and the link leads to a page that reproduces the look of the X login screen. What you type there goes to the attacker.
Security researchers at SentinelOne, who have tracked this campaign, describe two recurring lures: new-login alerts and fake copyright infringement notices demanding account verification. One version of the campaign abused Google's AMP cache domain as a redirect, so the initial link in the message pointed at a legitimate Google address before forwarding victims to the fake login page. A cautious reader checking the visible domain would have seen something reassuring.
What follows a successful theft is quick. According to the same research, attackers "swiftly lock out the legitimate owner and begin posting fraudulent cryptocurrency opportunities or links to external sites designed to lure additional targets."
That is the business model. The account is not the prize; the followers are. A compromised account with an established audience is a delivery system for the next fraud.
Who gets targeted
SentinelOne's analysis lists US political figures, international journalists, an X employee, large technology and cryptocurrency organizations, and holders of short, valuable usernames among the targets.
Named cases include the Linus Tech Tips account, with roughly 1.8 million followers, compromised in mid-2024, and the Tor Project account, compromised on January 30, 2025.
The targeting is not exclusive, though. The same lure is sent in bulk, and an ordinary account is worth taking if the attempt costs nothing.
What gives it away
X states that its official email comes only from x.com or e.x.com addresses. A message from anything else is not from X.
Genuine security notices also tend to name your account. A message that refers vaguely to "your account" and "a new device," without a handle, a location or a time, is a reasonable thing to distrust.
Two absolute rules are worth holding onto: X does not send attachments with security alerts, and no legitimate service asks for your password by email.
What actually protects you
Do not use the link. This single habit defeats the entire attack. If a message says your account is at risk, close it and open the X app, or type the address into your browser yourself. If the alert was genuine, the warning will be waiting for you inside your account. If it was not, you have lost nothing.
Treat urgency as a warning sign. The FTC's guidance makes the point that phishing works by manufacturing pressure. A message engineered to make you hurry is telling you to slow down.
Choose phishing-resistant two-factor authentication. X supports three second-factor methods: text message, an authentication app, and a security key. They are not equal. A code sent by SMS or generated by an app can be phished, because a convincing fake page can simply ask you for the code and pass it along in real time. A security key cannot be used on a site that is not the real one, which is why the UK's National Cyber Security Centre advises moving away from SMS codes where a stronger option exists.
If you have already entered your details, change the password immediately from within the app rather than from any link, review the third-party apps authorized on the account, and turn on two-factor authentication if it was not already on. In the UK, suspicious emails can be forwarded to report@phishing.gov.uk; in the US, they can be reported at ReportFraud.ftc.gov.
The uncomfortable part of this scam is that the warning it imitates is a real and useful one. The defense is not to ignore security alerts. It is to never let the alert itself choose where you log in.



