An email arrives in your inbox. It looks exactly like a message from X. It warns that someone just signed into your account from an unfamiliar device in an unfamiliar city, and asks you to act immediately. The panic it triggers is precisely what the attackers are counting on.

As The Guardian first reported, a wave of phishing emails impersonating X's legitimate login notifications is currently circulating. The emails claim a new device has accessed the recipient's account and urge them to click a link to reset their password or review which apps have access. The advice mirrors what X genuinely tells its users to do — which is what makes the scam so effective.

A forgery built to fool

The fake emails are difficult to dismiss at a glance. They replicate X's branding, colour scheme, logo, and formatting with precision, including correct grammar and spelling — a standard that distinguishes this campaign from cruder attempts. The two elements that betray the deception are the sender's email address and the destination of the embedded links, both of which diverge from anything associated with the real platform.

"The emails replicate X's login alerts almost pixel for pixel," said Darren Guccione, CEO of security firm Keeper Security, adding that the sender address and link destination are "easy to miss under pressure."

Clicking either link in the email leads not to X, but to a counterfeit site built to capture login credentials. In some cases, the link authorises a malicious third-party application, granting attackers full control of the account without requiring the user's password at all — bypassing two-factor authentication in the process.

Jake Moore, a global cybersecurity adviser at ESET, noted that the fake emails tend to omit the recipient's X handle and remain deliberately vague about the supposed login location, both of which are details the genuine notification always includes. X has confirmed it sends security emails only from @X.com or @e.X.com, never includes attachments, and will never request a password via email, direct message, or reply.

Hijacked accounts and cryptocurrency fraud

The scale of the underlying problem is significant. Roughly 57,000 people fell victim to crypto phishing scams conducted through X in the past year, losing a combined $47 million, according to figures cited by The Next Web. Once criminals gain access to an account, they typically use it to promote fraudulent cryptocurrency tokens, run so-called "double your money" schemes, spread phishing links to the account's existing followers, or push disinformation.

"Scammers want your X username and password, or to trick you into approving a malicious link that gives them access to your account without needing your password," said Jake Moore, global cybersecurity adviser at ESET.

X has been under sustained pressure over crypto fraud on its platform. In April, the company announced plans to automatically lock any account that mentions cryptocurrency for the first time in its history, requiring additional verification before the account can post again — a measure its head of product described as a direct response to hijacking-based scam activity. The platform also suspended around 800 million accounts for spam and manipulation in 2024 alone.

What to do if the email lands in your inbox

Security experts are consistent in their advice: never click a link contained in a login alert email, regardless of how convincing it looks. Instead, open X directly by typing the address into a browser or using the official app, and check the security settings from there. If you have already clicked a link and entered credentials, change your password immediately, revoke access to any unrecognised third-party applications under your account settings, and enable two-factor authentication if it is not already active. Moore notes that simply opening a fake page without submitting any information is unlikely to have caused harm.

This article is free to read. It always will be — no paywall, no account, no tracking.