TL;DRScammers send near-perfect fake X login alerts to steal passwords. Hijacked accounts are used for crypto scams and phishing. X says it only emails from @X.com or @e.X.com.

Scammers are sending phishing emails that are near-exact replicas of X’s legitimate login notifications, warning recipients of a login “from a new device” in a location they have never been. The emails include X’s logo, correct formatting, proper grammar, and the same colour scheme as real alerts. They ask the recipient to click a link to change their password or review app access. Both links lead to fake sites designed to steal credentials or authorise a malicious app that gives attackers direct access to the account without needing a password.

“Scammers want your X username and password, or to trick you into approving a malicious link that gives them access to your account without needing your password,” said Jake Moore, a global cybersecurity adviser at ESET. Once criminals have access, they use the account for crypto scams, phishing attacks, and misinformation campaigns. Roughly 57,000 people fell victim to crypto phishing scams on X last year, losing a collective $47 million. Phishing infrastructure is scaling across platforms, with over 4,300 fake FIFA domains and credential-harvesting operations running simultaneously during the World Cup.