X Scam: This Fake Email Can Hack Your Account in Minutes
A new wave of scams is targeting users of X (formerly Twitter). Phishing emails reproduce the platform's login alerts almost exactly. The goal is to steal your login details or gain full access to your account without even knowing your password.
This article will also interest you: Telegram Desktop Flaw: a Simple Link Could Hack Your Account
The method is highly effective because it exploits a reflex that X itself has trained into its users.
How does this scam targeting X users work?
The fraudulent email perfectly imitates official notifications from X:
- the logo is identical;
- the layout matches;
- the text contains no mistakes;
- the message warns you of a suspicious login from a new device.
Two buttons are offered:
- Change your password;
- Review the apps connected to your account.
The problem: both lead to fake sites controlled by the scammers.
Two techniques for hacking an X account
Jake Moore, a cybersecurity advisor at ESET, distinguishes two scenarios.
1. Classic credential theft
The victim is redirected to a fake X login page. They enter their username and password, which the attacker collects immediately.
2. Authorizing a third-party app
This method is more insidious. The link asks the user to authorize a third-party application. Once permission is granted, the app can access the account without needing the password.
| Method | What the attacker gets | What the victim notices |
|---|---|---|
| Fake login site | Username + password | Nothing right away |
| Authorized third-party app | Full access to the account | Nothing until the first post |
In both cases, the owner notices nothing until the scammer starts posting in their place.
What are hacked X accounts used for?
Hijacked accounts have a market value. They are used to:
- spread cryptocurrency scams;
- launch further phishing campaigns;
- spread disinformation;
- impersonate the victim with their contacts.
A hacked account can therefore act as a large-scale relay before its owner realizes what is happening.
How can you spot a fake X email?
Two signs make it possible to detect the scam quickly.
1. The sender's address
X only sends emails from:
- @X.com
- @e.X.com
Any other domain is fake.
2. The links inside the message
Hover over a button without clicking. The destination URL appears. If it does not point to x.com, do not click.
3. A third sign that is often overlooked
Fake emails stay vague:
- they do not mention your X username;
- they do not specify the location of the supposed login.
Genuine emails from X always include your username.
Why does this scam work so well?
X regularly sends genuine login alerts by email. Each "was this you?" notification trains users to click links in security messages.
The phishing reproduces that behavior exactly. The user sees an alert and clicks, just as they have done many times before with real emails from X. The only difference: this time, the link does not lead to X.
Generative artificial intelligence adds to the problem by making it possible to produce visually identical templates at scale. Deepfake-assisted fraud has risen by 3,000% since 2023.
How can you protect your X account?
1. Never click a link in an alert email
Open the X app directly, or type x.com in your browser, to check your account activity.
2. Check the sender's address
Any email that does not come from @X.com or @e.X.com should be treated as suspicious.
3. Watch connected apps
In X settings, regularly review the list of authorized third-party apps. Revoke immediately any app you do not recognize.
4. Turn on two-factor authentication (2FA)
Prefer an authenticator app over an SMS code, which is more vulnerable to SIM swapping.
5. Choose a unique, long password
Use a password manager so you do not reuse credentials that have already been exposed.
6. Check your active sessions
Sign out of any device or browser you do not recognize.
FAQ: common questions about the X scam
Does X really send login alerts by email?
Yes. X sends genuine security notifications. That is exactly the behavior the scammers imitate.
How can you tell if an X email is fake?
Check the sender's address (@X.com or @e.X.com) and the destination URL of the links. A genuine email from X also mentions your username.
What should you do if you clicked the link?
Change your X password immediately, revoke active sessions and third-party apps, turn on two-factor authentication, check posts and messages sent without your knowledge, and report the fraudulent email to X and to the relevant authorities.
Can a third-party app really access my account without a password?
Yes. If you authorize a malicious app, it receives an access token that lets it act on your account without knowing your password.
Is deepfake related to this scam?
Indirectly. Generative AI makes it easier to create fake emails that look identical to the originals. Deepfake-assisted fraud has surged by 3,000% since 2023.
What to remember
- A phishing campaign imitates X login alerts.
- Two techniques are used: credential theft through a fake site, or authorization of a third-party app.
- Hacked accounts are used to spread crypto scams, phishing, and disinformation.
- Genuine X emails come only from @X.com or @e.X.com.
- Never click a link in an alert email: always go through the app or the official site.
- Turn on two-factor authentication and watch the apps connected to your account.
The key reflex: never handle a security alert email by clicking. Open X directly and check your account activity yourself.