NG Solution Team
Cybersecurity

How to protect your X (Musk) account and spot scams?

New phishing campaign targets X users: fake security alert emails lure victims to counterfeit login pages

A new phishing campaign is targeting users of X. Attackers are sending emails that mimic X security alerts and urging recipients to click a link that leads to a fake login page. Before interacting, verify the sender and URL — X emphasizes that certain replies or attachments are clear indicators of fraud.

How the scam works
The emails copy the look and feel of official X messages, using the platform’s logo and familiar design. They claim a suspicious login occurred from a new device or unusual location and pressure the recipient to “verify” their sign-in or “secure” their account immediately. The button or link in the message redirects to a spoofed login page; if you enter your username and password, the attacker captures your credentials. In some instances the emails also include malicious attachments meant to infect the device.

(The image associated with this campaign was generated with AI.)

What X says officially
X reminds users that the only legitimate sending domains are @x.com and @e.x.com. The company also states:
– It never sends emails containing attachments.
– It will never ask for your password by email, direct message, or reply.
– If X believes an account is compromised, it may reset the password and will send a password-reset link that points only to the official site X.com.

Why X accounts are being targeted
Social accounts—especially those with large followings—are valuable to cybercriminals because they can quickly amplify scams, fraudulent promotions, or malicious links to thousands of users. Attackers also hijack accounts to promote financial scams (cryptocurrency schemes, fake investments) or to harvest personal information.

Practical steps to protect your X account
– Check the sender before opening an email: confirm it comes from an authentic domain (@x.com or @e.x.com).
– Don’t click suspicious links or open unexpected attachments.
– Use a strong, unique password for your X account.
– Enable two-factor authentication (2FA).
– Keep your phone and computer updated with the latest security patches.
– Install reputable antivirus software and avoid apps from unofficial stores.

What to do if you’ve been targeted
If you’ve disclosed credentials or lost money, act fast: change your password, enable 2FA, and follow X.com’s account recovery options. In India, victims can contact the national cybercrime helpline at 1930. Report the fraudulent message to your email provider and, if possible, to X.

Phishing campaigns are getting more sophisticated; taking a few seconds to verify the sender and URL can prevent an account compromise and limit the spread of these scams.

Related posts

Has the US Government Suffered Another Major Cybersecurity Breach?

David Jones

Has Microsoft patched the RoguePlanet Defender vulnerability?

Emily Brown

Was Tata Electronics’ cybersecurity breach responsible for exposing Apple and Tesla documents on the dark web?

Michael Johnson

This website uses cookies to improve your experience. We assume you agree, but you can opt out if you wish. Accept More Info

Privacy & Cookies Policy