New X phishing scam mimics real security alerts to steal accounts
Fake login-alert emails have been a phishing workaround for years and many reports have pointed to scammers impersonating platforms like Meta going back to at least 2022. The latest version of this phishing scams is now targeting X users, and cybersecurity researchers say it's more convincing than most.
The new phishing scam mimics real security alerts in the sense that you get an email and open the inbox to see an alert claiming someone just logged into your X account from an unfamiliar device. Your first instinct is to click through and lock things down immediately. That instinct is exactly what a new phishing scam is counting on.
This is the exact trick an X user has experienced, according to a report by The Guardian. The report disclosed that one recipient described getting an email flagging a supposed login from a new device located in Arizona, despite living in London, with the device listed as Firefox Desktop on Mac. The email asked if this was them and, if not, pushed them to act immediately to secure the account.
![]() |
| Source: The Guardian |
The advice mirrors what X itself tells users to do whenever a login is detected on users' accounts. This is exactly what makes it convincing. The scam repeats X's own genuine security advice, which are changing your password, logging out of other sessions, and reviewing connected apps.
All these steps are real but the only problem here (and where many users fall victim of this scam) is that none of the links attached to the email lead to the official X site. They lead to pages built to steal your password or trick you into granting a scammer's app full access to your account.
Beyond the mimicking X email page
What makes the fake email so convincing is that the emails are visually close to flawless copies of X's real notifications that match the logo, layout, colors, and wording. Even grammars and spellings—which used to be a reliable red flags before—are no longer the problems for scammers anymore because AI tools now let them produce polished text regardless of their own language skills.
![]() |
| Source: The Guardian |
Jake Moore, global cybersecurity adviser at ESET, says the details that actually expose a fake emails or messages are easy to overlook unless you know where to look. Moore cited the sender's email address and where the embedded links actually lead once clicked are the biggest tells that you're probably dealing with a scammer.
He highlighted that genuine X security emails only come from @X.com or @e.X.com addresses, and the company never requests a password via email, DM, or reply. Other tells include missing account handles or vague, inconsistent details about the login's location.
Moore explains that the goal is either to obtain your username and password directly, or to get you to approve a malicious link that hands over account access without needing your password at all. From there, a hijacked account is typically repurposed for further fraud, including crypto scams and misinformation campaigns.
What you should do if you get X's security email alert
If you get any security alert email from X, don’t panic and don’t rush to click anything in the email. The first thing you need to do, as advised by the security researchers, is open the X app directly. If there’s a genuine security problem, it will show up there right after you sign in to the account. In addition to that, before you trust any security email, check that the sender's address matches X's official domains, and hover over links rather than clicking them outright.
If you've already entered a password or one-time code on a page you didn't verify, change your password right away and confirm two-factor authentication is active. Turning on 2FA and changing your password will ensure that scammers don't take control of your X account even if they have the previous password. If you only opened a link without submitting any information, you're likely fine.


