New X Phishing Scam Copies Real Login Alerts Pixel-by-Pixel to Hijack Accounts
Scammers are sending near-perfect fake X login alerts, mimicking the company’s logo, formatting, and language exactly. The only giveaways are the sender address and where the links actually direct users.
X emphasizes that it never asks for passwords by email.
Key Details:
-
Sender: Emails originate from addresses not belonging to @X.com or @e.X.com, raising suspicion.
-
Links: Links in the emails lead to fake sites designed to steal credentials or authorize malicious apps that compromise accounts without needing a password.
-
Motivation: Once inside, criminals use hijacked accounts for crypto scams, phishing attacks, and misinformation campaigns.
-
Prevention:
- Be wary of emails claiming to be from X asking for passwords by email.
- Never click links in such emails; open the app directly instead.
- Enable two-factor authentication (2FA) for enhanced security.
"Scammers want your X username and password, or to trick you into approving a malicious link that gives them access to your account without needing your password," explains Jake Moore, a global cybersecurity adviser at ESET.
In light of these developments, it’s crucial to remain vigilant against phishing attempts, especially as scammers leverage advanced AI tools to create increasingly realistic deepfakes.