Search Beyond News…

Fraudsters are exploiting fake 'new device login' alerts to hijack X accounts and fuel crypto‑scam operations

Executive summary: Fraudsters are sending fake ‘login from a new device’ messages to X (formerly Twitter) users in order to steal passwords for use in crypto scams and further phishing attacks. The scheme illustrates a rising trend of credential phishing targeting social media platforms to enable cryptocurrency fraud, posing financial risks to users and reputational risks to the platform.

Who is involved: X users, fraudsters impersonating X’s security team, and crypto‑scam operators who exploit the stolen credentials.

Likely next: X may roll out additional login‑verification prompts and users are advised to enable two‑factor authentication; regulators could issue guidance on social‑media phishing linked to crypto fraud.

The Guardian reports that attackers are sending deceptive emails mimicking X’s security notifications, prompting users to reveal passwords that are then used to steal cryptocurrency or launch further phishing waves. The campaign highlights how credential‑theft tactics are increasingly tied to the crypto ecosystem, where stolen credentials can be monetised quickly. While the article does not quantify the scale, it underscores a growing threat vector for both platform users and the broader digital‑asset market.

Timeline

Analysis — what this means

Sectors affected

Historical parallels

Sources

Browse the full archive →