Back to Insights
Threats4 min read21 July 2026

Fake X Login Alerts Are Stealing User Credentials for Crypto Scams

Criminals are sending near-perfect copies of X's own security notification emails to harvest passwords, then weaponising stolen accounts to run cryptocurrency fraud and phishing attacks against victims' followers.

t2s
train2secure NewsdeskSecurity awareness team
A photoreal close-up of a person's hands hovering over a laptop keyboard in a dimly lit room, the laptop screen casting

Fraudsters are impersonating X's official login-warning emails to steal user credentials, using hijacked accounts to push cryptocurrency scams and phishing attacks against unsuspecting followers.

What the Attack Looks Like

The email arrives looking completely legitimate. The sender name, the layout, the wording, all of it mirrors the real security alerts X sends when a new device accesses your account. The message asks a simple question: was this you? There is a button. Most people click it without thinking.

That button does not go to X. It routes the victim to a spoofed login page, built to be visually indistinguishable from the real sign-in screen at x.com. When a user types in their username and password, attackers collect the credentials silently in the background. The fake page then redirects the user to the genuine X site, so the entire theft happens without the victim realising anything went wrong.

This is a textbook phishing attack. There is no software vulnerability to patch, no CVE number to track. The exploit is human psychology, specifically the instinct to respond quickly to what looks like a security warning from a trusted service.

Why X Accounts Are a High-Value Target

Stolen X accounts are not just trophies. They are operational assets.

An established account comes with real followers who already trust the person behind the handle. Criminals use that trust in two main ways. First, cryptocurrency fraud: the hijacked account posts fake investment opportunities, often citing fabricated endorsements from celebrities or public figures, promising quick returns on coin purchases. Second, secondary phishing: the compromised account sends direct messages to followers containing malicious links, harvesting yet more credentials from people who have no reason to doubt a message from someone they follow.

The Verizon 2024 Data Breach Investigations Report found that phishing and stolen credentials together featured in over 68 percent of breaches involving a human element. Social-engineering attacks like this one are not fringe events. They are the dominant playbook.

The Control That Failed: Security Awareness

This attack succeeds precisely because it mimics a message users expect to receive. Legitimate platforms do send login-alert emails. That familiarity is the weapon. When a notification looks routine, the critical thinking that might otherwise flag something as suspicious simply does not activate.

The missing control here is trained scepticism. A user who has learned to pause before clicking any link inside an email, regardless of how official it looks, breaks the attack chain at the very first step. That habit is not intuitive. It has to be taught, practised, and reinforced. Organisations and individuals who invest in security awareness training build exactly that kind of reflexive caution, and it costs far less than recovering from an account compromise.

Multi-factor authentication is the second missing control. Even when credentials are stolen, MFA stops an attacker from completing a login. The stolen password becomes worthless without the second factor, typically a time-limited code sent to the account owner's phone. X supports MFA, including authentication apps and hardware security keys, and every user should enable it immediately.

What Defenders and Users Should Do Now

The practical steps here are clear and achievable by anyone.

Never click links inside login-alert emails. If you receive one, open a new browser tab, type x.com directly into the address bar, and check your account security settings from there. X allows you to review active sessions and recent login activity inside the settings menu. Verify the alert is real before taking any other action.

Enable two-factor authentication today. Go to Settings, then Security and account access, then Security. Turn on two-factor authentication using an authenticator app rather than SMS if possible, since SIM-swapping attacks can intercept text-message codes.

Use a unique, strong password for X. If the same password appears on other sites, change all of them. A password manager generates and stores strong unique passwords automatically, removing the temptation to reuse credentials.

Check your account for signs of compromise. Review your sent messages and recent posts. If you spot anything you did not write, report it to X through its help centre immediately and revoke access from any unrecognised sessions.

Report suspicious emails. Forward phishing emails impersonating X to your email provider's abuse reporting function and flag them inside your inbox as phishing rather than simply deleting them. That helps spam filters protect other users.

What Organisations Should Learn

This incident is a reminder that credential phishing targets individuals, but the blast radius extends far beyond the account holder. A single compromised account can expose hundreds or thousands of followers to follow-on scams. For businesses whose executives or brand accounts operate on X, that exposure carries reputational and financial consequences.

Security teams should ensure that phishing simulation programmes include social-media impersonation scenarios, not only email impersonation of internal tools or banks. The threat surface has expanded well beyond the corporate inbox. Training staff to apply the same scepticism to personal accounts that they apply to work accounts reduces the overall risk, because people carry their habits across contexts.

Organisations looking to benchmark their current training posture against recognised frameworks can review the relevant controls at train2secure.com/standards. For teams evaluating programme options, pricing details are available here.

The attack is simple. The defence is learnable. The gap between the two is awareness.

How This Attack Could Have Been Stopped

  • Train users to pause before clicking any link inside an email claiming to be a security alert, regardless of how official the message looks.
  • Enable multi-factor authentication on all social-media and corporate accounts so that stolen passwords cannot be used alone to complete a login.
  • Run phishing simulations that include social-media impersonation scenarios, not only internal IT or banking spoofs, so staff recognise the pattern across all their accounts.

Train2Secure delivers bite-sized, scenario-based training that builds exactly the sceptical habits this attack exploits the absence of.

Start free, no card required

Frequently asked questions

How can I tell if a login-alert email from X is real or fake?

Do not trust the email itself. Open a new browser tab, type x.com directly, log in, and check your account security settings for recent login activity. Legitimate alerts will be reflected there. Never click the link inside the email to verify.

What happens to my account if attackers steal my X password?

If MFA is not enabled, attackers can log in immediately and use your account to post cryptocurrency scams or send phishing messages to your followers. They may also change your email address and password, locking you out entirely.

Does enabling two-factor authentication fully protect against this type of phishing?

MFA stops most credential-stuffing and basic phishing attacks because a stolen password alone is not enough to log in. However, some advanced phishing kits can relay MFA codes in real time. Using a hardware security key provides the strongest protection available.

Why are X accounts specifically targeted for crypto scams?

Established accounts come with built-in audiences of real followers who trust the account owner. Criminals treat that follower base as an existing distribution channel for fraud, making a high-follower account significantly more valuable than a fresh one.

Ready to Reduce Your Human Cyber Risk?

Sign up and start training your team in minutes. No sales calls, no demos — just pick a plan and go. Phishing simulations, video courses, and certificates from day one.

train2secure analytics dashboard showing training completion stats and user progress