theSIGNAL BUSINESS
19 July 2026
"The art of deception lies not in the lie itself, but in how closely it resembles the truth."
Business

Fake X Login Alerts Are Stealing Accounts Worldwide

A wave of near-perfect phishing emails mimicking X's login notifications is tricking users into surrendering account access to criminals.

Picture this: an email lands in a London inbox warning of a suspicious login from Arizona, on a Firefox browser running on a Mac. The formatting is crisp, the X logo is centred at the top, the grammar is flawless. Nothing looks wrong — until it is too late. This is how a new generation of phishing attacks is dismantling the assumption that a polished, official-looking email can be trusted.

The fake notifications are engineered to be almost indistinguishable from the genuine login-alert messages that X sends to its users. They replicate the platform's colour scheme, layout, and standard wording with remarkable precision. Two details, however, quietly betray them: the sender's email address does not end in @x.com or @e.

x.com, and the embedded links do not point to X's own servers. "The two biggest giveaways are the email address it comes from, and where the links actually take you," says Jake Moore, a global cybersecurity adviser at ESET. X itself has confirmed that it will never request a password by email, never send attachments, and never ask for credentials through a direct message or reply.

If a recipient clicks through, one of two outcomes follows. Either they are delivered to a counterfeit login page designed to harvest their password, or they are prompted to authorise a third-party application that grants the attacker persistent access — no password required. "Scammers want your X username and password, or to trick you into approving a malicious link that gives them access to your account without needing your password," Moore explains.

Photo: Stephen Phillips - Hostreviews.co.uk / Unsplash
A side-by-side comparison reveals how closely scam emails mimic legitimate X login notifications.
🔗
2
Telltale signs that expose a fake X email
Discuss
  • What specific steps can individuals take to verify whether a login-alert email is genuine?
  • Why might criminals prefer gaining access through an authorised app rather than a stolen password?
Business

Bank of England Bans Coal Bonds as Collateral

From October, commercial banks such as Barclays and HSBC will no longer be permitted to use thermal coal bonds as collateral when borrowing from the Bank of England — a quiet policy shift published on its website in June that climate campaigners are calling a landmark signal. The Bank cited direct financial risk: as economies move toward net zero, coal-linked assets could lose value rapidly, making them unsafe to hold on a central bank's balance sheet. Roughly 150 major financial institutions already restrict coal financing, according to Paris-based non-profit Reclaim Finance, yet the Bank of England's new rule is stricter than policies currently maintained by the European Central Bank, raising the question of whether other central banks will now feel pressure to follow.
  • Should central banks use their lending rules to actively shape climate policy?
Business

Tube Worker Wins Toxic Dust Whistleblower Case

For 15 months, Micky Steeds cleaned decades of compacted dust from London Underground vents and lift shafts wearing nothing more protective than a paper mask — dust that tests later confirmed contained asbestos, chromium, arsenic, and iron oxide. A UK employment tribunal ruled in May that Steeds, dismissed after raising repeated safety complaints, had been unfairly sacked. His disclosures were deemed "genuine and reasonable" and legally protected under the Employment Rights Act 1996. London Underground had insisted that cleaning practices did not disturb asbestos fibres.…
  • Should subway operators face criminal liability when safety whistleblowers are dismissed?
—
Scammers want your X username and password, or to trick you into approving a malicious link that gives them access to your account without needing your password.
Jake Moore, Global Cybersecurity Adviser, ESET
ASIA · Business
China's economy grows 4.3% in Q2, slowest since late 2022
AMERICAS · Business
Trump made $1.4bn from crypto in one year. Is Justin Sun the man who helped him do it?
EUROPE · Business
Why did Ryanair-Air Malta plane window blow out mid-air and could it happen again?
MIDDLE EAST · Business
Iran's oil supply threat extends beyond Strait of Hormuz
theSIGNAL IN THE LAB
IVOCABULARY
collateralindistinguishable
counterfeitbetraydisclosures
harvestmisinformation
IIGRAMMAR FOCUS
Cleft sentences — It was X that / What I need is
Cleft sentences split information into two clauses to place emphasis on a particular element. 'It was X that...' focuses on a noun or phrase, while 'What + clause + be...' emphasises a fact or action.
It was · What · that · which · is · were · who
  1. the sender's email address that quietly betrays the fake X login alerts, not the formatting or layout.
  2. It Micky Steeds who raised repeated safety complaints before he was dismissed by London Underground.
  3. What the Bank of England's new rule stricter than any policy currently maintained by the European Central Bank.
  4. It was thermal coal bonds the Bank of England banned as collateral for commercial borrowing from October.
  5. criminals typically do after gaining access is pivot the compromised account toward cryptocurrency scams.
  6. It was an employment tribunal ruled in May that Steeds had been unfairly sacked.
IIIIDIOMS
Define each idiom in your own words. Then write one sentence of your own using one idiom of your choice.
  1. it is too late (para 1: 'until it is too late')
  2. betray them (para 2: 'two details quietly betray them')
  3. pivot toward (para 3: 'criminals typically pivot the compromised account toward')
  4. balance sheet (para Bank of England: 'unsafe to hold on a central bank's balance sheet')
  5. feel pressure to follow (para Bank of England: 'other central banks will now feel pressure to follow')
IVCRITICAL THINKING
All three stories involve institutions — tech platforms, central banks, and public transport operators — that held information or authority others did not. To what extent is institutional silence or inaction itself a form of harm? Draw on at least two of the articles in your answer.
VCREATIVE · HEADLINES
Write a headline for the X phishing story in each of the following styles. One line each, no explanation:
  • TABLOID NEWSPAPER
  • LUXURY MAGAZINE
  • ACTIVIST BLOG
VIWRITING
The Bank of England's coal bond decision and the Tube whistleblower case both involve powerful institutions being pushed — by policy or by individuals — to account for risks they had previously downplayed. Write a short opinion piece arguing which form of pressure, systemic rule change or individual whistleblowing, does more to drive meaningful institutional change.
VIIDEGREES OF EXTREMITY
Complete each ladder from mild to strong.
  • unusual→→
  • resemble→→
  • concerned→→
  • restrict→→
  • unhappy→→
  • hint→→
VIIISPEAKING
  1. Which phishing detail would most people miss — and why?
  2. Could coal bond restrictions trigger wider economic consequences?
  3. How should whistleblower protections be strengthened in practice?
  4. Which article raises the most urgent unresolved question?