Picture this: an email lands in a London inbox warning of a suspicious login from Arizona, on a Firefox browser running on a Mac. The formatting is crisp, the X logo is centred at the top, the grammar is flawless. Nothing looks wrong — until it is too late. This is how a new generation of phishing attacks is dismantling the assumption that a polished, official-looking email can be trusted.
The fake notifications are engineered to be almost indistinguishable from the genuine login-alert messages that X sends to its users. They replicate the platform's colour scheme, layout, and standard wording with remarkable precision. Two details, however, quietly betray them: the sender's email address does not end in @x.com or @e.
x.com, and the embedded links do not point to X's own servers. "The two biggest giveaways are the email address it comes from, and where the links actually take you," says Jake Moore, a global cybersecurity adviser at ESET. X itself has confirmed that it will never request a password by email, never send attachments, and never ask for credentials through a direct message or reply.
If a recipient clicks through, one of two outcomes follows. Either they are delivered to a counterfeit login page designed to harvest their password, or they are prompted to authorise a third-party application that grants the attacker persistent access — no password required. "Scammers want your X username and password, or to trick you into approving a malicious link that gives them access to your account without needing your password," Moore explains.