Scammers are targeting X users with phishing emails claiming suspicious login activity from new devices. The fake messages aim to steal passwords for cryptocurrency scams and further fraud.
Users are receiving emails stating "We noticed a login to your account from a new device. Was this you?" with locations far from their actual whereabouts. These messages do not originate from X.
The phishing campaign exploits legitimate security concerns. When users click links in the emails, they are directed to fake login pages designed to harvest credentials.
Once attackers gain access to accounts, they can:
- Steal authentication credentials
- Launch cryptocurrency scams
- Execute phishing attacks targeting followers
- Compromise verified accounts for credibility
How to protect yourself:
- Never click links in unsolicited security emails
- Visit X.com directly to check account activity
- Enable two-factor authentication
- Review active sessions in account settings
- Report suspicious emails to X's security team
X has not issued an official statement on the campaign's scope, but security researchers confirm the emails are fraudulent. Users should remain cautious of any unexpected account notifications.
Elon Musk is attempting to escape Federal Trade Commission oversight of X's data handling practices. Public commenters have warned the FTC that Musk cannot be trusted to protect user privacy.
European and international law enforcement agencies have dismantled nine organized crime groups and arrested 29 suspects in a coordinated crackdown on illegal streaming operations.
The Guardian's editorial calls for ministers to terminate Palantir's NHS data access contract, citing concerns that engineers could gain unlimited access to identifiable patient records without proper consent.
Hugging Face detected an intrusion into its production infrastructure this week, with an agentic AI system gaining access to internal clusters and credentials. The company's own AI-based security triage identified the breach.