Multiple outlets report a new phishing campaign targeting X users through convincing email messages designed to look like legitimate X login alerts. The scam emails warn the recipient of a login from a new device or from a location the user has not recognized. According to reports, the messages closely mimic X’s real notifications, including the company logo, formatting, wording, and color scheme, making them difficult to distinguish from authentic alerts.

Instead of prompting users to secure their account through a legitimate process, the emails direct recipients to click a link that leads to a fraudulent site intended to capture credentials. One outlet notes that the campaign is designed to steal passwords rather than provide account protection. The reports also describe that, upon interaction, the phishing flow can be used to hijack accounts.

Both sources emphasize the importance of verifying login activity and taking care not to follow links from unexpected security notifications. Users who receive such messages are encouraged to access their accounts through official methods rather than the email link.