Novexa News

X login warning emails are being used in fraud scams

Scam emails imitating X security alerts are being used to steal passwords and help criminals run further fraud, including crypto and phishing attacks

The Guardian BusinessPublished July 19th, 2026 6:00 AMUpdated August 24th, 2026 7:00 PM3 min read
X login warning emails are being used in fraud scams

Scam messages that imitate X security alerts are being used to trick users into handing over their passwords, according to reporting highlighted by The Guardian. The messages are designed to look like account warnings, often claiming there has been a login from a new device or from a location that does not match the user’s own whereabouts. That familiar-looking alarm is the point: it pushes people to react quickly before checking whether the notice is genuine.

We noticed a login from a new device and why it works

The phrase we noticed a login from a new device the message from frauds captures the way these scams try to borrow trust from a platform that many people still associate with their long-running X, formerly Twitter, accounts. For users who have had the same account for years, an alert about an unfamiliar login can feel urgent and credible. That sense of urgency is what fraudsters rely on.

The reported aim is not simply to cause confusion. The messages are used to steal passwords, giving criminals access to accounts that can then be used in other frauds. The source material says those follow-on crimes can include crypto scams and phishing attacks. In other words, one compromised account can become a tool for targeting other people.

The wider business risk for users and platforms

This matters because social accounts are no longer just places to post updates. They can contain personal information, contacts, private conversations and a history of trust built up over many years. When a scammer gains control of an X account, the damage can extend beyond the original victim. Messages sent from a hijacked account may appear more believable to friends, colleagues or followers, which can make secondary fraud easier to carry out.

The risk is also practical for people who use the platform for work, networking or customer contact. A compromised account can undermine confidence in a business profile, create confusion among followers and open the door to further attempts at theft. The Guardian Business report places the scam in the broader context of online fraud tactics that depend on impersonation and panic rather than technical sophistication.

What users should watch for

The key warning sign described in the source material is an unexpected email about a new login, especially one that refers to a place far from where the user actually is. Because these messages are designed to look like legitimate security notices, users should treat sudden login alerts with caution and avoid clicking through without checking whether the message is authentic.

The most important point is that the message itself is part of the scam. It is meant to obtain a password and then move the account into the hands of fraudsters. Once that happens, the account may be used to spread more scams, including attempts tied to cryptocurrency or phishing.

For anyone with a long-standing X account, the safe response is to slow down and verify before acting. That is the central lesson from this fraud pattern: the alert is the bait, and the real target is the login information behind it.

Comments

No approved comments yet.

Related Articles