Scammers are targeting X users with phishing emails claiming suspicious login activity from new devices. The fake messages aim to steal passwords for cryptocurrency scams and further fraud.
Users are receiving emails stating "We noticed a login to your account from a new device. Was this you?" with locations far from their actual whereabouts. These messages do not originate from X.
The phishing campaign exploits legitimate security concerns. When users click links in the emails, they are directed to fake login pages designed to harvest credentials.
Once attackers gain access to accounts, they can:
- Steal authentication credentials
- Launch cryptocurrency scams
- Execute phishing attacks targeting followers
- Compromise verified accounts for credibility
How to protect yourself:
- Never click links in unsolicited security emails
- Visit X.com directly to check account activity
- Enable two-factor authentication
- Review active sessions in account settings
- Report suspicious emails to X's security team
X has not issued an official statement on the campaign's scope, but security researchers confirm the emails are fraudulent. Users should remain cautious of any unexpected account notifications.
France's data protection authority (CNIL) has fined Hôpital privé de la Loire €500,000 for failing to adequately protect the personal data of 727,000 patients and their relatives.
The FBI is investigating a possible security breach at an ID verification company that may have exposed driver's license scans belonging to millions of Americans. The agency confirmed the investigation to Bloomberg News on Thursday.
Attackers compromised Coder's Cloudflare infrastructure and injected malicious Terraform modules designed to steal credentials. The unauthorized registry servers delivered the infected packages to users.
A US senator has called on the NSA to provide official guidance on virtual private network selection and usage, citing confusion over the growing array of available options.