‘We noticed a login from a new device’: the message from fraudsters targeting your X account
Fraudsters are sending fake login notifications to trick users into giving them access to their X accounts, which can be used to commit further fraud, including crypto scams and phishing attacks.
Intelligence analysis by Llama

Fraudsters are sending fake login notifications to trick users into giving them access to their X accounts. These notifications are almost identical to legitimate login notifications and can be identified by small telltale signs. Users should not click on links in these emails and should instead open the genuine X app to check for any security issues.
Fraudsters are sending fake emails that look like X login notifications. They want to trick you into giving them access to your account so they can steal your password and commit more fraud. Don't click on the links in these emails and instead open the real X app to check for any security issues.
Analysis
A New Type of Scam
Fraudsters are using a new tactic to gain access to users' X accounts. They are sending fake login notifications that are almost identical to legitimate login notifications. These notifications include the X logo, the same formatting, colours and copy, with correct grammar and spelling. However, there are small telltale signs that indicate the email is not legitimate. For example, the email address it comes from is not from @X.com or @e.X.com, and the location of the login is vague.
How to Identify a Scam
The two biggest giveaways are the email address it comes from and where the links actually take you. X will only send you emails from @X.com or @e.X.com. They will never send emails with attachments, or request your X password by email, direct message or reply. If you do click on a link in the email, you will be brought to a fake website designed to steal your password, or to authorise a scammer's app to access your account directly, often under the guise of a tool for performing a 'security audit' or 'troubleshooting'.
What to Do If You Receive a Scam Email
If you ever receive an email like this, it is very normal, but remember not to panic, and don’t click the links to divulge any personal data. Instead, open the genuine app, and if there really is a security issue, you’ll see it there. Check the email headers and URL links to ensure they are from the X.com domain. You can report fraudulent emails to your email provider using the built-in spam and phishing tools. If you clicked on a link, and only opened the page, you’re probably fine. But if you have ever entered your password, or a one-time passcode to a web address you didn’t check, change your password immediately and double-check you have two-factor authentication turned on.
Key points
- Fraudsters are sending fake login notifications to trick users into giving them access to their X accounts.
- These notifications are almost identical to legitimate login notifications and can be identified by small telltale signs.
- Users should not click on links in these emails and should instead open the genuine X app to check for any security issues.
- X has taken steps to prevent these types of scams, including sending legitimate login notifications and providing users with information on how to identify and report fraudulent emails.
- Users can take steps to protect themselves by being cautious when receiving emails and checking the email headers and URL links to ensure they are from the X.com domain.
X has taken steps to prevent these types of scams, including sending legitimate login notifications and providing users with information on how to identify and report fraudulent emails. Additionally, users can take steps to protect themselves by being cautious when receiving emails and checking the email headers and URL links to ensure they are from the X.com domain.
If users click on the links in the scam emails and enter their password or one-time passcode, their account may be compromised, and they may be at risk of further fraud. Additionally, if users do not have two-factor authentication turned on, they may be more vulnerable to these types of scams.



