Fraudsters are exploiting a familiar security prompt — “we noticed a login from a new device” — to trick X users into giving away their passwords. The latest Guardian Scam Watch report says the messages are designed to look like genuine account alerts, but the real aim is to push people to a fake login page or a false help route where credentials can be stolen. The scam is timely because account-related fraud remains one of the most common tactics reported across major platforms and consumer services. (theguardian.com)
What happened
According to the Guardian’s report, scammers have been sending X users fake “new device login” alerts that imitate a security warning. The message is meant to create urgency: if you think someone has just accessed your account, you may click quickly and enter your password without checking whether the alert is genuine. The scammers then use the details to take over the account or move into other fraud, such as phishing, impersonation or crypto scams. (theguardian.com)
Why this matters
Social media accounts are not just for posts and messages. They can also contain:
- private direct messages,
- saved contact details,
- linked email addresses and phone numbers,
- access to other accounts if you reuse passwords, and
- a trusted public identity that can be used to scam your friends, clients or followers. (theguardian.com)
Once a scammer controls a social account, they may post bogus links, message your contacts for money, or use the account to make the next scam look more believable. The Guardian’s reporting and broader scam guidance from UK authorities both point to password theft as the gateway to wider fraud. (theguardian.com)
Who may be affected
Anyone with an X account could be targeted, but the risk is higher if you:
- use the same password on multiple sites,
- have a public-facing profile, business account or creator account,
- respond quickly to security warnings without checking the source,
- manage money, customers or communities through your account, or
- recently changed your password and are expecting account-related emails or texts. (theguardian.com)
Warning signs
Be cautious if a message or email:
- claims there was a login from a new device or unusual location,
- pressures you to act immediately,
- contains a link to sign in or “secure” the account,
- asks for your password, one-time code or recovery details,
- uses poor spelling, odd sender details or a mismatched web address, or
- asks you to call a number or reply to the message. (gov.uk)
If the alert is genuine, you should normally be able to confirm it by opening X directly through the app or by typing the site address yourself, rather than tapping a link in the message. That is a practical step, not a guarantee, so if you are unsure, check from the account settings and official help pages. (gov.uk)
What readers should do now
- Do not click the link in the alert. Open X separately and check your recent login activity from inside the account if possible. (gov.uk)
- Change your password if you entered it on a page you do not trust, or if you suspect the message was fake. Use a strong, unique password. (gov.uk)
- Enable two-factor authentication if you have not already. This adds an extra barrier even if your password is stolen. (gov.uk)
- Check recovery options and connected devices for anything unfamiliar. If X shows a device you do not recognise, remove it. If any account settings have changed, restore them. (theguardian.com)
- Report the scam if you received it by text or email. In the UK, suspicious texts can be forwarded to 7726 for free, and phishing can be reported through GOV.UK. (gov.uk)
If you may already have been caught out
If you typed your password into a suspicious page, act quickly:
- change the password on X and anywhere else that used the same password,
- log out of other sessions or devices,
- check your email for password-reset or security-change messages,
- review posts, replies, direct messages and linked apps, and
- warn contacts if the account may have been used to send messages on your behalf. (gov.uk)
If money was involved, or if you think your bank details were exposed, contact your bank immediately and follow its fraud process. GOV.UK and Ofcom both advise reporting scam contact promptly and not engaging with the sender. (gov.uk)
How to stay safer next time
- Use a password manager to create unique passwords for each account.
- Turn on two-factor authentication for X and your email account.
- Be wary of any message that creates panic or urgency.
- Never share passwords or one-time codes with anyone, including anyone claiming to be support staff. (gov.uk)
- Check account security directly inside the app or official website rather than through a message link. (gov.uk)
This kind of scam works because it looks routine. A fake warning about a “new device login” borrows the language of real security systems, which makes it feel believable at a glance. That is why slowing down and checking the source is one of the best defences. (theguardian.com)
Key takeaway
If you get a “new device login” alert for X, do not tap the message and do not enter your password from the link. Open the app or website separately, check your account security settings, and change your password straight away if anything seems off. (theguardian.com)