Twitter Blue to X Phishing Breakout – Gridinsoft Blogs
gridinsoft.com
external-link
Amid the chaos of Twitter’s transition to the new name – X, scammers have devised yet another deception scheme. They offer Twitter Blue users to transfer their subscriptions to X, but the victim gives the attackers access to their Twitter account instead of moving. Twitter Blue to X Phishing Emails As Twitter’s global rebranding is… Continue reading Twitter Blue to X Phishing Breakout

Summary

  • Scammers exploit Twitter’s rebranding (transition to name “X”) confusion for phishing.
  • Twitter Blue users targeted, offered migration to “X,” but scammers gain account access.
  • Phishing emails seem genuine, appearing to come from x.com and passing the Security Policy Framework (SPF), and include deceptive authorization link, opening a legitimate API authorization screen.
  • Clicking link grants attackers control over victim’s Twitter account settings and content.
  • Victims can block access by revoking app authorization in Twitter settings.
  • Twitter is aware and “working on a solution.”
Article's Safety Recommendations (probably a bit generic and self-promotional)
  1. Being cautious with unfamiliar emails, especially attachments or links.
  2. Verifying URLs by hovering over them.
  3. Not sharing personal info on suspicious/unknown sites.
  4. Be careful with attachments and links.
  5. Using two-factor authentication (2FA) for account security.
  6. Keeping antivirus software updated to prevent malware.

Edited based on comment from: @incogtino@lemmy.zip

Safety Recommendations: Quit Twitter.

@incogtino@lemmy.zip
link
fedilink
English
131Y

Ethical phishing: Email Twitter users, steal their credentials, close their accounts

/jk

@delmain@beehaw.org
link
fedilink
English
31Y

/jk

… unless

@incogtino@lemmy.zip
link
fedilink
English
71Y

This is a great short analysis, but I think the generic recommendations are a bit strange when tacked onto it

Firstly, who knows what to expect from the Twitter X changeover. If I had a blue subscription I wouldn’t not (!) expect to get an email about migrating considering the chaos so far

Then the email is verified as coming from Twitter, and sends you to the genuine Twitter API. No amount of 2FA or antivirus is going to save you here

@Elephant0991@lemmy.bleh.au
creator
link
fedilink
English
21Y

You’re right. Edited.

@incogtino@lemmy.zip
link
fedilink
English
61Y

Cool cool, definitely not criticising, and a great article to post

I think the weakness of the article was mentioning that the email passed the Security Policy Framework (i.e. appeared to legitimately be from x.com) without discussing why this is possible and who is responsible for it not happening

They even say in bold that ‘the primary responsibility less with the end user’, but in this case even careful users could easily be caught

Create a post

A nice place to discuss rumors, happenings, innovations, and challenges in the technology sphere. We also welcome discussions on the intersections of technology and society. If it’s technological news or discussion of technology, it probably belongs here.

Remember the overriding ethos on Beehaw: Be(e) Nice. Each user you encounter here is a person, and should be treated with kindness (even if they’re wrong, or use a Linux distro you don’t like). Personal attacks will not be tolerated.

Subcommunities on Beehaw:


This community’s icon was made by Aaron Schneider, under the CC-BY-NC-SA 4.0 license.

  • 1 user online
  • 144 users / day
  • 275 users / week
  • 709 users / month
  • 2.87K users / 6 months
  • 1 subscriber
  • 3.12K Posts
  • 65.1K Comments
  • Modlog