Cybersecurity Agencies Warned of Rising X Account Hacks

Attackers are targeting high-profile accounts to promote fraudulent cryptocurrency schemes ahead of the holiday season.

Updated on Sept. 19, 2026 in Cybersecurity

Close-up of a black fiber-optic cable conduit plugged into a metallic server port, glowing with cool electric blue light.
International cybersecurity agencies are reporting an increase in account takeovers on X, as attackers use social engineering to distribute fraudulent cryptocurrency schemes. AI Illustration. Upload story photo >

Live Poll

Do you trust social media platforms to keep your account secure from hackers?

International cybersecurity agencies have issued warnings regarding a surge in X account takeovers orchestrated to amplify cryptocurrency scams. Attackers are using sophisticated social engineering, with X maintaining that there is no evidence of a centralized platform breach.

Why it matters

The campaign exploits accounts with large, established followings to maximize the reach of fraudulent content during periods of high social media activity. This trend threatens the integrity of public discourse on the platform as malicious actors leverage trusted identities to influence audiences.

Users have reported receiving up to 10 malicious direct messages within a few hours. The method relies on attackers masquerading as known contacts to bait users into clicking links that compromise their credentials.

The players

X

A social media platform currently expanding into financial services with its new X Money payment feature.

The details

The attack mechanism involves social engineering, where malicious actors send direct messages that appear to originate from a user's mutual contacts. Once a user clicks an embedded link, they effectively surrender control of their account to the attackers. These compromised profiles are then repurposed to post fraudulent cryptocurrency-related material, often timed to coincide with high-traffic periods.

Timeline

  1. July 2026: A major account-takeover campaign was reported in India.

  2. September 1, 2026: Thousands of users received unsolicited password-reset emails.

  3. September 19, 2026: Cybersecurity agencies issued formal warnings regarding these account hacks.

  4. Upcoming festive months: Hacking activity is expected to intensify.

The Tech Race

This wave of account takeovers tracks closely with historical patterns of social engineering that escalate during peak festive seasons. Security agencies are now racing to mitigate these threats before the upcoming holiday months drive further spikes in malicious activity.

Users should be cautious of any unsolicited direct messages or unexpected password-reset emails, even if they appear to come from mutual contacts. Protecting your account now requires heightened vigilance, as attackers are specifically targeting accounts with large followings to gain reach.

The takeaway

The recent wave of account takeovers demonstrates how social engineering remains a primary vector for crypto-related fraud on major social platforms. Readers should enable multi-factor authentication immediately and verify the source of any link received via direct message to avoid account compromise.

What happens next

Security experts and users should prepare for increased malicious activity during the upcoming festive season months.

Further reading

For more information on current digital threats, visit the Cybersecurity section.

Source note: This article includes information reported by The New Indian Express.

Live Poll

Do you trust social media platforms to keep your account secure from hackers?