Cybersecurity Agencies Warned of Rising X Account Hacks
Attackers are targeting high-profile accounts to promote fraudulent cryptocurrency schemes ahead of the holiday season.
Updated on Sept. 19, 2026 in Cybersecurity

Live Poll
Do you trust social media platforms to keep your account secure from hackers?
International cybersecurity agencies have issued warnings regarding a surge in X account takeovers orchestrated to amplify cryptocurrency scams. Attackers are using sophisticated social engineering, with X maintaining that there is no evidence of a centralized platform breach.
Why it matters
The campaign exploits accounts with large, established followings to maximize the reach of fraudulent content during periods of high social media activity. This trend threatens the integrity of public discourse on the platform as malicious actors leverage trusted identities to influence audiences.
Users have reported receiving up to 10 malicious direct messages within a few hours. The method relies on attackers masquerading as known contacts to bait users into clicking links that compromise their credentials.
The players
X
A social media platform currently expanding into financial services with its new X Money payment feature.
The details
The attack mechanism involves social engineering, where malicious actors send direct messages that appear to originate from a user's mutual contacts. Once a user clicks an embedded link, they effectively surrender control of their account to the attackers. These compromised profiles are then repurposed to post fraudulent cryptocurrency-related material, often timed to coincide with high-traffic periods.
Timeline
July 2026: A major account-takeover campaign was reported in India.
September 1, 2026: Thousands of users received unsolicited password-reset emails.
September 19, 2026: Cybersecurity agencies issued formal warnings regarding these account hacks.
Upcoming festive months: Hacking activity is expected to intensify.
The Tech Race
This wave of account takeovers tracks closely with historical patterns of social engineering that escalate during peak festive seasons. Security agencies are now racing to mitigate these threats before the upcoming holiday months drive further spikes in malicious activity.
Users should be cautious of any unsolicited direct messages or unexpected password-reset emails, even if they appear to come from mutual contacts. Protecting your account now requires heightened vigilance, as attackers are specifically targeting accounts with large followings to gain reach.
The takeaway
The recent wave of account takeovers demonstrates how social engineering remains a primary vector for crypto-related fraud on major social platforms. Readers should enable multi-factor authentication immediately and verify the source of any link received via direct message to avoid account compromise.
What happens next
Security experts and users should prepare for increased malicious activity during the upcoming festive season months.
Further reading
For more information on current digital threats, visit the Cybersecurity section.
Source note: This article includes information reported by The New Indian Express.
Live Poll
Do you trust social media platforms to keep your account secure from hackers?






