Cyber Security Agencies Warned of X Account Hacks

Authorities report hackers are hijacking prominent X profiles to circulate fraudulent crypto currency schemes.

Updated on Sept. 19, 2026 in Cybersecurity

Bold vector editorial illustration of a security key fob surrounded by abstract geometric light shards, symbolizing digital security and cybersecurity warnings.
Cyber security agencies issued global warnings Tuesday after a wave of account takeovers on X were used to promote fraudulent crypto currency schemes. AI Illustration. Upload story photo >

Live Poll

Do you trust social media platforms to keep your account secure from hackers?

Cyber security agencies have issued warnings regarding a surge in hacks targeting prominent X accounts. Attackers are exploiting these profiles to promote crypto currency schemes, often leveraging large audiences to amplify their fraudulent content.

Why it matters

The campaign exploits the trust associated with established social media accounts to deceive followers into engaging with malicious content. High activity levels during upcoming festive seasons are expected to increase the risk of these account takeovers.

Users have reported receiving up to 10 suspicious messages within hours, with attackers using direct messages disguised as mutual contacts to compromise accounts. X has reported no evidence of an actual system-level breach despite the wave of activity.

The players

X

This social media platform, formerly known as Twitter, recently launched a payment feature titled X Money.

The details

Attackers gain control of accounts after users click malicious embedded links disguised as messages from mutual contacts. Once access is obtained, these accounts are used to post crypto currency-related material to influence a wider audience.

Timeline

  1. A major takeover campaign occurred in India during July 2026.

  2. Thousands of users received unsolicited password-reset emails on September 1, 2026.

  3. Cyber security agencies issued warnings on September 19, 2026.

  4. Hacking activity is expected to intensify during the upcoming festive months.

The Tech Race

This wave of account hijacking highlights a critical vulnerability in trust-based social networks as they pivot toward financial integrations. These attacks represent a shift from traditional data theft to the weaponization of established accounts for the promotion of digital currency schemes.

Users should be wary of unexpected direct messages and password-reset requests, as clicking unauthorized links can result in a loss of account control. Enabling two-factor authentication on social profiles is recommended to mitigate the risk of these unauthorized takeovers.

The takeaway

Security experts advise users to avoid clicking suspicious links in direct messages, regardless of who appears to have sent them. Vigilance is especially critical during periods of high platform activity to prevent account compromise.

Further reading

For more information on staying safe online, visit our Cybersecurity section.

Source note: This article includes information reported by The New Indian Express.

Live Poll

Do you trust social media platforms to keep your account secure from hackers?