Close Menu
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
What's Hot

KelpDAO commits 2,000 ETH to DeFi united recovery fund for rsETH restoration

May 3, 2026

Steel Power Unveiled: Is SteelPower Male Enhancement Formula Legit? Read Steel Power Supplement Report!

May 2, 2026

Seoul Court Rescues Bithumb from Record 6-Month Suspension

May 2, 2026
Facebook X (Twitter) Instagram
Recession Profit AlertsRecession Profit Alerts
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
Recession Profit AlertsRecession Profit Alerts
Home»Security»High-profile X Accounts Targeted in Phishing Campaign
High-profile X Accounts Targeted in Phishing Campaign
Security

High-profile X Accounts Targeted in Phishing Campaign

February 21, 2026No Comments3 Mins Read

A phishing campaign targeting high-profile X accounts has been observed hijacking and exploiting them for fraudulent activity. 

The campaign, uncovered by SentinelLabs, has impacted various individuals and organizations, including US political figures, international journalists, a platform employee, major technology firms, cryptocurrency organizations and owners of valuable short usernames.

SentinelLabs’ analysis links this activity to a similar operation from 2024 that compromised multiple accounts to spread scam content for financial gain. Although this campaign primarily focuses on X accounts, the attackers have also targeted other popular online services.

Phishing Tactics and Account Takeover

Over the past few weeks, the security firm has identified various phishing lures used in this campaign. One common tactic involves sending fake login notifications via email and directing targets to credential phishing sites. Another approach uses copyright violation warnings to deceive users.

In some cases, attackers have leveraged Google’s AMP Cache domain to bypass email security filters and redirect users to phishing websites. These deceptive pages prompt users to enter their X account credentials, allowing attackers to take control of accounts. Once compromised, accounts are quickly locked from their rightful owners and used to promote fraudulent cryptocurrency schemes or external sites designed to deceive additional victims.

Read more on cryptocurrency-related scams: Web3 Attacks Result in $2.3Bn in Cryptocurrency Losses

Widespread Infrastructure and Attack Patterns

The campaign has utilized multiple phishing domains, such as securelogins-x[.]com for email delivery and x-recoverysupport[.]com for hosting phishing pages. These domains have been linked to an IP address associated with a Belize-based VPS provider. Most of these phishing sites were registered through a Turkish hosting service.

See also  StripedFly malware targets more than a million PCs, disguising as a crypto miner

Further investigation into the attack infrastructure reveals that the domains often employ FASTPANEL, a website management service that, while legitimate, is frequently abused by cybercriminals due to its ease of use and low cost.

Many of the malicious sites hosted on the campaign’s servers remain operational. This indicates the attackers’ ability to sustain long-term phishing efforts while evading detection.

Emerging Account Intrusions and Crypto Fraud

Recent incidents suggest the campaign may be expanding its targets. On January 30 2025, the official X account of the Tor Project was compromised in a manner consistent with these phishing tactics.

Similarly, social media accounts tied to the Decentralized Autonomous Wireless Network (DAWN) were hijacked to lure victims into phishing traps targeting X and Telegram credentials.

Some of the compromised domains have also been linked to crypto-themed scams. For example, buy-tanai[.]com was initially marketed as an AI-powered trading tool but was later found to be a placeholder for potentially fraudulent activities. The attackers appear to stage such domains for future use, adapting their content to fit evolving scams.

Historical Connections and Prevention Measures

This campaign follows a pattern of high-profile account takeovers seen in mid-2024, including the hijacking of the Linus Tech Tips X account. More recently, in January 2025, the X account of late crypto-enthusiast and antivirus software founder John McAfee was reactivated to promote a dubious cryptocurrency called $AIntivirus.

To protect against such threats, users should:

  • Use a strong, unique password for X accounts
  • Enable two-factor authentication (2FA)
  • Avoid clicking on links in unsolicited messages
  • Verify URLs before entering credentials
  • Initiate password resets directly through official websites
See also  FBI-Led Operation Duck Hunt Shuts Down QakBot Malware

SentinelLabs said it continues to monitor the situation and urged anyone who encounters similar suspicious activity to report it.

Image credit: sdx15 / Shutterstock.com

Source link

accounts Campaign highprofile Phishing Targeted

Related Posts

How North Korean spies spent months in-person to drain $285 million from Drift

May 2, 2026

Meteora reports $1.5 million OTC scam loss in Q1 MET report

May 2, 2026

Crypto hack losses top $630M in April, highest since February 2025

May 2, 2026

US seized $500M in Iranian crypto assets, Treasury secretary says

May 2, 2026
Top Posts

Quantum Computing Market to Reach US$ 8,788.8 Million by 2031 | Key Companies: IBM Quantum, Google, Honeywell, Rigetti, IonQ, Microsoft, D-Wave, Zapata Computing

February 8, 2026

AAVE Breakdown Targets $85 Support Before Dead Cat Bounce to $110

April 24, 2026

Bitcoin Treasury Giant Metaplanet Speaks to Shareholders at Japan Bitcoin Future Forum – Bitcoin News

March 26, 2026

Type above and press Enter to search. Press Esc to cancel.