The story so far: A number of users of the X platform have complained of receiving strange or uncharacteristic direct messages (DMs) in which they were urged to vote for the sender. The DMs include a link to help the sender win a prize opportunity or contest. While many might not immediately register such requests as a security threat, here is what users should know about the scam and keeping their accounts safe.
How does the scam work?
The ‘Vote for Me’ scam is a phishing attack in which the perpetrator tries to get hold of the victims’ private credentials by sending direct messages that appear to come from trustable, legitimate sources.
In the case of X, users received unexpected DMs from accounts asking them to click on a link and vote for the sender to help them win a podcast-related opportunity. Public votes with a deadline are common in many online competitions, where users click a link to cast a vote.
Fraudsters are using that habit to urge users into responding quickly to a low-effort call to action. They also use company names like Google and Spotify to lend a sense of legitimacy to the scam.
Once the link is opened, the user is taken to a sign-in page where they are asked to enter their X username and password. Unknowingly, they open the fake page that is set up to harvest users’ credentials in order to take over their accounts. These ‘Vote for Me’ requests appear to come from both verified and non-verified X handles.
In India, multiple sources have received ‘Vote for Me’ messages from seemingly hacked accounts, with police officers in Kashmir taking note of the matter and issuing a general warning, per a Kashmir Observer report.
Complaints about ‘Vote for Me’-style scams have also been circulating on X for several months now.
What other scams are fraudsters running on X?
X users are being targeted with fake security alert emails designed to collect their username and password credentials, according to a report from The Guardian. The outlet reported that once the victim’s password was exposed, the hackers could carry out crypto scams or phishing attacks.
For those receiving fake security alerts via email, the notifications feature X’s typical logo and typographic style, as well as legitimate sounding instructions warning users to check/update their password. However, the fake emails may not mention the user’s handle or the user’s correct login location. The sender’s email ID will also not be the official X email ID, though this may be difficult for some users to vet.
What should affected users do?
Users should not click strange links in X messages, and they should never enter their username or password into a website unless they are signing into the official X platform. In case you receive a ‘Vote for Me,’ message from a user you do not know well, block the account and do not engage with the sender. In case the message comes from someone you do know, reach out to them via another channel (if possible), and verify if their X account has been compromised.
X has also warned users about fake emails that appear to originate from its company, urging users to reach out for help and to not download attachments from such emails.
“X will only send you emails from @X.com or @e.X.com. However, some people may receive fake or suspicious emails that look like they were sent by X. These emails might include malicious attachments or links to spam or phishing websites. Please know that X will never send emails with attachments or request your X password by email,” stated the social media platform.
In order to reduce the risk of a compromised account, users can set up multi-factor authentication via their X account or devices.
India-based users who believe they are being targeted with phishing emails/messages can file a complaint via the National Cyber Crime Reporting Portal, as well as with X via its official channels.