On 3 January the X account of Mandiant — the threat-intelligence firm that Google bought for $5.4 billion, whose job is literally to detect this kind of thing — began posting links to a cryptocurrency wallet. It was not Mandiant. Attackers had taken the account, renamed it after a legitimate crypto project and used it to push a wallet-draining site to the company’s 120,000 followers for several hours. The Hacker News reports it is one of a run of such takeovers: a Canadian senator, a Brazilian politician and a nonprofit organisation have all had their verified accounts hijacked in recent weeks to promote crypto scams and phishing pages.
Why verified accounts
X sells its checkmarks: blue for individuals who pay for Premium, grey for government bodies and officials, gold for organisations. The ticks are supposed to mean identity has been checked, and readers treat posts from ticked accounts as credible — which is exactly what a scammer wants. A gold-tick account announcing a token launch or an airdrop gets clicks that an anonymous account never would. The stolen credentials are also traded: the report says hackers sell access to verified accounts to other criminals, with prices rising with the follower count.
How the accounts are taken
Mostly the old ways. Phishing emails imitating X’s own security notices; passwords reused from other breached sites; and, in Mandiant’s case, the account had let its two-factor protection lapse during a change of authentication policy at X — a brute-force attack on the password did the rest. X removed the option of SMS two-factor authentication for non-paying users last year, which left some accounts with no second factor at all.
What to do
- Turn on two-factor authentication with an authenticator app or a security key (Settings → Security and account access → Security → Two-factor authentication). Do not rely on SMS.
- Use a password unique to X, generated by a password manager.
- Review connected apps and revoke anything you do not recognise; third-party tools are a common back door.
- For organisations: delete dormant verified accounts, or at least secure them — an unused gold tick is a scam waiting to be bought.
In Bangladesh the same pattern runs on Facebook, where verified pages of media outlets and celebrities are periodically hijacked to sell mobile-phone “offers” and betting sites. The lesson is the same on every platform: a badge tells readers to trust the account, so the account must be harder to steal than the badge is to trust.
Source: India Today, via Prothom Alo.




