Indian cyber agencies have warned that X account takeovers could intensify during the festive season, with attackers using fake direct messages to hijack prominent profiles, spread cryptocurrency promotions and exploit increased online advertising and user activity across India and countries.

Could Festive Season Become Prime Time for X Account Hackers?

The420 Correspondent
6 Min Read

Indian cyber agencies have warned that the upcoming festive season could bring a larger wave of attacks targeting X accounts, with hackers allegedly using compromised profiles to promote cryptocurrency schemes and reach wider online audiences.

According to an assessment by Indian cyber agencies, the hacking activity has affected users not only in India but also in the United States, the United Kingdom, Australia, Japan, South Korea and several European countries. The assessment indicates that the threat could continue, with accounts carrying large numbers of followers particularly attractive to attackers because of their reach and credibility.

Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise

The report also raises concerns that hackers may be hired by cryptocurrency traders to take control of established X accounts and use them to promote crypto-related content. With online activity expected to rise during the festive season in India, cyber agencies anticipate that attackers could find a larger pool of active and high-visibility targets.

Fake Direct Messages Used to Take Over Accounts

A wave of X account takeovers was reported among Indian users around two months earlier, with attackers allegedly relying on deceptive direct messages to compromise accounts.

The messages appeared to come from people already connected to the targeted users and typically asked recipients to support an online activity, such as voting in an influencer contest. Users who clicked the accompanying links allegedly found their X accounts compromised within seconds.

After gaining access, the attackers allegedly changed the email address linked to the account and began publishing cryptocurrency-related posts. Similar messages were then sent to contacts associated with the compromised account, allowing the attack to spread through trusted online connections.

The method exploits the credibility of an existing contact rather than relying entirely on messages from unknown accounts. Once a trusted profile is compromised, messages sent from it can appear legitimate to friends, followers or professional contacts.

The assessment has also highlighted the role of business and promotional activity during the festive season. Companies typically increase advertising and marketing on social media during this period, creating additional activity that attackers could potentially exploit.

Festive Advertising Could Expand the Attack Surface

Cyber agencies are concerned that increased social media advertising during the festive period could provide attackers with more opportunities to target active accounts and amplify fraudulent content.

Companies and prominent users often publish more frequently during major festivals, while users are also more likely to engage with advertisements, promotional offers and other online campaigns. The assessment suggests that this increased activity could make it easier for attackers to circulate malicious links or misuse compromised accounts.

Sources indicated that X has systems in place to limit the impact of account compromises, but further strengthening may be required ahead of the festive season.

The concern is particularly significant where attackers gain control of accounts with large followings. Such profiles can provide access to sizeable audiences and may carry greater credibility than newly created fraudulent accounts.

The reported use of compromised accounts to promote cryptocurrency schemes also adds a financial dimension to the threat. The assessment suggests that attackers may be targeting recognised handles specifically because fraudulent promotions posted from established accounts are more likely to attract attention.

Similar Activity Reported Outside India

The pattern of suspicious activity has also appeared outside India. On September 1, 2026, thousands of X users reportedly received unsolicited password-reset emails, including several prominent figures associated with the cryptocurrency sector.

Some users reportedly received as many as 10 such messages within a few hours. X said it had found no evidence that its systems had been breached.

The password-reset activity coincided with the wider rollout of X Money, the platform’s new payment feature. However, the available information does not establish that the two developments were directly connected.

Indian cyber agencies have nevertheless warned that the broader pattern of account-targeting activity is likely to continue. With festive-season traffic expected to increase sharply, agencies are concerned that attackers could intensify efforts to compromise prominent accounts and use them for cryptocurrency promotions or other fraudulent activity.

The assessment places particular emphasis on vigilance during a period when users and businesses are likely to be more active online. The combination of trusted-account impersonation, malicious links and high-volume promotional activity could make the festive season an especially attractive period for attackers seeking to expand the reach of compromised accounts.

About the author — Suvedita Nath is a science student with a growing interest in cybercrime and digital safety. She writes on online activity, cyber threats, and technology-driven risks. Her work focuses on clarity, accuracy, and public awareness.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected