The Architecture of a Massive Turkish Phishing Attack that Hacked Me
On Jan 22, my Twitter/X account was hacked in a Turkish phishing attack. My account was renamed to @XLegalAppeal, many other accounts were sent phishing DMs and I was locked out of my account for 6 days. Here's the cyber forensics of exactly how it happened, who did it, and how to prevent it happening to you.
My investigation uncovered a massive, long-running phishing campaign with over 60 identified domains operating since August 2024. All domains follow the -x.com naming pattern, designed to look like official X/Twitter domains. The campaign is still active, with 2 new domains registered on Jan 31, 2026.