Bloomberg Impersonator Scam Hijacks Accounts via Malicious Calendly OAuth

yuntiandeng · x · 2026-08-24

A user reported a sophisticated phishing attack where an attacker impersonated a Bloomberg journalist using a verified X account. The victim received a DM with a fake Calendly link leading to an OAuth authorization page for a malicious app named "Iphone IOS." Granting access allowed the app to post crypto spam from the victim's account. The incident highlights vulnerabilities in X's verification system, where purchased blue checks and deceptive bios facilitate trust scams.

Related event: Phishers impersonate Bloomberg reporters to hijack X accounts(3 posts)→

Original post →

More from Safety

Safety channel →