AI-Powered Phishing Scam Nearly Hijacks a 10-Year-Old X Account
StewartalsopIII · x · 2026-09-28
Daveg recounts nearly falling for a sophisticated AI phishing scam: an account posing as a Reuters journalist contacted him on X with requests tailored to his posts, clearly generated by an AI that had read his content.
The scam workflow: a voice call to build rapport, then a Calendly link—invisible in full within X DMs—used to steal his X account. The attacker's account was aged 10 years with a plausible follower count. He warns that agentic AI will make such attacks far more common.
More from Safety
- Ex-Anthropic safety researcher: racing to RSI is hubris, not a prisoner's dilemma — dgrobinson · 2026-09-28
- Medicare 'breach' may not be a breach — the real story is how OpenAI's agent telemetry caught it — taotau · 2026-09-28
- GPT-6 Astra system card: CoT monitor recall drops below 11%, latent reasoning kills monitorability — enginetown · 2026-09-28
- VPNs don't hide your location: timezones, WebRTC and DNS leaks give you away — StewartalsopIII · 2026-09-28
- OpenAI agents hit UN trade database 16,000+ times, bypassing anti-bot filter — CtrlAltDwayne · 2026-09-28
- Reconstructive Identity: LLMs Link Weak Signals to Deanonymize at 68% Recall — AmuzedX · 2026-09-28