Vote Link Phishing Scam: Recovering A Hacked X Account

Vote Link Phishing Scam: Recovering A Hacked X Account

Social media accounts today are more than communication tools. They often hold years of personal memories, professional connections, and digital identity. Losing access to such an account can have significant personal and professional consequences. Yet users who fall victim to account takeovers often find that regaining access is far more difficult than expected, particularly when platforms rely heavily on automated grievance systems.

 

This was the experience of an X (formerly Twitter) user whose account was compromised after she unknowingly clicked on a phishing link sent through a trusted contact. The attackers quickly changed the registered email address, locked her out of the account, and eventually, the account itself was suspended. Despite immediately attempting to recover her account, she was unable to regain access through the platform’s official channels. This is a common pattern of the Vote Link Phishing Scam, which we at SFLC.in have been monitoring for the past few months.

 

The user repeatedly reported the incident to X and followed X’s account recovery process by contacting the platform’s grievance officer. However, each attempt resulted in standardised, automated responses that failed to address the core issue. Since the attackers had already changed the account’s recovery credentials, the platform’s automated processes were unable to distinguish the legitimate account owner from an unauthorised user. Instead of resolving the complaint, the grievance mechanism trapped the user in a cycle of ineffective recovery steps. Helpless, the user turned to SFLC.in’s RightsLine, the 24×7 free legal helpline for all forms of online harm.

 

Recognising that the platform’s internal grievance process had failed, SFLC.in  assisted the user in filing an appeal before the Grievance Appellate Committee (GAC) under Rule 3A of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021. The appeal argued that X had failed to provide effective grievance redressal despite repeated complaints and sought restoration of the account through manual verification.

 

The Grievance Appellate Committee was established to provide users with an independent forum when they are dissatisfied with the response of an intermediary’s Grievance Officer or receive no meaningful resolution. It reflects an important principle of digital governance, that platforms should not be the sole decision-makers in disputes concerning their own grievance processes.

 

Following the GAC appeal, X initiated a manual review of the case and verified the user’s account ownership. The platform subsequently restored access by allowing the account to be transferred to a new registered email address. What weeks of unsuccessful interaction with automated recovery systems could not achieve was ultimately resolved through the statutory appellate process.

 

What is the Vote Link Phishing Scam?

The scam uses fake award nominations, podcast opportunities, and voting campaigns to steal social media credentials. Messages are often sent from accounts belonging to friends, colleagues, academics, or other familiar contacts that have already been compromised. The message may claim that the sender or someone they know has been nominated for an award and needs votes. The details can be tailored to the recipient’s profession or interests. Reported examples include journalism awards, podcasting opportunities, Spotify-related voting campaigns, and community awards.

 

The message contains a link to a fake voting page. The page may copy the branding of a legitimate organisation but is hosted on an unrelated or fraudulent domain, made specifically for stealing user data. It presents a fake poll and asks the user to log in with X, Instagram, email, or another account. One reported version offered options to continue with Instagram, email, or X. Asking for credentials to a service unrelated to the vote is a key warning sign; for example, a Spotify-related vote should not require an X or Instagram password. Other warning signs include an unfamiliar domain and pressure to vote quickly.

 

In another incident reported to SFLC.in through RightsLine, aan X user received a message on June 20, 2026, from an academic they followed, claiming the academic had been nominated for a journalism award. The linked page asked for the user’s X username and password and then claimed an OTP would be sent, but no OTP arrived. Within about 12 hours, the user was locked out of the account, and the associated phone number and email address had been changed. The account recovery process then requested a confirmation code the user did not have. Similar phishing scams have also been reported in the USA .

 

After an account is compromised, it is used to send the same type of message to its followers. In the reported incident, the compromised account sent messages claiming that the account holder had been nominated for a podcasting award and asking recipients to vote. Some recipients were subsequently affected themselves. This allows the scam to spread through trusted accounts and their existing networks. Scammers may also create urgency by saying that voting is about to close, follow up with recipients who do not respond, or ask for a screenshot after the vote. These tactics can encourage people to act without checking the message or link.

 

Anatomy of a Scam

Most cyberattacks today do not begin with sophisticated malware or technical vulnerabilities. They begin with people. Social engineering refers to a class of attacks in which cybercriminals manipulate individuals into revealing sensitive information, clicking malicious links, or granting access to accounts and systems. Instead of attacking technology directly, these scams exploit trust, familiarity, and human behaviour.

 

A common form of social engineering is phishing, where attackers impersonate a trusted individual, organisation, or service through emails, text messages, phone calls, or social media. Increasingly, these messages are personalised. Attackers often research their targets, mimic legitimate communication styles, or compromise existing accounts to make fraudulent messages appear authentic. This makes modern phishing campaigns significantly more difficult to identify than the generic spam emails of the past.

 

The impact of these attacks extends far beyond individual users. In 2023, the cyberattacks on MGM Resorts and Caesars Entertainment demonstrated how a simple social engineering tactic could disrupt billion-dollar enterprises. According to Reuters, attackers associated with the Scattered Spider group gained initial access by impersonating employees and convincing IT helpdesk staff to reset login credentials.

 

In this Vote Link Phishing scam as well, the scammers relied on the victim’s social connections on X. Once an account was compromised, the attackers were able to use it to send direct messages to the account’s followers, making the phishing message appear to come from someone the recipients already knew and trusted. X also allows users to upload their address books and uses imported contact information, subject to users’ settings, to help people find and connect with others. A person’s account can appear as a suggested account to someone who has their phone number or email address in their contacts. These features are intended to facilitate connections, but they also illustrate how information about a person’s social and professional network can make social-engineering attacks more convincing.

 

The important privacy concern is therefore not simply that a platform allows users to send messages. It is that information about relationships, followers, contacts and activity can help an attacker identify people who are more likely to trust a compromised account. In a scam such as this one, the attacker’s advantage comes from being able to exploit an existing relationship rather than sending an obviously unsolicited message to a stranger.

 

There is also a question of how platforms respond once an account has been compromised. X identifies unexpected Direct Messages, changes to account information and unusual account activity as signs of a compromised account. It also says that email-address changes generate an alert to the previously used email address, allowing the account holder to attempt to regain control.

 

However, the reported incident illustrates the consequences when an attacker changes the recovery email address and phone number and the legitimate account holder is subsequently unable to access the account. The platforms should be able to detect and rapidly contain this kind of activity, not only for the individual whose account has been taken over, but also for everyone who receives messages from that account while it is under the attacker’s control.

 

While online platforms have invested heavily in automated systems to detect suspicious activity, account recovery often remains dependent on standardised workflows that may not adequately address cases involving identity theft or credential compromise. Effective grievance redressal therefore requires more than automated detection. It requires mechanisms capable of evaluating evidence, verifying identity through meaningful review, and providing users with accessible remedies when automated systems fall short.

 

How to Protect Yourself

  1. Be cautious of unexpected requests to vote for an award, podcast, competition, or community initiative, even if the message comes from someone you know. Check the full web address before entering any information and make sure it is the official website of the organisation mentioned in the message.
  2. Pay attention to what information the page asks for. If a voting page asks for your X, Instagram, or email password when those accounts are unrelated to the vote, do not proceed. Similarly, do not let messages such as “voting ends today” pressure you into acting without checking the link first.
  3. If a friend or colleague sends an unexpected voting request, contact them through another app or channel to confirm that they sent it. Their account may have been hacked. Do not send screenshots or other proof of having voted if the page or request seems suspicious.
  4. If you have entered your password on a suspicious page, change it immediately through the platform’s official website or app. If you use the same password elsewhere, change it there too. Check that your recovery email and phone number have not been changed, and review active sessions for anything unfamiliar.
  5. If you are locked out of your account, warn your contacts through another channel that messages from your account may contain a scam link.

For users, good digital hygiene remains the first line of defence. However, as social engineering techniques continue to evolve, strengthening platform accountability and ensuring effective grievance redressal will remain just as important as improving individual cybersecurity practices.