Cybercrime

Hacked Mandiant X Account Abused for Cryptocurrency Theft

Mandiant’s account on X, formerly Twitter, was hacked and used to lure users to a cryptocurrency phishing site.

Mandiant’s account on X, formerly Twitter, was hacked and used to lure users to a cryptocurrency phishing site.

Mandiant’s account on the social media platform X, formerly Twitter, was hacked on Wednesday and abused to lure users to a website designed to steal cryptocurrency from victims. 

The account of Mandiant, which is part of Google Cloud, was renamed to ‘Phantom’ and its profile image and description were updated to appear affiliated with the legitimate Phantom cryptocurrency wallet.

Messages posted on the hijacked account promoted a website hosted at claim-phntm.com, which claimed to distribute cryptocurrency tokens through an airdrop. In reality, the site is designed to steal users’ cryptocurrency. 

The hacked account was later used to troll the cybersecurity firm, telling it to change its password.

Mandiant immediately took action to recover the account, but the hacker regained control at one point during the recovery process. 

Researchers at MalwareHunterTeam, who have been monitoring the incident, noted that it did not take Mandiant long to recover the account, considering that it has taken some X users days or even more to regain complete control of their account following a hacker attack.

While the hacker posted a message urging Mandiant to change its password, in many cases social media account hijacking involves abusing a third-party service rather than a direct attack on the account. 

Advertisement. Scroll to continue reading.

SecurityWeek has reached out to Mandiant for more information and will update this article if the company provides additional details.  

Major web browsers currently flag the domain promoted by the hacker as a potential phishing site. 

This incident occurred just as cybersecurity company CloudSEK published a report on X Gold accounts being sold on the dark web, in some cases for thousands of dollars. These accounts can be highly useful for phishing, disinformation and other types of campaigns.

Update: Mandiant told SecurityWeek that it’s investigating the incident.

“We are aware of the incident that impacted the Mandiant X account and are conducting a thorough investigation. We’ve since regained control and the account has been restored,” said a Mandiant spokesperson.

Related: Ukraine Cracks Down on Group Selling Hacked Accounts to Pro-Russia Propagandists

Related: Targeted Links Used to Steal Tens of Millions in Global Scam Campaign

Related: Indian PM’s Twitter Hacked Again by Crypto Scammers

Related Content

Cybercrime

Hackers used the account, which has 13 million followers, to amplify a Clippy-themed cryptocurrency account.

Cybercrime

The account was compromised over the weekend and Elmo’s 650,000 followers were given antisemitic threats and a reference to the Jeffrey Epstein investigation.

Cybercrime

Eric Council Jr. was sentenced to prison for hacking SEC’s official X account and publishing fraudulent posts increasing Bitcoin value.

Cybercrime

US officials have not determined who was behind an apparent cyberattack on the social media site X that limited access to the platform for...

Network Security

Information is coming to light on the cyberattack that caused X outages, but it should be taken with a pinch of salt.

Network Security

Elon Musk claimed that the social media platform X was being targeted in a “massive cyberattack" that impacted availability.

Cybercrime

Eric Council Jr. pleaded guilty to hacking the X (formerly Twitter) account of the US Securities and Exchange Commission.

Cybercrime

An Alabama man has been arrested over his role in the hacking of the SEC's X account, which led to a Bitcoin price spike.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version