They Came through a Friend’s Door: How My X Account Was Hijacked — and What You Must Know
KBS Sidhu 10 June 2026
I was the one that let the Trojan Horse in.
 
It began with a message from a friend. A DM on my X (formerly Twitter) account.
 
Not an anonymous email from a Nigerian prince. Not a suspicious link from an unknown number. A direct message on X (formerly Twitter) from someone I know personally — a well-regarded individual in my network — saying he was competing for an “online ambassadorship” and requesting my vote. He sent a link. I clicked it.
 
That single click cost me my Twitter account.
 
I am writing this not out of embarrassment — though there is some of that — but out of a sense of obligation to the nearly 50,000 people who follow me on X and the 5,000 readers of this Chronicle. If a retired IAS officer, also a good-old electronics engineering graduate, who has spent decades navigating institutional complexity, and who is currently writing on cybersecurity vulnerabilities in India’s digital public infrastructure, can be taken in by this trap, so can you. So can anyone. And if you need a measure of the irony: my elder son, a technology entrepreneur based in the United States, has spent years hammering one instruction into the heads of both his parents — do not click on any external links, irrespective of where they arrive, whether on your mobile, WhatsApp, or any other app. I had heard him. I had nodded. And then I clicked.
 
The Anatomy of the Attack
Let me be precise about what happened, because the devil is entirely in the details.
 
The link did not take me to a voting page. It took me to what appeared to be a standard OAuth login screen — the familiar “Sign in with X” interface, complete with the correct fonts, the correct colours, the correct layout. I chose to log in with my Twitter ID. The moment I clicked “Allow,” it was over.
 
What I had done, without knowing it, was hand the attackers an OAuth authentication token. This is not a password. It is something more insidious: a session-level credential that tells a connected application — in this case, my X account — that the user has already been verified. Two-factor authentication, which I had enabled, was rendered completely irrelevant. I had already authenticated. The attacker simply walked through the door I had inadvertently opened.
 
Within minutes, my account was theirs. But they did not stop there. With professional precision, they de-linked my registered email address from the X account. This was the masterstroke. Account recovery on X depends on email verification. Remove the email, and the legitimate owner — me — is locked out of the standard recovery pathway. X, astonishingly, permitted this de-linking without sending a confirmation to the email being removed, and without an SMS to the mobile number registered for two-factor authentication. The platform’s own security architecture became the instrument of my exclusion.
 
The attackers then did what all good operators do with a newly acquired asset: they exploited it. Automated messages went out to contacts in my DMs, each one carrying the same lure — “KBS Sidhu is competing for an international ambassadorship of influencers, please vote.” Simultaneously, posts appeared on my timeline claiming I had made millions using a cryptocurrency advisor, complete with links to further traps. My identity, my credibility, my network — all were being monetised in real time.
 
When I eventually recovered the account and scrolled through my DMs, I found at least a score of similar messages from other accounts — each one a mirror of what had been sent in my name. Clear evidence that my contacts had themselves been hacked through the same mechanism, possibly even through a message that appeared to come from me.
 
The Human Factor: Why Smart People Click
I want to dwell on this for a moment, because the instinct is to say: how could you fall for it?
 
The honest answer is: because it did not look like a trap.
 
The message came from a real person I know. The interface I was taken to looked exactly like Google’s login page — not a crude imitation, but a pixel-perfect replica. There was no spelling error, no suspicious domain name visible in the moment of decision, no red flag that the trained eye would catch in a fraction of a second. These are not amateur hour phishing attempts. These are professional operations, run by technically sophisticated actors who understand social engineering as well as they understand code.
 
They exploit the foundational trust we place in our networks. We are conditioned to be suspicious of strangers. We are not conditioned to be suspicious of friends. That asymmetry is precisely what they weaponise.
 
What X Must Answer For
I will not let the platform off the hook.
 
X’s decision to allow the de-linking of a registered email address — without sending a confirmation to that address, and without an SMS to the two-factor authentication mobile number — is not a minor oversight. It is a serious security design failure. The two-factor system exists precisely to prevent unauthorised account changes. Bypassing it silently, in order to accommodate what turned out to be a malicious actor’s request, undermines the entire architecture of account security.
 
In India, where X has tens of millions of users, many of them public figures, journalists, officials, and opinion leaders, this is not a trivial matter. The platform has regulatory obligations under the Information Technology Act and the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021. Account security is not optional compliance. It is a core duty.
 
I have raised this with X’s support process. It is lengthy. It requires screenshots, applications, and patience. In the meanwhile, the hacker operates.
 
The Larger Warning: India’s Digital Vulnerability
This incident is a microcosm of a larger problem I have been examining in the context of India’s digital public infrastructure — the UPI ecosystem, the Aadhaar-linked payment rails, the RBI’s regulatory perimeter around fintech. We have built remarkable architecture. We have not always built a commensurate security culture.
 
The vulnerability here is not primarily technical. OAuth is a legitimate and generally secure protocol. The vulnerability is human: the willingness to click, the trust placed in familiar faces, the absence of a moment’s hesitation before granting an application access to one’s digital identity. No amount of two-factor authentication can protect an account whose owner has been socially engineered into handing over the keys.
 
India’s digital literacy programmes must urgently incorporate threat literacy — not just how to use a smartphone, but how to recognise when a smartphone is being used against you.
 
One Word of Advice — and a Checklist
I promised one word of advice, and I will keep that promise: Don’t.
 
Do not click on hyperlinks — even when they appear to come from people you know and trust. Especially then. A hacked account is indistinguishable from a real one. The message will sound like your friend. The request will seem reasonable. The link will look legitimate. Do not click.
 
If you suspect you have already clicked on something suspicious, act immediately:
Go to your Google account, navigate to Security, and revoke access for any unfamiliar third-party applications. On X, go to Settings, then Security, then Apps and Sessions, and terminate all active sessions you do not recognise. Change your passwords on both platforms from a device you trust. And warn your contacts — not through the platform that may have been compromised, but through WhatsApp, phone, or any other channel — before they receive a message that appears to come from you.
 
A Final Word
I retrieved my account. The process was slow and the indignity was real. But the experience has sharpened something I already knew intellectually and now know viscerally: in the digital world, trust is the attack surface.
 
The friend whose account was used to send me that first message had no idea. He, too, had been taken in, probably by a message that appeared to come from someone he trusted. That is how these chains propagate — link by link, friend by friend, institution by institution, until an entire network has been compromised and nobody is quite sure where it began.
 
Stay alert. Stay sceptical. And — I cannot say this enough — do not click.
 
 
 
(Karan Bir Singh (KBS) Sidhu is a retired IAS officer and former Special Chief Secretary, Government of Punjab. He holds a Master’s degree in Economics from the University of Manchester, UK. He writes at the intersection of global trade negotiations, Trump-era tariff shocks, and contemporary geopolitics.)
Comments
Govt Cuts Subsidised Ujjwala LPG Refills to 4 from 9 amid Rising Global LPG Costs
Moneylife Digital Team 09 June 2026
The Union government has reduced the number of subsidised liquefied petroleum gas (LPG) refills available under the Pradhan Mantri Ujjwala Yojana (PMUY) from nine cylinders a year to four, citing mounting pressure on supplies and...
LPG Price Hiked by ₹29 Again; Opposition Slams Modi Govt as Households Feel Inflation Heat
Moneylife Digital Team 08 June 2026
Domestic LPG prices have been raised by ₹29/cylinder, marking the second increase in three months and drawing criticism from opposition parties. The Union government has defended the hike, citing a sharp rise in global LPG prices and...
FirstCry Slapped with ₹55,000 Order after Court Finds It Tagged Customer 'Fraud' without Inquiry
Moneylife Digital Team 06 June 2026
A district consumer disputes redressal commission has ruled against online baby products retailer FirstCry, directing the company to pay ₹50,000 as compensation, refund ₹2,130 with interest, and bear ₹5,000 in litigation costs — after...
50% of Owners of Older Petrol Vehicles Want Return of E0/E10 Fuel; Many Report ₹5,000-₹25,000 Extra Costs after E20 Rollout: LocalCircles
Moneylife Digital Team 05 June 2026
More than half of owners of petrol vehicles purchased in 2022 or earlier want the option to switch back to lower-ethanol petrol blends, with many reporting higher fuel expenses and increased repair costs since the nationwide rollout...
Free Helpline
Legal Credit
Feedback