{"id":49199,"date":"2023-10-12T08:28:42","date_gmt":"2023-10-12T12:28:42","guid":{"rendered":"https:\/\/www.kaspersky.com\/blog\/?p=49199"},"modified":"2023-10-12T08:36:15","modified_gmt":"2023-10-12T12:36:15","slug":"beware-of-twitter-blue-fake-accounts","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com\/blog\/beware-of-twitter-blue-fake-accounts\/49199\/","title":{"rendered":"Scammers with blue checkmarks on <s>Twitter<\/s> X"},"content":{"rendered":"<p>Since Elon Musk bought Twitter, there\u2019s been such a constant stream of changes on the social platform that it\u2019s been genuinely difficult to keep up \u2014 especially for those who don\u2019t spend all their free time on Twitter. One significant change that looks likely it\u2019s here to stay concerns X\u2019s account verification system \u2014 the notorious blue checkmarks. So let\u2019s investigate what has changed, what the unpleasant consequences are, and why you simply can\u2019t trust blue badges anymore.<\/p>\n<h2>Why you can\u2019t trust accounts with blue checkmarks anymore: scammers on <s>Twitter<\/s> X<\/h2>\n<p>Many users are not fully aware of what\u2019s happening with the account verification system on <s>Twitter<\/s> X, and continue to consider blue-badged accounts to be verified.<\/p>\n<p>Of course, scammers see this as a great opportunity. They target people using the social network to complain about the poor service of large companies such as hotel booking systems, airlines, banks, and so on. It used to be a fairly effective way to seek justice. Official, verified accounts of the companies responded to posts to help solve the problem, even if those posts had just a few likes and shares.<\/p>\n<p>Now, fraudsters can respond to the complaints of disgruntled customers from \u201cofficial\u201d profiles. After all, anyone can buy a blue checkmark, which until recently was a reliable indicator that you were dealing with a verified, official account. Scammers use these profiles to promise refunds and then, under this pretext, get their victims to reveal their financial data. Often, they <a href=\"https:\/\/www.which.co.uk\/news\/article\/fraudsters-exploit-easyjet-cancellations-aUK9Q4f7bPca\" target=\"_blank\" rel=\"nofollow noopener\">ask the user to provide a phone number<\/a> and then switch the communication to instant messengers and\/or voice calls.<\/p>\n<p>Recently, a <a href=\"https:\/\/www.theguardian.com\/technology\/2023\/aug\/27\/consumers-complaining-x-targeted-scammers-verification-changes-twitter\" target=\"_blank\" rel=\"nofollow noopener\">case was reported<\/a> in which a Booking.com customer, tired of waiting for a promised refund, decided to complain about the company on X. The customer received a response from an account pretending to belong to Booking.com support, inviting him to continue the conversation in private messages. The criminals then called the victim on WhatsApp and promised to refund the money through a \u201cpartner\u201d, for which the victim was asked to download a certain app.<\/p>\n<p>The fake Booking.com support account looked quite convincing. Only a couple of details gave the scammers away: an unexpected hyphen in the account name and the date of joining X \u2014 July 2023. Fortunately, the user suspected something was wrong in time; he stopped communicating with the criminals and contacted journalists, who incidentally ultimately helped him get a real refund from the booking platform. It\u2019s safe to assume that not all victims of scammers on ex-Twitter are so lucky.<\/p>\n<h2>What checkmarks and badges are now available on X?<\/h2>\n<p>It really isn\u2019t easy to make sense of what\u2019s been happening on the microblogging platform over the past year. Let\u2019s retrace how events unfolded with the infamous blue checkmark and the X Premium subscription:<\/p>\n<ul>\n<li>The Twitter Blue paid subscription concept was developed before the deal with Musk, and the idea of buying blue checkmarks was in no way planned. It was <a href=\"https:\/\/blog.twitter.com\/en_us\/topics\/company\/2021\/introducing-twitter-blue\" target=\"_blank\" rel=\"nofollow noopener\">launched in test mode<\/a> for users in Australia and Canada in June 2021, adding several useful features such as bookmark folders, Reader Mode, and the ability to edit tweets.<\/li>\n<li>In November 2022, shortly after the deal with Musk, Twitter <a href=\"https:\/\/www.businessinsider.com\/twitter-rolls-out-elon-musks-blue-check-verification-2022-11\" target=\"_blank\" rel=\"nofollow noopener\">launched a new version of Twitter Blue<\/a>, introducing the opportunity for anyone to get a blue checkmark. Additional <a href=\"https:\/\/www.theverge.com\/2022\/11\/10\/23452625\/twitter-verified-official-blue-gray-check\" target=\"_blank\" rel=\"nofollow noopener\">gray checkmarks<\/a> also appeared \u2014 these were given to verified accounts that had previously had blue checkmarks. However, this feature was quickly discontinued, since it deprived the paid blue check mark of any meaning (because it simply highlighted paid profiles).<\/li>\n<li>Due to an influx of fake accounts, Twitter Blue subscription purchases were blocked for a while. But this option <a href=\"https:\/\/www.forbes.com\/sites\/johnkoetsier\/2022\/12\/10\/twitter-blue-launches-monday-heres-whats-included\/?sh=207fb03371fa\" target=\"_blank\" rel=\"nofollow noopener\">reappeared<\/a> in December 2022 \u2014 this time with new gold and gray checkmarks added (but with completely different meanings \u2014 more on that below).<\/li>\n<li>For the next few months, accounts with blue checkmarks purchased as part of the Twitter Blue subscription coexisted alongside profiles that received the blue badge the traditional way \u2014 through verification.<\/li>\n<li>In April 2023, the platform began revoking \u201cold\u201d badges of verified accounts. However, it\u2019s not entirely clear whether they were revoked from all profiles. For example, Stephen King claimed that his blue checkmark remained, and was included in the number of Twitter Blue subscribers, although <a href=\"https:\/\/twitter.com\/StephenKing\/status\/1649147510525423626\" target=\"_blank\" rel=\"nofollow noopener\">he did not pay for it<\/a>.<\/li>\n<li>Finally, in July 2023, <a href=\"https:\/\/twitter.com\/lindayaX\/status\/1683353772917940225\" target=\"_blank\" rel=\"nofollow noopener\">Twitter was renamed X<\/a>, and got a new logo and address: x.com (at the time of writing this text, this address works along twitter.com). Meanwhile, the Twitter Blue subscription was renamed <a href=\"https:\/\/help.twitter.com\/en\/using-twitter\/twitter-blue\" target=\"_blank\" rel=\"nofollow noopener\">X Premium<\/a>.<\/li>\n<\/ul>\n<p>Confused? That\u2019s understandable. The rate of change on this platform is quite remarkable. So let\u2019s talk about what badges we\u2019re left with now on X, after all this turmoil.<\/p>\n<h3>Blue checkmark: means almost nothing<\/h3>\n<p>The blue checkmark next to a profile name basically means just one thing: this account has an active X Premium subscription. Most likely, the account owner paid for this subscription, although there may be some exceptions (like Stephen King).<\/p>\n<div id=\"attachment_49201\" style=\"width: 3010px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2023\/10\/12081005\/beware-of-twitter-blue-fake-accounts-1-scaled-1-scaled.jpg\"><img decoding=\"async\" aria-describedby=\"caption-attachment-49201\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2023\/10\/12081005\/beware-of-twitter-blue-fake-accounts-1-scaled-1-scaled.jpg\" alt=\"What does the blue checkmark mean on X?\" width=\"3000\" height=\"2317\" class=\"size-full wp-image-49201\"><\/a><p id=\"caption-attachment-49201\" class=\"wp-caption-text\">What the blue checkmark on X means: the account has an active X Premium (Twitter Blue) subscription<\/p><\/div>\n<p>So, <strong>the blue checkmark is no longer a guarantee that its owner can be trusted<\/strong>. It\u2019s just a premium account icon.<\/p>\n<h3>Gold checkmark: official accounts of commercial organizations<\/h3>\n<p>Simultaneously with giving out blue checkmarks to anyone who wants one, X has introduced a couple of other badges. <strong>Company accounts are now marked with a yellow icon <\/strong> (\u201cgold\u201d as they call it on the platform). Also, their profile picture is square-shaped (regular accounts still have round user pics).<\/p>\n<div id=\"attachment_49202\" style=\"width: 3010px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2023\/10\/12081049\/beware-of-twitter-blue-fake-accounts-2-scaled-1-scaled.jpg\"><img decoding=\"async\" aria-describedby=\"caption-attachment-49202\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2023\/10\/12081049\/beware-of-twitter-blue-fake-accounts-2-scaled-1-scaled.jpg\" alt=\"What does the yellow checkmark on X mean?\" width=\"3000\" height=\"2194\" class=\"size-full wp-image-49202\"><\/a><p id=\"caption-attachment-49202\" class=\"wp-caption-text\">What the yellow checkmark on X means: an official company account<\/p><\/div>\n<p>This subscription type is called <a href=\"https:\/\/help.twitter.com\/en\/using-twitter\/verified-organizations\" target=\"_blank\" rel=\"nofollow noopener\">X Verified Organizations<\/a> and costs much more \u2014 $1000 per month versus $8 for blue X Premium profiles. A \u201cgold\u201d business account can add other profiles to its list of affiliates and get blue, yellow, or gray badges for them. These cost an additional $50 for each affiliated account.<\/p>\n<h3>Gray checkmark: accounts of government organizations and officials<\/h3>\n<p><strong>The blueish-gray checkmarks in the current X color scheme indicate accounts of state and supranational organizations as well as their officials.<\/strong><\/p>\n<p><\/p><div id=\"attachment_49203\" style=\"width: 3010px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2023\/10\/12081126\/beware-of-twitter-blue-fake-accounts-3-scaled-1-scaled.jpg\"><img decoding=\"async\" aria-describedby=\"caption-attachment-49203\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2023\/10\/12081126\/beware-of-twitter-blue-fake-accounts-3-scaled-1-scaled.jpg\" alt=\"What does the gray checkmark on X mean?\" width=\"3000\" height=\"2254\" class=\"size-full wp-image-49203\"><\/a><p id=\"caption-attachment-49203\" class=\"wp-caption-text\">What the gray checkmark on X means: a government organization account<\/p><\/div><br>\nIf the account with the gray checkmark is for an organization, the account gets a square-shaped user pic, while for individuals it\u2019s still round.\n<div id=\"attachment_49204\" style=\"width: 3010px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2023\/10\/12081157\/beware-of-twitter-blue-fake-accounts-4-scaled-1-scaled.jpg\"><img decoding=\"async\" aria-describedby=\"caption-attachment-49204\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2023\/10\/12081157\/beware-of-twitter-blue-fake-accounts-4-scaled-1-scaled.jpg\" alt=\"What does the gray checkmark on X mean?\" width=\"3000\" height=\"2238\" class=\"size-full wp-image-49204\"><\/a><p id=\"caption-attachment-49204\" class=\"wp-caption-text\">What the gray checkmark on X means: an official figure\u2019s account<\/p><\/div>\n<h3>Logo icon: accounts affiliated with companies<\/h3>\n<p>Besides the checkmark next to the profile name, it\u2019s now also possible to add the logo of the organization the account is affiliated with. <\/p>\n<div id=\"attachment_49205\" style=\"width: 3010px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2023\/10\/12081237\/beware-of-twitter-blue-fake-accounts-5-scaled-1-scaled.jpg\"><img decoding=\"async\" aria-describedby=\"caption-attachment-49205\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2023\/10\/12081237\/beware-of-twitter-blue-fake-accounts-5-scaled-1-scaled.jpg\" alt=\"What does the logo icon next to the account name on X mean?\" width=\"3000\" height=\"2246\" class=\"size-full wp-image-49205\"><\/a><p id=\"caption-attachment-49205\" class=\"wp-caption-text\">What the logo icon next to the name on X means: the account is affiliated with a company<\/p><\/div>\n<p>However, for some reason, profiles of government organizations (the ones with gray checkmarks) cannot add affiliated accounts. So, for example, the account of the head of Microsoft is affiliated with the account of the company itself. But the account of the UN Secretary-General is unfortunately in no way connected with the account of the UN itself.<\/p>\n<div id=\"attachment_49206\" style=\"width: 3010px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2023\/10\/12081316\/beware-of-twitter-blue-fake-accounts-6-scaled-1-scaled.jpg\"><img decoding=\"async\" aria-describedby=\"caption-attachment-49206\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2023\/10\/12081316\/beware-of-twitter-blue-fake-accounts-6-scaled-1-scaled.jpg\" alt=\"What does the logo icon next to the account name on X mean?\" width=\"3000\" height=\"2242\" class=\"size-full wp-image-49206\"><\/a><p id=\"caption-attachment-49206\" class=\"wp-caption-text\">For some reason, government organizations are not allowed affiliate accounts<\/p><\/div>\n<h2>How to protect yourself from scammers on X<\/h2>\n<p>Unfortunately, the new system of multi-colored paid checkmarks on X is quite confusing. <\/p>\n<p>Let\u2019s take the example of Microsoft to illustrate. There are various Microsoft departments and projects with X accounts marked with gold checkmarks, but none of them are affiliated with the main company account. Among the affiliated profiles are top Microsoft executives, but you won\u2019t find @Windows or @Microsoft365 there.<\/p>\n<div id=\"attachment_49207\" style=\"width: 3010px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2023\/10\/12081346\/beware-of-twitter-blue-fake-accounts-7-scaled-1-scaled.jpg\"><img decoding=\"async\" aria-describedby=\"caption-attachment-49207\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2023\/10\/12081346\/beware-of-twitter-blue-fake-accounts-7-scaled-1-scaled.jpg\" alt=\"X accounts affiliated with the Microsoft X account\" width=\"3000\" height=\"2346\" class=\"size-full wp-image-49207\"><\/a><p id=\"caption-attachment-49207\" class=\"wp-caption-text\">The list of accounts affiliated with the Microsoft X account only includes the company\u2019s top executives<\/p><\/div>\n<p>The genuine Microsoft tech-support X account \u2014 @MicrosoftHelps \u2014 is not affiliated with the main @Microsoft account or any of the others. What\u2019s more, this X account (of one of the world\u2019s largest technology companies) has no checkmark at all \u2014 not even a blue one!<\/p>\n<div id=\"attachment_49208\" style=\"width: 3010px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2023\/10\/12081423\/beware-of-twitter-blue-fake-accounts-8-scaled-1-scaled.jpg\"><img decoding=\"async\" aria-describedby=\"caption-attachment-49208\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2023\/10\/12081423\/beware-of-twitter-blue-fake-accounts-8-scaled-1-scaled.jpg\" alt=\"Official Microsoft technical support account\" width=\"3000\" height=\"2330\" class=\"size-full wp-image-49208\"><\/a><p id=\"caption-attachment-49208\" class=\"wp-caption-text\">The genuine support account @MicrosoftHelps has no checkmarks and is not affiliated with any other account of the company<\/p><\/div>\n<p>Because of this confusion, it\u2019s difficult to give clear advice on how to verify the authenticity of X accounts. Therefore, here are a few general considerations:<\/p>\n<ul>\n<li>Accounts with blue checkmarks should not be trusted. Anyone can buy this badge now, and the verification process seems to be quite superficial.<\/li>\n<li>Profiles with gold or gray checkmarks are more reliable on paper \u2014 obtaining these badges is definitely more expensive, and the verification is probably more thorough. But the chaos on the platform gives plenty of reasons to doubt their reliability.<\/li>\n<li>Perhaps the most useful indicator of a profile\u2019s authenticity is the creation date \u2014 this cannot be bought (at least, yet). If a profile was created a long time ago, there\u2019s some reason to trust it (although it\u2019s important to remember that a profile can always be renamed). Recently created \u201cofficial accounts\u201d, on the other hand, are very suspicious even with colored checkmarks.<\/li>\n<li>In any case, you shouldn\u2019t give financial information to anyone on X, \u201cemployees\u201d of some company or not; whoever requested it is highly likely a scammer, and it\u2019s best to shut down all communication with them.<\/li>\n<\/ul>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"premium-generic\">\n","protected":false},"excerpt":{"rendered":"<p>Fraudsters are buying blue checkmarks to impersonate well-known brands on X (ex-Twitter) and scam users.<\/p>\n","protected":false},"author":2726,"featured_media":49200,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[2683],"tags":[80,726,97,4247,422,83],"class_list":{"0":"post-49199","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-threats","8":"tag-fraud","9":"tag-scam","10":"tag-security-2","11":"tag-social-networks","12":"tag-threats","13":"tag-twitter"},"hreflang":[{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/beware-of-twitter-blue-fake-accounts\/49199\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/beware-of-twitter-blue-fake-accounts\/26354\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/beware-of-twitter-blue-fake-accounts\/21787\/"},{"hreflang":"ar","url":"https:\/\/me.kaspersky.com\/blog\/beware-of-twitter-blue-fake-accounts\/11099\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/beware-of-twitter-blue-fake-accounts\/26637\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/beware-of-twitter-blue-fake-accounts\/26756\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/beware-of-twitter-blue-fake-accounts\/29248\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/beware-of-twitter-blue-fake-accounts\/28102\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/beware-of-twitter-blue-fake-accounts\/36249\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/beware-of-twitter-blue-fake-accounts\/21093\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/beware-of-twitter-blue-fake-accounts\/21888\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/beware-of-twitter-blue-fake-accounts\/30579\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/beware-of-twitter-blue-fake-accounts\/34969\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/beware-of-twitter-blue-fake-accounts\/26924\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/beware-of-twitter-blue-fake-accounts\/32641\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/beware-of-twitter-blue-fake-accounts\/32295\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com\/blog\/tag\/twitter\/","name":"twitter"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/49199","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/users\/2726"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/comments?post=49199"}],"version-history":[{"count":1,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/49199\/revisions"}],"predecessor-version":[{"id":49209,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/49199\/revisions\/49209"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media\/49200"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media?parent=49199"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/categories?post=49199"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/tags?post=49199"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}