New Delhi: What do former ambassador Navtej Sarna and senior journalist Tavleen Singh have in common? They are both among several prominent Indians whose X accounts have been hacked over the past few weeks, with hackers using the profiles to post near-identical messages about investing in cryptocurrency.
The posts claim the account holder had been quietly investing in crypto and had made enough to buy a new car. They also said that they wanted to thank a coach tagged as @coach_hannahrae. Most of the posts carried a photo of a black Mercedes.
In each case, the account owner lost access to their profile and only learnt of it when followers began asking questions.
Quite simply, the attackers take over an X account with a large following and use its credibility to push cryptocurrency.
The account matters more than the message. Followers who would normally scroll past a crypto pitch from a stranger are far likelier to pay attention when it appears under the name of a former Indian ambassador or a veteran columnist.
Apart from the fake investment-coach story built around the @coach_hannahrae handle, in some versions, the hacked account promotes a newly minted “memecoin” and posts a wallet address for followers to buy it.
This isn’t the first time X accounts have been compromised in this manner.
In April, a wave of X account takeovers using a fake-DM method swept through Indian users, in a month that separately saw record crypto-theft losses worldwide. More than $600 million was stolen across nearly 30 incidents by crypto data aggregator DeFiLlama’s count.
In India, several popular handles were hijacked.
They include two widely followed commentators posting as Ramprasad_c and NAN_DINI_ (the latter under the name “Nandini”), who had the same @coach_hannahrae coach appearing on their timelines soon after.
They are not public officials but high-follower accounts in the country’s politically engaged commentary space, and their reach is exactly what made them worth stealing: a takeover instantly put the scam in front of a large, trusting audience. It spread further because each DM came from a mutual contact the victim already knew.
The method used each time is the same. The hackers mostly get in through phishing rather than a technical break-in.
In one version, the victim received a direct message from what appeared to be a genuine contact, asking them to vote for the sender in a competition and sharing a link. In another, the bait is an email about a supposed copyright violation, made to look like it came from X.
The link opens a fake login page, and once the victim enters their password and two-factor code, they are logged out, the account email is changed, and access is lost within seconds.
The account then begins posting crypto messages and sending the same DM to the victim’s contacts.
Two other methods are also used. One of them is SIM swapping, where fraudsters persuade a mobile operator to move a victim’s number to a SIM they control, allowing them to intercept one-time passwords.
This was how the US Securities and Exchange Commission’s account was breached in 2024.
In the second method, session hijacking, malware steals the token from an already logged-in session, a cookie that keeps a user signed in, and allows the attackers to skip the password and two-factor step entirely.
Also Read: Why telcos are opposing SIM blocking within 2-3 hours in digital arrests & other cyber fraud
Which accounts were hit?
The scam has hit several prominent Indians. Navtej Sarna, who served as India’s High Commissioner to the UK and Ambassador to the US and Israel, had his account post the “I bought a new car” message around Independence Day.
The post appeared just above his real posts about his book, which is how many of his followers realised something was wrong.
On 11 August, senior journalist Tavleen Singh’s account carried the same @coach_hannahrae message about buying a car.
Former Air Force chief Air Chief Marshal B.S. Dhanoa then highlighted the trend on X, and others in the thread noted that the account of K.B.S. Sidhu, a retired IAS officer who was Special Chief Secretary in Punjab, had also been hacked.
Past hacks
Indian public figures have been targeted for years. Veteran lyricist and screenwriter Javed Akhtar’s account was hacked in 2024. Tamil film actor Trisha Krishnan’s account was used in February 2025 to promote a fake coin called $KRISHNAN. The account of IPL franchise Delhi Capitals was taken over to push a token called $HACKER.
Scammers have also circulated a fake, BBC-branded article claiming businessman Anant Ambani had endorsed a crypto platform. In December 2021, an account linked to Prime Minister Narendra Modi posted a false claim that India had adopted Bitcoin as legal tender.
A separate Modi-linked handle was hacked earlier, in September 2020, when the account tied to his personal website and mobile app, @narendramodi_in, was used by a group calling itself “John Wick” to ask followers to donate to the PM National Relief Fund for Covid-19 in cryptocurrency such as Bitcoin and Ethereum.
The difference now is volume. Platforms such as Pump.fun, launched in 2024, have made it cheap to mint a worthless token in minutes, with no real project behind it and nothing to do but dump it on buyers. Off-the-shelf phishing kits have made it easy to hijack accounts on a large scale.
What is X doing about it
In April 2026, X’s then Head of Product, Nikita Bier, said the platform was building a system that would automatically lock an account and ask for verification the first time it posts about cryptocurrency.
Bier said this should “kill 99% of the incentive”, since a stolen account is of little use if it cannot post crypto without clearing an extra check.
Bier also blamed Google, saying Gmail was not filtering out the phishing emails before they reached users. His remarks followed a widely shared post by a UK creator, who described losing his account to a fake copyright email.
Bier has since left the company. He stepped down as head of product in early August 2026, a little over a year after taking the job, and said he would stay on as an adviser. X has not named a successor.
That leaves it unclear how far the promised crypto lock has actually been rolled out, how consistently it is being applied, and how well it works against determined attackers. The spate of hijacked Indian accounts this month suggests the problem is far from solved.
Security researchers advise moving away from SMS-based two-factor authentication towards an authenticator app, or a hardware security key or passkey. These are harder to defeat with SIM swaps or phishing, because they confirm they are dealing with the genuine site before logging a user in.
It also helps to be wary of any copyright-violation email or “vote for me” link in a DM, and to avoid entering an X password on any page reached by clicking a link.
(Edited by Sugita Katyal)
Click Here For The Original Source.
