Our X account was hacked today. We sent a message to an X employee two weeks ago after we suspected an attempt was made to compromise our account.
🧵 Here is what we know:
On March 5, a Telegram user sent us a valid link to an X post of ours in what we suspect to have been a social engineering technique to access our account.x.com
However, we noticed the link was formatted in a strange way. It was an official X Developer staging site using X's official domain, however it included a specific path and "token" query string which X links do not normally have.