---
title: "I fell for a phishing attack and lost access to my X account. Here are five mistakes I did that you need to avoid!"
url: https://daily.dev/posts/i-fell-for-a-phishing-attack-and-lost-access-to-my-x-account-here-are-five-mistakes-i-did-that-you--cfsxn3pdx
source_url: https://christianheilmann.com/2026/02/22/i-fell-for-a-phishing-attack-and-lost-access-to-my-x-account-here-are-five-mistakes-i-did-that-you-need-to-avoid/
type: article
source: "Christian Heilmann"
published: 2026-02-22T11:58:15.370Z
updated: 2026-02-22T11:58:36.331Z
tags: ["security", "authentication", "phishing"]
reading_time: 8
upvotes: 7
comments: 2
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# I fell for a phishing attack and lost access to my X account. Here are five mistakes I did that you need to avoid!

**[Christian Heilmann](https://daily.dev/sources/christianheilmann)** · 8 min read · 7 upvotes · 2 comments

## Summary

A developer with 20 years on Twitter/X shares a personal account of falling for a sophisticated phishing attack that resulted in losing access to their account. The post details five key mistakes: acting in a rush during a security task, not scrutinizing a convincing phishing email, failing to check the sender address or link URL, ignoring the browser autofill not triggering on the fake login form, and not having an authenticator app set up. The attacker quickly changed the account email and locked the victim out. Practical takeaways include always verifying sender and URL, treating missing autofill as a red flag, and using an authenticator app rather than SMS-based 2FA.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://christianheilmann.com/2026/02/22/i-fell-for-a-phishing-attack-and-lost-access-to-my-x-account-here-are-five-mistakes-i-did-that-you-need-to-avoid/>

## Community discussion

Top comments from developers on daily.dev.

**@fabianletsch** · 0 upvotes

> Wow that was an impressive attack!
>
>
> I would argue one more thing that too many people get wrong:
>
>
> Stop using the same damn password for everything!!!!!

**@stuartgreig** · 0 upvotes

> What would of saved you is having two factor setup in the first place. I don't understand why these sites don't force you to enable it

## Similar posts on daily.dev

- [I fell for a phishing mail and lost access to Twitter/X ?](https://daily.dev/posts/i-fell-for-a-phishing-mail-and-lost-access-to-twitter-x--sghyafznr) · Christian Heilmann · 1 upvotes · 1 comments
- [New X phishing scam copies real login alerts down to the pixel to hijack accounts](https://daily.dev/posts/new-x-phishing-scam-copies-real-login-alerts-down-to-the-pixel-to-hijack-accounts-t40pio7ve) · The Next Web · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#authentication](https://daily.dev/tags/authentication), [#phishing](https://daily.dev/tags/phishing)

[View this post on daily.dev](https://daily.dev/posts/i-fell-for-a-phishing-attack-and-lost-access-to-my-x-account-here-are-five-mistakes-i-did-that-you--cfsxn3pdx)
