Secure Your X (Twitter) Account in Five Steps

Secure Your X (Twitter) Account in Five Steps

A five-step X account security guide covering two-factor authentication, active sessions, connected apps, phishing and recovery.

This third guide in our five-step account security series covers X (formerly Twitter). Protecting the account means checking both new sign-ins and access that may already exist through sessions or connected applications.

1. Strengthen sign-in and recovery

In Settings and privacy, open Security and account access, then Security and Two-factor authentication. X lists an authentication app and a security key among its available methods; choose a method you can use reliably and keep any backup code in a secure place. An authenticator app avoids dependence on text message delivery. Follow the current steps in X's two-factor authentication guide.

Use a long, unique password for X and secure the email account used for recovery. If password reset protection is available in your account settings, review it as another safeguard. Neither a password change nor 2FA should be assumed to end every existing application session automatically.

2. Review active sessions and devices

Open Apps and sessions in X settings and inspect where the account is signed in. Sign out sessions you do not recognize and those on devices you no longer use. A changing IP address alone does not prove compromise; review the device, time and your own activity together. If you see actions you did not authorize, change the password from a trusted device and follow X's compromised-account guidance.

3. Revoke unnecessary app access

Review connected third-party apps and the permissions each app can use. Revoke access for apps you no longer need or do not recognize, including services that promise follower growth or information about profile visitors. X's app and session guidance explains where to review these connections. If a service asks for your X credentials, check the destination carefully before entering anything.

4. Treat urgent messages as phishing attempts

Messages that claim your account will be suspended, that a complaint has been filed, or that you must verify a badge can be attempts to steal credentials. Do not use the message's link to sign in. Open X directly by typing x.com into your browser, then check for the notice in your account. Look at the complete hostname before entering a password or code; a name that merely contains “x” or “support” is not proof that a site belongs to X.

5. Protect the device and respond to suspicious access

Keep the browser, operating system and security software current. Malware can steal stored passwords or session cookies, so a stolen, still-valid session may remain a concern even when 2FA is enabled. Avoid signing in on devices you do not trust. If the account shows unauthorized activity, review sessions and app grants, secure the linked email account, change credentials from a trusted device and contact X support if access cannot be recovered.

A LeakData match can prompt a closer look at exposed credentials or related account activity. It is not, on its own, proof that someone has entered your X account.