X (Twitter)

X DM scams: the fake reporter, and how to spot the rest

Published
Read
4 min
Also called
  • Fake reporter DM
  • Fake interview scam
  • Media impersonation
  • Twitter DM phishing

The short answer

If a reporter DMs you for an interview and the scheduling link asks you to sign in with Google, it is a scam. A real interview never needs your password, and a real video call never needs you to install anything.

On 5 August 2026, communications adviser Lulu Cheng Meservey posted a warning about a DM she’d just received. It has been seen more than eighty thousand times, which tells you roughly how many people recognised it.

Watch out for this scam where a fake reporter (usually claiming to be with Bloomberg or TechCrunch) asks to interview you. A lot of founders have gotten these

The idea is: the target gets excited to be featured in an article, they respond, they’re invited to schedule an interview, then apparently there’s some kind of calendar page that asks for a google login

Here is the message she got, exactly as it arrived.

Message request on X@juhierubyBlue check · 30m ago

tell 1: Ruby representing @Bloomberg here,

tell 2: Lulu, My team and I are writing an upcoming article tell 3: exploring how AI is reshaping the relationship between technology companies, the public, and the media. tell 4: Given your expertise & presence in the space, we believe your insights would help us craft a piece that our readers would truly appreciate.

Let me know if you're interested, you can reach me here directly on X or via email at tell 5: (Ruby@bloomberg.com)

  1. 1Reporters write for a publication, they don't represent it — "representing" is how agencies and brand partnerships talk. And it's a first name only — there is no surname here to check against Bloomberg's masthead, which is the one check that would end this in seconds.
  2. 2A capital M in the middle of a sentence. Beyond the sloppiness: stories carry an individual byline and an editor, not a "team", and a real correspondent names the desk they're on.
  3. 3A subject broad enough to send to ten thousand people without changing a word. Real pitches carry an angle, a deadline, and a reason it's you and not somebody else.
  4. 4This clause and the two that follow it contain no information at all. Between them they never name one thing you have said, built or done — because whoever sent this doesn't know.
  5. 5An email address typed into a DM is a claim, not evidence — anyone can type anything. The check that works runs the other way: find the address on the outlet's own site and start a fresh email there instead.
Verbatim from the screenshot Lulu Cheng Meservey published on 5 August 2026. Highlighting added.

The profile that sent it

The message is competent enough. The profile is where it falls apart — and it’s also the part you can check before you’ve replied to anything.

The profile behind it@juhierubyBio and stats as shown

tell 1: Correspondent @Bloomberg, covering business, Startups, AI, Crypto @Opinion
NY · tell 2: Joined January 2010
tell 3: 1.1K Following · 1K Followers

  1. 1The claim the whole thing rests on, and it's checkable in about five seconds — against Bloomberg's own masthead, never against the profile making the claim.
  2. 2Sixteen years old. Paired with the follower count below, that's the signature of an account that was bought or taken over rather than built for the job — and an old join date sails straight past the instinct that says "brand new account, be careful."
  3. 3A Bloomberg correspondent covering AI and crypto, followed by a thousand people and following about as many back. Working reporters are followed far more than they follow.
From the same screenshots. The strongest signals in this scam are on the profile, not in the message.

One caveat worth stating plainly: an account with a 2010 join date and a real-looking posting history was very likely taken over or bought rather than created for this. If so, whoever originally built it is a victim here too, not the person writing these DMs.

How it plays out

The interview is scenery. Every element of the first message exists to get a reply.

  1. It arrives as a message request

    Not from someone you follow. The account has a blue check, a plausible bio, a believable posting history and an old join date, so the profile survives the half-second glance most people give it.

  2. You reply, because replying costs nothing

    This is the entire purpose of the first message. A reply confirms a real, interested human is on the other end — which is what makes you worth spending a second message on.

  3. You're invited to schedule the interview

    The second message carries the link: a calendar page to pick a slot. It looks like the most ordinary thing in the world, because booking a time is what actually happens next with a real reporter.

  4. The calendar page asks for a Google login

    This is the whole scam, and the step Meservey's warning points at directly. The sign-in screen is a copy. What it takes is not only the password but the session token, which is why enabling two-factor afterwards doesn't undo it.

  5. What they were actually after

    Never the interview. Mailbox access, a live session, or a foothold on a company laptop — used for the next move or resold. Security researchers tie this pattern to groups working their way into crypto and cloud companies.

The variant that skips the password

The Google login is the branch Meservey’s warning describes. A second branch has been catching people this year without asking for anything that feels like a secret.

You join the call. Your audio doesn’t work, or theirs doesn’t. A prompt appears — often a convincing copy of the real thing — saying your client needs an update or a driver, with a file to run. Researchers call this ClickFix: rather than stealing a credential, the attacker gets you to perform the installation yourself, which walks past most of the protections built to stop downloads you didn’t ask for.

Malwarebytes documented a campaign in February 2026 doing exactly this from a fake Zoom meeting page, quietly installing commercial monitoring software on Windows machines. The same shape turns up in fake recruiter calls aimed at crypto companies, sometimes with a deepfaked executive on the far end of the video holding the story together.

The tell is structural rather than visual: a real video call never needs you to install something to fix audio mid-meeting. Zoom, Meet and Teams all update themselves and all run in a browser. If the audio dies, the fix is to leave and rejoin on the web, and any genuine person on the other end will wait.

The five-second checks

The first two cost nothing and catch nearly everything.

  • Check the masthead. Search the outlet’s staff directory for the name — the outlet’s own site, not the person’s X profile. TechCrunch, which has been warning about impersonators using domains like email-techcrunch[.]com and techcrunch[.]ai since March, puts it bluntly: if the name isn’t on the roster, you have your answer.
  • Reply somewhere else. Write to the address on their staff page instead of answering the DM. A real reporter answers. A scammer never sees it.
  • Read the domain right to left. The owner is the last two parts before the first slash. techcrunch.ai is not TechCrunch, and bloomberg-interviews.media would not be Bloomberg.
  • Ask one specific question. What’s the angle, who else are you speaking to, when does it run? Real answers are boring and immediate.
  • Refuse to install anything, ever. No legitimate interview requires new software.

The other DM scams doing the rounds

The fake reporter is one shape. On X the same machinery gets pointed at different pretexts, and the move underneath is always to get you off X and onto a page that asks you to sign in:

  • The account emergency. A DM or reply says your account has a copyright strike or is about to be suspended, with an appeal form. The form is a login page. X does not handle appeals over DM.
  • The recruiter. A job paying well for work you already do, with a take-home assignment or a “candidate portal” to install. Common against developers, and the assignment is the payload.
  • The support agent. You post publicly about a problem with an exchange, a wallet or a bank, and someone helpful DMs you within minutes. Nobody legitimate arrives that fast, and none of them need your seed phrase or a screen-share.
  • The recovery service. Aimed at people already scammed once, promising to get the money back for a fee. It never comes back, and lists of previous victims get resold precisely because a second hit is easier than a first.
  • The warm stranger. A months-long friendly conversation that eventually arrives at an investment platform showing excellent returns, right up until a withdrawal is attempted.

The pretexts are interchangeable. The request is always the same one.

Why this keeps working

It isn’t gullibility. The fake reporter DM targets a real ambition — being written about — and then leans on ordinary professional courtesy to move you along. Not wanting to keep a journalist waiting is the same instinct that gets someone to install a “Zoom update” without thinking. Every step asks for something small, and each one is only reasonable given the step before it.

The way out is to break the chain somewhere that costs you nothing. Checking a byline against the masthead takes five seconds and has never once offended a real reporter. If they’re genuine, you’ve lost nothing. If they aren’t, you’ve just kept them out.

Common questions

People also ask

Do real reporters actually send cold DMs on X?

Yes, constantly — which is exactly why this works. A cold DM is not itself suspicious. What separates a real one is that it names a specific story and never routes you through a link that asks you to sign in to anything.

How do I check whether a reporter is real?

Look the name up on the outlet's own staff page, then contact them at the address listed there rather than replying in the DM. If they're real, a note to their published address costs you nothing. If they aren't, you never touched the link.

Does a blue check mean the account is genuine?

No. A check is a paid subscription, not a verification of identity. The account in this case had a check, a detailed bio and a join date going back to 2010 — old, established accounts get compromised and repurposed precisely because they look trustworthy.

I clicked the link but didn't type anything. Am I compromised?

Almost certainly fine. Loading a phishing page does not by itself hand over an account. The risk starts when you enter credentials, approve a login prompt, grant an app access, or run a downloaded file. If you did none of those, close the tab and move on.

Why would a scammer want to interview me specifically?

They don't want the interview. They want whatever your login reaches — a company mailbox, a cloud console, a wallet, or a laptop inside a network worth selling access to. Founders and early employees are targeted because their accounts sit close to all four.