Supabase X Hack Recap - May 9 2025

1 min read Original article ↗
On May 9, 2025 our X account was hacked.
We're now in control of the account.
Here's a recap of what happened and what to watch out for:
- We received an email from an address "X Notice" with the subject line "Concern About Your Content, @supabase"
- The email was styled to look like an X notification and suggested our content was flagged
- There was a button in the email to appeal the flag--this was the phishing link
- Once the link was clicked and the password entered, the phisher gained access to our X account
- Once in the account, they turned off 2fa + attempted to add a delegate account + connected buffer + hootsuite + sent crypto spam tweets
- When we became aware of the hack we regained access to the account and have reset security settings + app access
If you see anything suspicious please ping Copple (https://x.com/kiwicopple) or me (https://x.com/CraigCannon)
Stay safe out there!