Overview
- Attackers used the hijacked session to post scam cryptocurrency links from his personal account.
- Two‑factor authentication was active and prevented a full account takeover, according to Kamath.
- The message closely imitated an X security alert, citing a supposed login from Delhi on a Chrome desktop.
- Kamath said the email reached his inbox despite spam and phishing filters and that the operation appeared fully automated.
- He urged a shift toward holistic cybersecurity frameworks that address human behavior as well as technical controls.