According to security researchers, a new phishing is targeting verified Twitter accounts. Verified Twitter accounts refer to those that have a blue badge with a tick mark in the center.

See also: Twitter: Removes 3,400 accounts used in government propaganda campaigns
These accounts typically represent notable influencers, prominent figures, politicians, journalists, activists, as well as government and private organizations.
The phishing campaign follows Twitter's recent blue badge removal of a large number of verified accounts, stating that they were ineligible and were verified in error.
A phishing email is urging Twitter users to “update” their details or risk losing their blue badge. The email appears to be successfully bypassing Gmail.
These emails come as Twitter inexplicably removes verified status from a number of notable accounts, including that of English TV presenter, producer and national host of Heart Radio, Jamie Theakston.
The Bloxy News , with 556,000+ followers, is another example of an account that lost its blue badge, with a generic message as the reason for revoking its verification status.
See also: Twitter will ban sharing photos/videos without consent
It's no surprise that Twitter's ongoing removal of blue badges has upset many in the Twitterverse, as verified accounts are often seen as distinguished, noteworthy, and expected to lead by example, at least that's what Twitter says after verifying them.

Some have noted that the timing of Twitter's mass removal of verification coincides with changes in executive leadership, after former Twitter CEO Jack Dorsey stepped down and handed the reins to CTO Parag Agrawal.
The phishing email, discovered by BleepingComputer, is sent to verified users, many of whom may choose to list an email address on their resume for professional reasons.
The phishing message first lures the user into clicking the “Update here” button.
The button links to https://www.cleancredit[.]in/wp-content/uploads/2021/12/index.html which further redirects the user to a page at: https://dublock[.]com/ dublock/twitter/
It appears that both of these websites have been compromised and abused by attackers to host phishing pages.
See also: Hackers exploit Omicron mutation for phishing attacks
After entering their Twitter credentials, the user is asked to also provide the two-factor authentication code that is sent to them.
After collecting the username, password, and two-factor authentication code, the phishing page redirects the user to the Twitter homepage.
Twitter users, with or without a blue badge, should be wary of such phishing emails and avoid opening any links or attachments.
