The hijacking of digital identity and the urgent need for cyber accountability

Hijacked accounts of prominent figures were used to promote cryptocurrency scams
We are all living in transient times. Our dependence on the digital environment has begun to start shaping our perspectives. The digital ecosystem is witnessing an alarming and escalating trend that demands immediate legal and policy attention: the systematic compromise and takeover of high-profile accounts on X (formerly Twitter). From journalists to public figures, the list of victims continues to grow, exposing not merely individual vulnerabilities but a deeper structural crisis in platform security architecture. As someone who has tracked the evolution of cyber law jurisprudence for over three decades, I find this pattern deeply symptomatic of larger fault lines in how social media platforms approach identity verification, account security, and post-incident accountability.
Account takeovers on X typically occur through a combination of technical exploitation and social engineering. Phishing remains the most prevalent vector as attackers craft deceptively authentic login pages or direct messages that trick users into surrendering credentials. SIM-swapping attacks, where malicious actors hijack a victim's mobile number to intercept two-factor authentication codes, have also surged, particularly targeting individuals whose phone numbers are linked to their accounts for verification purposes.
Credential stuffing, being the automated testing of leaked username-password combinations from unrelated data breaches, continues to be an effective, if unsophisticated, method. More concerning is the emergence of insider-facilitated breaches, where compromised employee access or third-party contractor vulnerabilities within the platform itself have been exploited, as demonstrated in previous high-profile incidents.
The convergence of these methods reveals a troubling reality: account security is only as strong as its weakest link, whether that link resides in user behaviour, platform infrastructure, or third-party integrations.
The targeting of journalists and public figures is neither coincidental nor arbitrary. These accounts carry what I term "amplified digital credibility," being the intrinsic ability to disseminate information at scale with inherent public trust. When compromised, such accounts become potent instruments for spreading disinformation, market manipulation, or political propaganda, often within the narrow window before the breach is detected and remedied.
We have witnessed instances where hijacked accounts of prominent figures were used to promote cryptocurrency scams or issue false statements with significant real-world consequences, including market volatility. The asymmetry here is stark: the effort required to compromise an account is minimal compared to the exponential damage that a single malicious post from a trusted handle can inflict upon public discourse, financial markets, or geopolitical stability.
This is where the legal and policy dimensions of the said phenomenon become critical. Social media platforms have evolved into the primary architecture of contemporary public discourse. When the accounts of those entrusted with shaping public opinion are compromised, the very foundation of trust in digital communication is shaken.
This raises fundamental questions about intermediary liability, the adequacy of existing intermediary due diligence frameworks, and whether current legal regimes, including India's Information Technology Act, 2000, and the emerging Digital Personal Data Protection Act, 2023 framework, sufficiently address the unique harms arising from identity-based cyber intrusions on social media.
Unfortunately, at the time of writing, the Indian cyber law does not provide direct, clear guidance in this regard. Intermediaries are mandated to implement and maintain reasonable security practices and procedures, while discharging their obligations under the law. However, issues pertaining to security of user accounts is not specifically mentioned under the IT Act, 2000 and rules and regulations made thereunder. Breach of social media accounts would constitute computer-related offences under Section 66 of the IT Act, 2000. The absence of robust, mandatory, and time-bound breach notification requirements specific to social media identity theft represents a significant legal lacuna.
Unlike financial data breaches, which often trigger statutory disclosure obligations in various jurisdictions, account takeovers on social media platforms largely remain governed by platform discretion rather than binding legal mandate.
This is one area that the Indian cyber law must immediately focus on. This assumes all the more significance as India still does not have any dedicated law on artificial intelligence or governing its misuse.
Given the existing ground reality, users, particularly those with public-facing profiles, must adopt a layered security approach. Enabling two-factor authentication rather than SMS-based verification significantly reduces vulnerability to SIM-swapping. Regular password rotation, combined with the use of unique, complex passwords, remains foundational.
Equally important is vigilance against phishing attempts. Users must verify the authenticity of login prompts and refraining from clicking on unsolicited links purporting to be from X or related services. Public figures would also benefit from limiting the linkage of personal mobile numbers to their accounts, opting instead for dedicated, less publicly known contact methods for verification purposes.
Users need to be mindful of the fact that the response of the intermediary platforms to their complaints may not be swift or as per their expectations.
The response mechanism post-compromise remains an area requiring substantial improvement. Users have reported delays in account recovery, particularly when attackers alter linked email addresses or phone numbers immediately upon gaining access. The efficacy of X's support infrastructure in swiftly restoring compromised accounts, especially for non-monetized or non-premium users, continues to lag behind the urgency the situation demands.
The recurring nature of these incidents necessitates the need for adopting a multi-pronged response. Platforms must be held to higher standards of proactive security architecture, including mandatory security audits and transparent incident reporting. Regulatory frameworks worldwide, including India's evolving digital regulatory landscape, must evolve to specifically address warranting expedited grievance redressal mechanisms. The existing grievance redressal mechanisms are not as effective as were expected and leave much to be desired,
As digital identity increasingly becomes synonymous with real-world credibility and influence, safeguarding it must transcend individual responsibility and become a shared obligation between users, platforms, and regulators. The sanctity of public discourse in the digital age depends on nothing less. The Indian cyber law needs to play a decisive role in this regard by coming up with new distinct provisions regarding the above phenomenon and the accountability aspects connected therewith. Till such time as it happens, it is time for users to be extra careful, duly diligent and cautious in respect of their social media accounts and issues concerning the same.
The author, Dr. Pavan Duggal, Senior Advocate, Supreme Court of India, is a global leading authority and expert on cyber law, artificial intelligence, and emerging technology law. With 37 years of practice, he has left an indelible mark on the evolution of cyber law jurisprudence across the world. He can be contacted at pavan@pavanduggal.com.
Senior Advocate, Supreme Court & Global Chair, International AI Accountability Forum; Views presented are personal.













