top of page
8d5d6b71-7192-4ac1-89eb-37184277f2e0.gif

London taxi drivers warned over hacked social media accounts spreading malicious links



Advert for Freenow by Lyft.

London taxi drivers are being warned not to open unexpected links sent through X after multiple members of the trade reported losing control of their social media accounts.


The apparent phishing campaign is spreading through direct messages sent from accounts belonging to drivers already known within the taxi community. Recipients may therefore believe the message is genuine because it comes from a familiar or trusted profile.

Advert for Gett. Picture of a taxi driver smiling looking at the camera

One version seen by TaxiPoint claims the sender is competing to co-host a podcast about “life behind the wheel” and asks the recipient to vote through an accompanying link.


The message reads: “Hi mate, sorry to bother you! I’m currently in the running to co-host a podcast all about life behind the wheel, funny taxi stories, memorable passengers, local history, and the everyday characters that make working on the road so entertaining. If you’ve got a minute, I’d really appreciate your vote.”

Drivers have been advised not to follow the link. The address displayed in the message does not appear to be an official domain, despite using wording intended to resemble a podcast-related request.


Several drivers have reported being unable to regain access after their accounts were compromised. The affected profiles are then allegedly used to contact more people within the account holder’s existing network, allowing the attack to spread through the closely connected London taxi community.


Other suspicious activity reported by drivers includes compromised accounts publishing cryptocurrency investment claims. One screenshot shows a taxi-related account claiming to have earned enough money through crypto trading to buy a new vehicle. Such posts may be used to direct followers towards further fraudulent accounts or schemes.

The precise number of affected drivers remains unknown. The pattern described by drivers is consistent with phishing, where a victim is directed to a false website and tricked into entering account credentials or other sensitive information.


Anyone receiving an unexpected voting request, podcast invitation or investment message should contact the apparent sender through another channel before responding. The suspicious link should not be opened, even when the message comes from someone personally known to the recipient.

Drivers who can still access their X account should immediately change the password, review connected applications and active sessions, and remove any unauthorised access. X recommends using two-factor authentication as an additional security check. Those already locked out can submit a compromised-account recovery request through the X Help Centre.


The National Cyber Security Centre also advises victims to change passwords on any other accounts where the same credentials were used, check their email account for unauthorised forwarding rules and log out all connected devices and applications.


Subscribe to our FREE TaxiPoint newsletter. Receive the latest news to your inbox.
(Please note this does not include our Premium access content)

Thanks for subscribing!

Taxi-Point--August-2026--Website-GIF-Loop-Banner--720x200px.gif
RENT WITH (720 x 200 px) (1).gif
Taxipoint - Web Banner - 12.24.png
Footer Banner Checked Safe August 2026.gif
July 2026 website footer Graphic.jpg
Footer-TX4.jpg
Taxipoint Ads -Fleet Web Banner -April 2025.jpg

The views expressed in this publication are not necessarily those of the publishers.

All written and image rights are reserved by authors displayed. Creative Common image licenses displayed where applicable.

Reproduction in whole or in part without prior permission from the publisher is strictly prohibited.

All written content Copyright of TaxiPoint 2026.

bottom of page