
When X Fails to Protect: How Europe’s Verified Users Are Abandoned to Identity Crime
By Cora Westerink, Tilburg
Imagine paying for a verified online identity—only to watch it be hijacked, sabotaged, and used against you. Now imagine the platform responsible refusing to act, even as the sabotage escalates. This is not dystopian fiction. It is happening right now on X (formerly Twitter). And Europe is watching in silence.
🔹 I Am a Verified User. I Am Not Safe.
Since 2024, I have been a paying subscriber to X’s verification program. I maintained verified accounts under my real name and artistic pseudonyms, including @IntoBrightLight and @FrozenInFlights. These accounts were intended to protect my identity as an artist, writer, and citizen journalist. They did the opposite.
My verified digital presence has been:
- Hijacked,
- Rendered inaccessible to me,
- Exploited without consent,
- Silently overwritten by a hostile anonymous entity operating under the alias @PracticeTwiet.
Let me be clear: I did not create @PracticeTwiet. I do not control it. I do not know who does. But it:
- Sabotages my login attempts;
- Controls or mimics my IP address;
- Manipulates and deletes posts from my real verified accounts;
- Redirects communications and access tokens tied to my professional identity.
🔹 X’s Irish Office Refuses to Act
In two formal letters—on 18 May and 1 August 2025—I asked X Dublin to:
- Restore access to my verified accounts.
- Secure evidence (login IPs, logs, metadata).
- Cooperate with Dutch authorities under EU jurisdiction.
Their reply? A generic message directing me to access data from accounts I cannot access. No investigation. No data preservation. No human response.
🔹 This Is More Than Bad Customer Service. It’s a Violation of European Law.
Under the General Data Protection Regulation (GDPR) and Regulation (EU) 2018/1725, every EU citizen has the right to:
- Access their personal data,
- Rectify and delete false data,
- Be protected against misuse of their identity.
Platforms operating in the EU—including X’s Dublin office—are required to uphold these rights. They are not optional. Refusing to investigate or acknowledge criminal identity theft targeting a verified user is not just negligence. It’s a breach of duty.
According to the European Data Protection Board (EDPB), X is a separate data controller responsible for what happens to users’ personal data. That means they carry full legal responsibility when data is stolen, manipulated, or abused under their watch.
🔹 Where Are the Regulators?
What happens when a platform like X chooses silence over action?
European regulators, including:
- The European Data Protection Supervisor (EDPS),
- National Data Protection Authorities (e.g., Autoriteit Persoonsgegevens in the Netherlands),
- The European Commission itself,
must confront a painful question: Can Big Tech platforms ignore crimes against their own paying users—and get away with it?
🔹 A Wake-Up Call for Europe
This is not just my story. It is the story of countless users across the EU who have lost access to their own voice, their reputation, and their safety online. It is about:
- Digital sabotage committed with impunity,
- Cross-border cybercrime left uninvestigated,
- Verified digital identities that offer no real protection.
As long as X continues to ignore European law and corporate responsibility, we, the users, are left defenceless. And that, too, is a systemic failure.
📢 What Can You Do?
- Share this post to demand accountability from X Europe (check the details in my two letters below).
- Contact your national Data Protection Authority to report abuse.
- Support independent investigations into platform negligence.
- Hold EU institutions accountable for enforcing the laws they passed.
Europe must decide: Will it protect its citizens in the digital age—or let them be erased?
Cora Westerink
Artist, writer, citizen journalist
Tilburg, Netherlands
📧 cora.westerink@gmail.com
🌐 https://x.com/FrozenInFlights (if it still exists)
Sources 1 to 4:
- 4 European Data Protection Supervisor (EDPS)
2. 4 My registered letter to the X team, 18 May 2025
3. 4 My digital letter to the X team, 1 August 2025
4.4 Digital crimes committed against my verified X-accounts, some examples
