Overview
- Users reported receiving multiple legitimate password-reset emails and confirmation codes they did not request, with some inboxes getting up to ten messages in hours.
- X said it is actively investigating and that its initial review found no evidence of an internal systems breach, and the company has urged users to enable two-factor authentication and Password Reset Protect.
- Researchers and security firms say attackers are mass-triggering X’s public reset form and then using legacy exposed email/phone data, automated credential-testing botnets, and phishing to try to convert attempts into takeovers.
- The surge followed X’s expansion of X Money to Premium and Premium+ U.S. accounts on Sept. 1, a move researchers say increases the value of taking control of accounts and may have motivated the high-volume targeting.
- The activity builds on earlier problems: a 2021–22 API flaw and a 201-million-record file posted in April 2025 continue to circulate, and prior botnet tests documented by Breakglass Intelligence show low-percentage compromises still produce real account takeovers.