Particle.news
Download on the App Store

XInvestigates Mass Unrequested Password-Reset Emails After X Money Expansion

Finding no breach so far, X is probing a surge of legitimate reset messages that researchers link to old data leaks, credential-testing botnets and phishing.

Overview

  • Users reported receiving multiple legitimate password-reset emails and confirmation codes they did not request, with some inboxes getting up to ten messages in hours.
  • X said it is actively investigating and that its initial review found no evidence of an internal systems breach, and the company has urged users to enable two-factor authentication and Password Reset Protect.
  • Researchers and security firms say attackers are mass-triggering X’s public reset form and then using legacy exposed email/phone data, automated credential-testing botnets, and phishing to try to convert attempts into takeovers.
  • The surge followed X’s expansion of X Money to Premium and Premium+ U.S. accounts on Sept. 1, a move researchers say increases the value of taking control of accounts and may have motivated the high-volume targeting.
  • The activity builds on earlier problems: a 2021–22 API flaw and a 201-million-record file posted in April 2025 continue to circulate, and prior botnet tests documented by Breakglass Intelligence show low-percentage compromises still produce real account takeovers.