X Users Swamped by Password Reset Emails
On September 1, numerous X (formerly Twitter) users said password reset emails started pouring in. Unsolicited. One user reported getting 8 of them in just 3 minutes. That set off widespread concern.
Official Response: No Sign of a System Intrusion
X product engineer Mridul Singhai said attackers were repeatedly sending account recovery forms with publicly available usernames. Each submission triggered a password reset notification. But after investigating, the company found no evidence of a system intrusion. User account data was not compromised.
Possible Link to X Money
Singhai said the attack may be tied to the recent widespread rollout of X Money payment features. Account logins can now connect to banking functions. That gives attackers a possible target: force password resets, seize control of accounts, and steal funds.
Official Security Recommendations
X tells affected users to turn on "password reset protection" immediately, along with two-factor authentication. The company also recommends authenticator apps over SMS verification codes for stronger security.
Historical Comparison: 2020 Internal Breach
The latest attack is nothing like the 2020 X internal system breach. In that incident, an internal intrusion led to 130 accounts being reset and approximately $118,000 in Bitcoin being stolen. This time, the attack is entirely external. It abuses public forms without any system intrusion.

