X Users Hit by Password Reset Email Bombardment; No Data Breach Found, Says Official

X Users Hit by Password Reset Email Bombardment; No Data Breach Found, Says Official

N
News Editor
2026-09-01 16:31:09
On September 1, a large number of X (formerly Twitter) users were bombarded with unsolicited password reset emails, with some receiving 8 emails in 3 minutes. X engineer Mridul Singhai said attackers are abusing public usernames to submit account recovery forms, but the system has not been compromised. The motive may be linked to the recent launch of X Money payment features. Users are advised to enable password reset protection and two-factor authentication.

X Users Swamped by Password Reset Emails

On September 1, numerous X (formerly Twitter) users said password reset emails started pouring in. Unsolicited. One user reported getting 8 of them in just 3 minutes. That set off widespread concern.

Official Response: No Sign of a System Intrusion

X product engineer Mridul Singhai said attackers were repeatedly sending account recovery forms with publicly available usernames. Each submission triggered a password reset notification. But after investigating, the company found no evidence of a system intrusion. User account data was not compromised.

Possible Link to X Money

Singhai said the attack may be tied to the recent widespread rollout of X Money payment features. Account logins can now connect to banking functions. That gives attackers a possible target: force password resets, seize control of accounts, and steal funds.

Official Security Recommendations

X tells affected users to turn on "password reset protection" immediately, along with two-factor authentication. The company also recommends authenticator apps over SMS verification codes for stronger security.

Historical Comparison: 2020 Internal Breach

The latest attack is nothing like the 2020 X internal system breach. In that incident, an internal intrusion led to 130 accounts being reset and approximately $118,000 in Bitcoin being stolen. This time, the attack is entirely external. It abuses public forms without any system intrusion.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
900

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.