
Owners of X accounts have reported being hit by a sudden deluge of password reset confirmation emails, a wave of unsolicited notifications that security experts believe may be tied to an ongoing campaign targeting users of the platform’s new financial services. The messages, while not necessarily harmful on their own, could be part of a broader phishing operation designed to trick users into surrendering their credentials.
Key facts at a glance
- X users are receiving mass password reset emails, reportedly triggered by hackers attempting to gain unauthorized access.
- There is no evidence so far of an actual platform breach.
- X product engineer Mridul Singhai acknowledged the issue and said the platform’s security team is actively investigating.
- The attackers may be motivated by X Money, which allows paid subscribers to store funds and conduct payments within X.
- Follow-up phishing emails disguised as legitimate password reset messages may be using the flood of real alerts as cover for a secondary attack.
- Users are advised to verify sender domains, look for authenticated checkmarks, and avoid clicking links in unsolicited emails.
A flood of password reset notifications
Beginning around the time X Money expanded its availability, numerous users took to the platform to complain that their inboxes were filling up with password reset confirmation emails. Some described receiving multiple messages in a single hour, even though they had not requested any password changes. The pattern is a familiar one: attackers send a large number of password reset requests, hoping that some users will panic, click embedded links, or reveal additional information that can be used to compromise their accounts.
On Monday, X product engineer Mridul Singhai responded to a user’s post about the flood. “Attackers appear to believe that, now that @XMoney is widely available, they can gain unauthorized access to accounts,” Singhai wrote. “We are actively investigating the issue and, so far, have found no evidence of any breaches. We apologize for the multiple emails and appreciate your patience as we work to resolve this.”
Singhai’s acknowledgement confirmed what many security analysts had already suspected: the surges in password reset emails are not random glitches. They are likely the result of automated tools that bombard X’s authentication systems with password change requests for targeted usernames or email addresses. When a user receives a reset email, it is often because an attacker has already guessed or obtained enough identifiers to trigger the process. However, receiving such a message does not mean the attacker has successfully changed the password. In most cases, the reset email itself is the only barrier standing between the hacker and full account takeover.
The X Money motive
The timing of the email wave is notable because X launched X Money in July. The service is available exclusively to users with paid X Premium or Premium+ accounts. It allows account holders to hold money in the X platform, make payments, receive funds, and conduct peer-to-peer transfers with other users. This is a major step toward what X owner Elon Musk has described as an “everything app,” combining social networking with messaging, media, and financial transactions.
Because X Money is attached directly to user profiles, a compromised account could potentially give a hacker access not only to social data but also to stored funds and payment methods. This makes X accounts far more attractive targets than they were when they were merely repositories for posts and direct messages. Even users who have not signed up for X Money may be swept up in the attack because hackers cannot always know which accounts have financial features enabled until they attempt unauthorized access. The result is a shotgun approach: attackers fire off password reset requests across a wide pool of accounts, hoping to hit at least one that will allow them to monetize the intrusion.
A secondary phishing layer
Meanwhile, some X users have reported receiving suspicious follow-up emails that appear to come from X but are actually phishing attempts. These messages claim that the recipient’s account is under threat and instruct them to change their password immediately through a link embedded in the email. The link may look like it goes to X’s login page, but it actually leads to a fake site designed to harvest usernames, passwords, and possibly two-factor authentication codes.
Phishing experts note that this is a common tactic. By flooding users with legitimate password reset notifications, attackers create confusion and anxiety. Users become accustomed to seeing emails about password resets and may let their guard down when a more dangerous email arrives. The sheer volume of legitimate notifications can also cause users to miss subtle warning signs in the phishing emails, such as a typosquatted domain like xcom-secure-login[.]com or an address that does not match X’s official email format.
X has not officially confirmed that these phishing emails are linked to the password reset wave, but Singhai said it is “plausible” that attackers would launch a secondary phishing campaign alongside the reset notifications. He encouraged users to check that emails purporting to be from X come from the “x.com” domain and that they carry a blue BIMI checkmark. BIMI, which stands for Brand Indicators for Message Identification, is an email authentication standard that displays a verified brand logo in compliant email clients. A legitimate email from X should show a blue checkmark and come from a sender address ending in x.com. Even with those indicators, users should remain cautious, because sophisticated phishers can sometimes spoof or approximate such signals.
What password reset emails really mean
Receiving an email that verifies a password change request does not automatically mean an account has been compromised. Password reset emails are a widely used multi-factor authentication mechanism. When someone attempts to change a password without knowing the current one, the platform sends a confirmation email containing a unique link or code. Only the person with access to the email inbox can complete the change. Therefore, a flood of reset emails indicates that attackers are making repeated attempts, but those attempts have not necessarily succeeded.
Nevertheless, the experience is unsettling. Users who have done nothing wrong suddenly see their inboxes filled with alarming security messages. Some may begin to doubt the safety of their own accounts. In a panic, they may click the most prominent button in their email client, which could be the very click that leads to a phishing site.
Security experts stress that the best response is to slow down. If you receive a password reset email but did not request a password change, do not click the links inside it. Instead, open the X app or type X’s web address directly into your browser and log in normally. If your account is still accessible, you can change your password through the official security settings menu to be extra safe. This approach bypasses any phishing links entirely.
How to protect yourself
There are several steps X users can take to reduce the risk of falling victim to these attacks. First, hover over any links in email messages to see the actual destination URL before clicking. If the URL does not clearly point to x.com or one of its official subdomains, do not click it. Second, enable two-factor authentication on your X account. This adds an extra layer of security that can prevent attackers from logging in even if they do obtain your password. Third, use a unique password for X that you do not use on any other site. Password recycling is one of the most common ways that security breaches on other platforms lead to account takeovers on X.
It is also wise to be skeptical of any message that creates a false sense of urgency. Phishing emails often claim that your account will be suspended, locked, or permanently deleted if you do not act within minutes. These threats are designed to rush you into making a mistake. Legitimate companies rarely use such tactics. If an email tries to panic you with a deadline, treat it with suspicion.
For those who have already clicked a suspicious link or entered their password on an untrusted page, the recommended action is to change passwords immediately from the official X website or application, revoke access to any unusual third-party apps, and review your account activity for unrecognized logins. You should also contact X Support if you believe your account has been compromised.
Ongoing investigation
X’s legal and security teams have been drawn into the matter as well. James Burnham, X’s general counsel, shared Singhai’s post and stated that “[t]he legal and security teams [at] @X will stop at nothing to identify, locate, and hold criminally accountable any person anywhere on or off earth who attempts to victimize our platform's users.” His strong language reflects the potential seriousness of the situation, especially as X Money becomes more widely integrated.
As of this week, no evidence has emerged that any users have lost money or suffered unauthorized transactions as a result of the password reset wave. However, the investigation is ongoing, and X’s security team is reportedly working to trace the sources of the reset requests and identify the infrastructure behind the phishing emails. In the meantime, users should remain vigilant and continue to follow best practices for online security.
The wave of password reset emails may turn out to be nothing more than an annoyance, but it could also be the opening move in a more sophisticated attack. The safest course is to ignore unsolicited password reset notifications, verify any security alerts through official channels, and never let a panicked inbox override your better judgment.
Source:Mashable News
