VYPR
advisoryPublished Sep 4, 2026· 1 source

X Investigates Surge in Password-Reset Emails Amidst X Money Rollout

X is investigating a significant increase in unsolicited password-reset emails sent to users, coinciding with the broader rollout of its X Money financial services, though the company reports no evidence of breaches or successful account takeovers.

X, the social media platform formerly known as Twitter, is currently investigating a widespread surge of unsolicited password-reset emails being sent to its users. This wave of suspicious activity has emerged concurrently with the wider rollout of X Money, the company's new financial services offering. While the timing has raised concerns about potential account takeovers, X has stated that it has found no evidence of a breach or successful compromises of user accounts thus far.

Users began reporting the unexpected password-reset emails and verification codes on September 1st. A statement from X product engineer Mridul Singhai indicated that attackers may be attempting to exploit the expanded availability of X Money. "Attackers appear to believe that, now that @XMoney is widely available, they can gain unauthorized access to accounts," Singhai noted. He assured users that X was actively investigating the issue and apologized for the inconvenience, reiterating that no breaches had been detected.

X Money, which is available to eligible US users, offers financial services including interest-bearing accounts, a Visa debit card, and peer-to-peer payment capabilities, powered by Cross River Bank. The integration of financial services could potentially make some X accounts more attractive targets for malicious actors, especially those with payment access, large followings, business operations, or significant social engineering potential.

The observed activity aligns with common tactics where attackers submit password-reset requests in bulk. However, initiating a password reset request does not equate to successfully completing one, nor does it automatically confirm an account takeover. X's account recovery process typically requires access to the email address or phone number associated with the account to finalize the reset. To date, there is no indication that any X Money accounts or user funds have been accessed, nor has X definitively linked the password-reset activity directly to the X Money service itself.

This type of activity is not unique to X. Earlier this year, a similar flood of unsolicited password-reset emails affected Instagram users, demonstrating that such campaigns can occur on platforms without integrated financial services. Such 'reset flooding' can serve multiple purposes for attackers. It can be used as a smokescreen for more serious malicious activities, or as a nuisance tactic to pressure users into unnecessarily changing passwords, obscure genuine security notifications, or even prompt users to disable security features in an attempt to stop the barrage of messages.

X has provided guidance to users on how to stay safe during this period. They strongly advise against clicking links or entering codes from unexpected messages. Users should navigate directly to X's website or app to manage their accounts. Sharing reset codes or two-factor authentication (2FA) codes with anyone, including purported support staff, is also cautioned against. Enabling password-reset protection, which requires additional account information before sending a reset link or code, and utilizing two-factor authentication are recommended security measures.

Users are also reminded to use unique, strong passwords and to change their X password if it's reused elsewhere. Signs of an actual account takeover, such as unfamiliar posts, direct messages, profile changes, or unauthorized app connections, should be monitored. The company also warns about the risk of phishing attacks that mimic the reset process, especially when legitimate reset emails are circulating.

Malwarebytes recommends using real-time anti-malware solutions with web protection to identify and block malicious sites. For users unsure about the legitimacy of a message, tools like Malwarebytes Scam Guard can offer assistance. The core message from X and security experts is to remain vigilant, verify all communications directly through official channels, and ensure robust security measures like password-reset protection and 2FA are enabled.

Synthesized by Vypr AI