X Users Hit By Wave Of Password Reset Emails; Company Says No Breach Found So Far

X users were left worried of losing their accounts when they were triggered by an email from a torrent of unsolicited password reset notifications came in the inbox. Many users got notifications that sent a lot of others getting “Password reset request” emails within minutes, and some screenshots showed as many as 10 notifications within a few minutes. The unusual activity quickly triggered speculation online that the social media site is at the brink of a huge security breach or a large-scale takeover campaign.

X Password Reset Emails Flood Users | Photo Credit: AI Images
X Password Reset Emails Flood Users | Photo Credit: AI Images

The repeated notifications came even though the users had not asked to reset their password. Some reports said all of them came just seconds apart, making the activity seem especially suspicious. Social media screenshots from people with X accounts had inboxes stuffed with password reset emails and made users feel like they could potentially hijack the system or even take care of their own accounts.

X insists that so far it has not found any evidence of a breach of accounts. Mridul Singhai, a product engineering team member at X, said on the platform that X was “actively investigating the unusual wave of activity.” Singhai said the attempts appeared to be connected to the recent expansion of X’s payments feature, X Money.

"Attackers seem to think that now that @XMoney is widely available, they can gain unauthorized access to accounts,” Singhai said. X was investigating the problem and had found no evidence of breaches at that time, he said. He also apologized to users for the repeated emails and thanked them for their patience while the company looked into the activity.

The timing of the incident has been especially interesting because X Money has recently been made available to pay for things. The payments feature is built on the Cross River Bank banking infrastructure to allow users to transfer money through X. It was recently launched for Premium and Premium+ subscribers who have US accounts, after a somewhat limited launch.

The introduction of payment functionality on the platform has also raised the stakes on account security. An X account that may be connected to money transactions may be more attractive to cybercriminals than a normal social media account. That may explain the high level of concern among users after multiple password reset attempts with X, and it is yet to be seen by X whether those attempts are successful.

Another explanation has been suggested by security researchers and other people online. It has been speculated that attackers can use publicly available X usernames to initiate password reset requests at scale. In such a scenario, having a password reset email would not necessarily mean that the user’s password is stolen or that X’s internal systems have been compromised.

But the incident has renewed broader concerns about X and its predecessor, Twitter. X has had security incidents in the past and data exposure reports in previous years made many users nervous when the account is not as usual.

Cybersecurity experts have advised users not to panic but to take basic precautions. Users who receive unsolicited password reset emails should be advised not to click on suspicious links and instead access X directly through the official app or website to check their account if they don’t recognize the emails. If an attack is to occur, two-factor authentication may help to secure your account, even if the attacker somehow obtains access to your account.

Users are encouraged to activate X’s “password reset protect” feature to confirm a password by email or phone before changing one’s password. These security measures can prevent unauthorized password changes even if someone tries to reset the password again and again.

At the moment, there is no evidence in the X information that the flood of notifications was generated by a successful breach of the company's systems. This is important as repeated password reset requests can be made without an attacker actually having access to an account. Nevertheless, the very high number of alerts has understandably caused concern among users.

X’s investigation is ongoing and details of the incident could help determine whether the system reset was initiated by X itself, an abuse of the platform’s account recovery mechanism, or something else. But until X’s team has a more detailed look, users who receive unexpected reset emails should take them as a warning to re-examine their security settings rather than as a sign that their accounts have been compromised.

For now, the key message from X is that there is an investigation in place and no evidence of a breach so far. Users can minimize their exposure to the system by using strong and unique passwords, enabling two-factor authentication, and monitoring account activity for any unusual changes.