X Investigates Password Reset Attacks Targeting Users After X Money Launch
X investigates mass password reset attempts targeting users after the X Money launch, with no confirmed breaches or account takeovers reported.
X is investigating a wave of unsolicited password reset emails sent to users following the launch of its X Money payments service. The company said attackers appear to be attempting to exploit interest around the new feature, but it has not found evidence that user accounts were successfully compromised.
X product engineer Mridul Singhai said the company was reviewing reports from users who received multiple unexpected password reset notifications.
“Attackers appear to believe that, now that @XMoney is widely available, they can gain unauthorized access to accounts.”
Singhai said X was actively investigating the issue and apologised to users affected by the large number of emails. He added that the company had not found evidence of account breaches at the time of the update.
X Says No Confirmed Account Takeovers Have Been Found
X Money is the platform’s newly launched payments service, which includes a bank card and other payment-related features. The service is designed to help creators and users participate in X’s digital economy by making payments easier on the platform.
The launch of financial services can attract additional security risks because attackers often target platforms where users manage money or payment information. X said the current activity appears to involve attempts to trigger password reset processes rather than confirmed system compromises.
The company has not posted a detailed update through its official X account about the investigation. However, X’s general counsel, James Burnham, warned that the company’s legal and security teams would pursue individuals responsible for targeting users.
“The legal and security teams @X will stop at nothing to identify, locate, and hold criminally accountable any person anywhere on or off earth who attempts to victimize our platform’s users.”
Users Encouraged to Enable Two-Factor Authentication
As reports of the password reset attempts spread, users have advised others to enable two-factor authentication as an additional account protection measure. Some users also shared information about the issue through posts on X.
X’s AI chatbot Grok responded to some user discussions by explaining that attackers appeared to be “mass-triggering” password reset requests using public usernames. Grok said there were no confirmed system breaches or mass account takeovers.
The investigation remains ongoing as X works to determine the scope of the activity and prevent further misuse of its account recovery systems.
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Angry
0
Sad
0
Wow
0