NAIROBI, Kenya – Thousands of X users have been flooded with unsolicited password reset emails, prompting the social media platform to investigate an apparent wave of attacks targeting user accounts.
The messages began appearing in large numbers as attackers repeatedly triggered X’s password recovery system, leaving some users with several reset notifications despite never requesting a password change.
The incident has raised fears of a wider X security breach, particularly following the rollout of X Money, the platform’s new payments service.
However, X has stressed that it has found no evidence of an internal system breach so far.
X product engineer Mridul Singhai confirmed that the company was investigating the unusual activity after users began reporting the reset emails.
“Attackers appear to believe that, now that @XMoney is widely available, they can gain unauthorized access to accounts,” Singhai said.
He added that X was “actively investigating the issue” and had “so far, found no evidence of any breaches.” He also apologised to users for the multiple emails.
X’s AI chatbot Grok also described the activity as attackers “mass-triggering” the password-reset form using public usernames, while stating that there had been no confirmed system breach or mass account takeovers.
Because an X username is public information, an attacker does not necessarily need access to a user’s password to initiate the process. The resulting email can therefore arrive in a legitimate user’s inbox even though the account owner did nothing to request it.
Some users have reported receiving multiple messages within a short period. One reported example showed eight password-reset emails arriving within three minutes.
Receiving an unexpected password-reset email does not by itself mean that an attacker has accessed the account.
X’s current position is that it has not found evidence of a breach. The company is investigating whether attackers are attempting to use the recovery system as part of a wider account-takeover campaign.
The timing of the attack has attracted particular attention because it coincides with the wider rollout of X Money. The service expands X’s financial capabilities and allows the platform to become more deeply involved in payments and transactions.
Singhai said attackers appear to believe that gaining control of X accounts could give them an opportunity to exploit the new financial features.
Users receiving unsolicited password-reset notifications should avoid clicking links in unexpected messages. Instead, they should open the X application or website directly and check their account’s security settings.
Users can also activate Password Reset Protect, a security feature designed to add another layer of verification to password-reset attempts.
The setting can be found under:
Settings and privacy → Security and account access → Security → Password reset protect
Users should also enable two-factor authentication (2FA) if they have not already done so.
An authenticator app or passkey provides stronger protection than relying solely on a password, particularly if a user’s credentials have been exposed elsewhere.
Users should also avoid reusing their X password on other websites and should never share authentication codes with someone claiming to be an X employee or security specialist.




