Wed, 2 Sep 2026
Markets
DJIA 44,210.31 +0.42% S&P 500 6,204.88 +0.31% NASDAQ 20,398.05 -0.18% RUSSELL 2000 2,271.14 +0.55% FTSE 100 8,786.20 -0.09% DAX 24,120.40 +0.26% NIKKEI 225 39,986.30 +1.02% HANG SENG 24,072.30 -0.44% US 10-YR 4.281% -0.03 CRUDE OIL $67.41 +0.68% GOLD $3,342.10 +0.21% BTC $61,845 -1.12% EUR/USD 1.1782 +0.14% DJIA 44,210.31 +0.42% S&P 500 6,204.88 +0.31% NASDAQ 20,398.05 -0.18% RUSSELL 2000 2,271.14 +0.55% FTSE 100 8,786.20 -0.09% DAX 24,120.40 +0.26% NIKKEI 225 39,986.30 +1.02% HANG SENG 24,072.30 -0.44% US 10-YR 4.281% -0.03 CRUDE OIL $67.41 +0.68% GOLD $3,342.10 +0.21% BTC $61,845 -1.12% EUR/USD 1.1782 +0.14%
Wave of X password reset emails could be hiding a sneak phishing attack

Wave of X password reset emails could be hiding a sneak phishing attack

X users are receiving password reset confirmation emails apparently triggered by hackers, which may be hiding a second attack.

The X Money logo appears on a smartphone screen, and the X (former Twitter) logo displays as the background on a laptop computer screen.

X users are reportedly receiving multiple password reset confirmation emails en masse, allegedly triggered by hackers attempting to access their accounts. While there have been no reported breaches thus far, these emails may be hiding a secondary attack.

SEE ALSO: With the launch of X Money, Elon Musk gets one step closer to his 'everything app'

In a post on Monday, X product engineer Mridul Singhai acknowledged the deluge of password reset emails that many users have been receiving.

"Attackers appear to believe that, now that @XMoney is widely available, they can gain unauthorized access to accounts," Singhai posted, responding to a user who raised the issue. "We are actively investigating the issue and, so far, have found no evidence of any breaches. We apologize for the multiple emails and appreciate your patience as we work to resolve this."

X launched X Money in July, offering financial services to users with paid X Premium or Premium+ accounts. Users can hold money, make payments, and receive funds within the X platform, as well as conduct peer-to-peer transfers. As such, if a hacker is able to gain unauthorised access to people's X accounts, it could have serious financial consequences.

Sharing Singhai's post, X's general counsel James Burnham stated that "[t]he legal and security teams [at] @X will stop at nothing to identify, locate, and hold criminally accountable any person anywhere on or off earth who attempts to victimize our platform's users."

Receiving an email verifying a password change request doesn't automatically mean that your account has been compromised. Such emails are a commonly used multi-factor authentication mechanism, helping to ensure that strangers can't simply change your password without permission and lock you out of your account.

As such, while receiving these emails unsolicited does suggest that someone has attempted to access your account, it doesn't necessarily mean that they were successful. Still, such notifications aren't exactly reassuring.

Even more concerningly, while X's password reset emails pose no immediate danger in and of themselves, hackers may be using these messages to obfuscate their actual attack.

Some users claim that follow-up phishing emails are also being sent out amidst the X's password reset confirmations, disguised as legitimate emails from the platform. These phishing attempts reportedly tell users to change their passwords, which is typically a sensible measure when there's a security breach. However, the emails provide a fake X link to do so, attempting to trick users into providing their login credentials to hackers.

While X hasn't officially confirmed that this is happening, Singhai has stated it is "plausible." As such, he advised users to check that emails purporting to be from X come from "x.com," and that they have a blue BIMI check mark authenticating them.

As always, the best cybersecurity practice is to hover over links in emails to check where they're actually sending you, or better yet avoid clicking such links altogether. It's much safer to change your password by directly accessing X via its mobile app or by typing its URL into your web browser. You should also be suspicious of messages that claim you must act urgently, as hackers may try rushing you into giving them information in a panic before you've thought it through.