All NewsEducationTVBrokers
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
All NewsHome
← Back to AI & Technology

X Users Receive Unsolicited Password Reset Emails Amidst Security Concerns

Created at 1 Sep · 4:31 PM1 source↑ Market-relevant
IN SHORT

X users are reporting a surge in unsolicited password reset emails, login alerts, and account lockouts. While X has not confirmed a new data breach, researchers link the activity to a 2021 API flaw, a recent dataset of 201 million records, an active botnet, and a phishing campaign.

Key Numbers

201 millionrecords in a dataset posted in April 2025
200 millionusers affected by a 2021 API flaw
722,763credential pairs tested by a botnet in 12 minutes
4.8 millionX accounts tested by a botnet over its lifetime
85.6%botnet attempts blocked by two-factor authentication
138account compromises confirmed by a botnet

Who's Involved

X
social media platform experiencing user security alerts
Mridul Singhai
X engineer investigating account security issues
Troy Hunt
Site founder who cataloged a dataset of 200 million users
ThinkingOne
Hacker who posted a dataset of 201 million X user records
Breakglass Intelligence
Researchers who found an active botnet targeting X accounts
Proton
Email service experiencing disruption affecting some X users
X Users Receive Unsolicited Password Reset Emails Amidst Security Concerns

↳ Why This Matters

The widespread, unprompted security alerts on X raise significant concerns about user account security and the potential for unauthorized access, impacting user trust and potentially leading to financial losses or identity theft.

Key facts

  • X users are receiving unrequested password reset emails, login alerts, and account lockouts.
  • X has not admitted to a new data breach but is investigating the issue.
  • Researchers suggest the activity stems from a 2021 API flaw and a more recent dataset of 201 million user records.
  • An active botnet has been testing stolen credentials against X accounts, confirming some compromises.
  • A phishing campaign is also targeting X users with fake login alert emails.

Users of the social media platform X have been inundated with unsolicited password reset emails, login alerts, and account lockouts for several weeks, with a significant increase reported recently. While X has not officially confirmed a new data breach, the company is aware of the situation and investigating.

Mridul Singhai, an engineer at X, apologized for the inconvenience, stating that while no new breaches have been identified, attackers may be attempting to gain unauthorized access to accounts, possibly to access funds via the widely available @XMoney feature. He assured users that the company is actively investigating and has found no evidence of breaches.

Security researchers suggest the ongoing activity could be linked to a vulnerability in Twitter's API from January 2022, which allowed an attacker to match email addresses and phone numbers to accounts. A dataset derived from this flaw, containing over 200 million user records, has been cataloged. Compounding the issue, a hacker known as ThinkingOne posted a 34-gigabyte file containing 201 million X user records, including screen names and email addresses, on the BreachForums site in April 2025. Researchers confirmed that the emails in this dataset matched active accounts.

Further complicating matters, researchers at Breakglass Intelligence discovered an unsecured command-and-control panel in April 2026 that was actively using stolen credentials to test X accounts, confirming 18 new compromises within a short observation window. Over its operational history, this botnet had tested more than 4.8 million X accounts. Concurrently, a separate phishing campaign, unrelated to any data breaches, has been targeting X users since July. These phishing emails closely mimic X's legitimate "new device login" alerts, directing recipients to fake websites designed to steal passwords or authorize malicious applications.

Some X users have also reported experiencing unrequested reset activity on the Proton email service, which is often used as a recovery email. Proton has confirmed a service disruption due to hardware failure, though no direct link to the X activity has been established. X's help documentation indicates that the platform proactively resets passwords for accounts flagged as compromised or targeted by phishing, sending an email to the registered address.

Frequently asked questions

Yes, the emails are sent from X's own systems, making them legitimate in origin. However, they are unrequested by the account owners, which is the cause for concern.

Researchers believe the activity is linked to a combination of a 2021 API flaw, a dataset of 201 million user records, an active botnet testing credentials, and a recent phishing campaign.

No, X has not admitted or reported a new data breach. An X engineer stated they are investigating and have found no evidence of breaches.

Do not click any links. Check the sender address to ensure it is from @X.com or @e.X.com. Enable two-factor authentication with an authenticator app, use a unique password for X, and review your account's active sessions and connected apps.

What Happens Next

01X is actively investigating the issue.
02Users are advised to check sender addresses before clicking links.
03Users should enable two-factor authentication via an authenticator app.
04Users should use unique passwords for X and review active sessions and connected apps.

How It Developed

X users began reporting unsolicited password reset emails, login alerts, and account lockouts in early August.
X engineer Mridul Singhai apologized for the inconvenience, stating no new breach was found but hackers sought account control for financial gain.
Researchers linked the activity to a 2021 API flaw that exposed email addresses and phone numbers for over 200 million users.
A 34-gigabyte file with 201 million X user records was posted on a forum in April 2025.
An unsecured command-and-control panel was found actively testing stolen credentials against X accounts, confirming new compromises.
A phishing campaign mimicking X's login alerts has been targeting users since July, aiming to steal passwords.
Proton, a recovery email service used by some X users, experienced a separate service disruption due to hardware failure.

Sources

T1
X Data Breach? Users Are Getting Flooded With Password Reset Emails Nobody RequestedDecrypt

Related Stories

Hackers claim millions of patient records stolen from McKesson
31 Aug · 6:21 PM
Microsoft 365 outage continues into second day, service improving
31 Aug · 7:21 PM
Fake Claude desktop app distributes crypto-stealing malware
1 Sep · 2:06 PM
Anthropic tightens AI training security after models accessed unauthorized systems
1 Sep · 2:16 AM
Instagram mandates AI-generated profile labels
31 Aug · 6:41 PM