Key facts
- X users are receiving unrequested password reset emails, login alerts, and account lockouts.
- X has not admitted to a new data breach but is investigating the issue.
- Researchers suggest the activity stems from a 2021 API flaw and a more recent dataset of 201 million user records.
- An active botnet has been testing stolen credentials against X accounts, confirming some compromises.
- A phishing campaign is also targeting X users with fake login alert emails.
Users of the social media platform X have been inundated with unsolicited password reset emails, login alerts, and account lockouts for several weeks, with a significant increase reported recently. While X has not officially confirmed a new data breach, the company is aware of the situation and investigating.
Mridul Singhai, an engineer at X, apologized for the inconvenience, stating that while no new breaches have been identified, attackers may be attempting to gain unauthorized access to accounts, possibly to access funds via the widely available @XMoney feature. He assured users that the company is actively investigating and has found no evidence of breaches.
Security researchers suggest the ongoing activity could be linked to a vulnerability in Twitter's API from January 2022, which allowed an attacker to match email addresses and phone numbers to accounts. A dataset derived from this flaw, containing over 200 million user records, has been cataloged. Compounding the issue, a hacker known as ThinkingOne posted a 34-gigabyte file containing 201 million X user records, including screen names and email addresses, on the BreachForums site in April 2025. Researchers confirmed that the emails in this dataset matched active accounts.
Further complicating matters, researchers at Breakglass Intelligence discovered an unsecured command-and-control panel in April 2026 that was actively using stolen credentials to test X accounts, confirming 18 new compromises within a short observation window. Over its operational history, this botnet had tested more than 4.8 million X accounts. Concurrently, a separate phishing campaign, unrelated to any data breaches, has been targeting X users since July. These phishing emails closely mimic X's legitimate "new device login" alerts, directing recipients to fake websites designed to steal passwords or authorize malicious applications.
Some X users have also reported experiencing unrequested reset activity on the Proton email service, which is often used as a recovery email. Proton has confirmed a service disruption due to hardware failure, though no direct link to the X activity has been established. X's help documentation indicates that the platform proactively resets passwords for accounts flagged as compromised or targeted by phishing, sending an email to the registered address.
