ZeroHour
Story · 1 source · 1 articlefirst updated ()

X investigates wave of unsolicited password-reset emails tied to X Money launch; no breaches confirmed

mediumPhishing & fraudexploited in the wildimportance 45
What's new: First merged summary. The story progressed from initial user reports and X's 'no evidence of breach' statement on September 1 (TechCrunch) to follow-up coverage on September 4 (Malwarebytes) that added the reported attacker motive, the detail that completing a reset requires access to the account's email or phone number, expanded X Money product specifics, and a new warning that reset flooding…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

X users have reported mass unsolicited password-reset emails and codes since September 1, 2026, following the launch of the X Money payments service. X says it has found no evidence of any breach or account takeover, while security researchers warn the reset…

Numerous X users began reporting unexpected password-reset emails and codes on September 1, 2026, shortly after the launch of X Money, the platform's new payments service. X product engineer Mridul Singhai said attackers appear to believe that newly widespread X Money access makes accounts worth targeting, and the company says it has found no evidence of any successful breach, fund access, or account takeover. According to TechCrunch, X's Grok chatbot indicated attackers are mass-triggering the resets using public usernames. Completing a reset still requires access to the account's associated email address or phone number. X Money offers eligible US users interest-bearing accounts, a Visa debit card, and peer-to-peer payments, with banking infrastructure provided by FDIC-insured Cross River Bank. Malwarebytes Labs warns the reset flood can serve as cover for phishing or obscure genuine security alerts. Users are advised to enable Password Reset Protect, use authenticator-based two-factor authentication, and maintain unique passwords while the investigation continues.

  • Unsolicited password-reset emails and codes affecting X users have been reported since September 1, 2026, following the launch of the X Money payments service.
  • X says it has found no evidence of any successful breach, fund access, or account takeover; both TechCrunch (September 1) and Malwarebytes Labs (September 4) report the same status, with no confirmed breach so far.
  • X product engineer Mridul Singhai said attackers appear to believe newly widespread X Money access makes accounts worth targeting.
  • According to TechCrunch, X's Grok chatbot said attackers are mass-triggering the password resets using public usernames.
  • Completing a password reset still requires access to the account's associated email address or phone number.
  • X Money offers eligible US users interest-bearing accounts, a Visa debit card, and P2P payments, with accounts held at FDIC-insured Cross River Bank.
  • Malwarebytes Labs warns the reset flood can be used as cover for phishing or to obscure real security alerts.
  • Recommended mitigations: enable Password Reset Protect, use authenticator-based two-factor authentication, and maintain unique passwords.
ProductsX MoneyGrok
VictimsX usersX
OrganizationsCross River Bank
CountriesUS

Coverage timeline

  1. · 15d ago
    TechCrunch · Security· 45
    X says attackers are targeting user accounts after the launch of X Money

    X is investigating a wave of unsolicited password reset emails targeting users after the X Money payments launch, with no confirmed breaches yet.