Since 1 September, X users have been receiving password reset emails and codes they never asked for, sometimes repeatedly. The company says it knows roughly why, and the reason is the payments service it just switched on.
In a public post, X product engineer Mridul Singhai said attackers appear to believe that the wider availability of X Money gives them a reason to try for access to accounts. Singhai said the company was investigating, apologized for the repeated emails, and added that X had found "no evidence of any breaches".
A reset request is not a reset
The distinction matters, because a wave of reset emails looks alarming and mostly is not. Requesting a password reset is something anyone can do with just an email address or username. Completing one requires control of the email inbox or phone number attached to the account. What the volume indicates is that somebody is submitting reset requests against X accounts in bulk, which is a probe, not a compromise.
So far there is no evidence that anyone has reached an X Money account or the money in one, and X has not confirmed that the payments rollout is what triggered the activity. The timing is suggestive. It is not proof of a technical link, and this has happened before on platforms with no payments product at all, including a comparable flood of Instagram reset emails earlier this year.
Why the accounts are worth more this week
X Money gives eligible US users financial services inside the app, including interest-bearing accounts, a Visa debit card and peer-to-peer payments, with Cross River Bank providing the banking infrastructure. That changes the value of an account takeover. An account with payment access, a large following, business use, or good social-engineering potential is now worth materially more to an attacker than it was a month ago, and criminals reprice targets quickly when a platform adds a wallet.
The real risk is the phishing that rides alongside
Even where attackers cannot finish a reset, the noise is useful to them. A steady stream of legitimate-looking reset messages is excellent cover for a fake one, and a convincing phishing email arriving in the middle of genuine reset traffic is much harder to pick out. Reset flooding also works as pure nuisance: it can push somebody into changing a password they did not need to change, bury a more important security alert, or persuade a frustrated user to turn off the very controls that are protecting them.
That pattern, real notifications being used as camouflage for fraudulent ones, is one IntelFusions has seen elsewhere, most recently in a kit that delivered its lure inside genuine Docusign emails. Attacks on US consumer platforms tend to follow the money in exactly this way.
Turn on reset protection and leave the emails alone
If a reset email arrives that you did not request, the correct response is to ignore it. Do not click the link, and do not enter the code. If you want to check your account, open the X app or type the address into your browser yourself.
- Never share a reset code or a two-factor code. Support staff and advertisers do not ask for them.
- Turn on password reset protection, under Settings and privacy, then Account, then Security. X says the setting requires additional account information before it will send a reset link or code at all, which stops the flood at the source.
- Use two-factor authentication, ideally an authenticator app or a hardware security key rather than SMS.
- Use a unique password. If you reuse your X password anywhere else, change it through X's settings and not through a link in an email.
- Watch for the signs of an actual takeover: posts or direct messages you did not send, profile changes, login alerts, or unfamiliar connected apps.
The full consumer guidance is published by Malwarebytes. The short version is that the emails themselves are a symptom, and the thing most likely to cost somebody money this week is the fake one hiding among them.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.