
X Password-Reset Email Flood: What Users Should Do
X is investigating a wave of password-reset messages as its X Money service expands. The company says it has found no evidence of a breach or successful account takeovers, but the genuine alerts can create cover for phishing and reset-code scams.
The short version
What you need to know
- X users began reporting unsolicited reset emails and codes on 1 September. An X product engineer said the company was investigating and had found no evidence of a breach.
- Submitting a reset request is not the same as changing a password or taking over an account. The timing alongside wider X Money availability does not establish that the payments service caused the activity or that funds were accessed.
- Do not click an unexpected reset message or share its code. Open X independently, review account security, enable reset protection and strong two-factor authentication, and look for unfamiliar sessions or account changes.
What is happening with X password resets?
Malwarebytes reports that X users started receiving unexpected password-reset emails and codes on 1 September. X product engineer Mridul Singhai said attackers appeared to believe the wider availability of X Money made accounts worth targeting and that the company was investigating the repeated messages.
The important boundary is what has not been established. X says it has found no evidence of a breach or successful account takeovers, and there is no evidence that X Money accounts or funds were accessed. The timing may explain attacker interest, but it does not prove that the payments product caused a technical weakness.
A reset request is not an account takeover
Anyone who knows or guesses an account identifier may be able to start a recovery flow. Completing it should still require control of the linked email address or phone number and any additional protections on the account. A burst of messages therefore shows attempted activity or nuisance requests, not automatically a changed password.
The flood still creates risk. Criminals can send a fake message among genuine alerts, pose as support and ask for the latest code, or hope that a tired recipient clicks without checking. Repeated mail can also bury a separate login warning or other important account notification.
What X users should do now
Do not use links or contact details in an unexpected reset email. Open the X app or type x.com yourself, then inspect active sessions, connected apps, recent account changes and security alerts. Sign out anything unfamiliar, set a strong password that is not reused elsewhere and enable two-factor authentication, preferably with an authenticator app or security key where supported.
X also offers password-reset protection under Settings and privacy, Account, Security. That setting requires extra account information before a reset link or code is sent. Never give a reset or two-factor code to someone who contacts you as support, and secure the linked email account because it is part of the recovery chain.
Where a VPN helps — and where it does not
A reputable full-tunnel VPN can encrypt supported traffic between your device and the VPN provider on an untrusted local network. That can reduce local Wi-Fi observation while you open the genuine service, but it does not validate an email or decide who requested a reset.
A VPN cannot stop somebody submitting recovery requests, distinguish a real support message from an impersonator, protect a code you voluntarily share or remove an attacker from an already compromised account. Independent navigation, unique credentials, strong two-factor authentication and session review address this risk more directly.
VPN Rocks view
Unexpected reset messages deserve attention without turning them into proof of a breach. Check the account through a separate route, preserve any suspicious messages and respond to evidence such as unknown sessions or profile changes rather than panic-resetting through an email link.
Payments can make a social account more attractive to criminals, but precise wording matters: targeting, a reset request and a successful takeover are three different stages. Users and platforms should report which stage the evidence actually supports.
Primary reading
Sources and further reading
We add plain-English context and practical advice. These links let you inspect the underlying reporting, research and official guidance directly.