Following the introduction of X Money, X users have reported receiving numerous unsolicited password reset emails. X product engineer Mridul Singhai confirmed that the company is actively investigating these complaints, noting that attackers appear to believe they can gain unauthorized access to accounts now that X Money is widely available.
Despite the widespread password reset attempts, X states it has not yet found evidence of any successful account breaches. The company apologized for the multiple emails and is working to resolve the issue. X's chatbot, Grok, also confirmed that attackers are "mass-triggering" the password reset form using public usernames, but reiterated that there is "no confirmed system breach or mass takeovers."
X Money is X's new payments service, which includes a bank card and other features designed to facilitate payments for creators on the platform. The introduction of financial transactions on the platform is believed to be attracting malicious actors, leading to the current wave of attack attempts.
Users are reminding each other to enable two-factor authentication (2FA) to protect their accounts. X general counsel James Burnham posted a statement indicating that X's legal and security teams will pursue those who attempt to victimize the platform's users.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
X users are receiving unsolicited password reset emails, which the company attributes to attackers attempting to gain unauthorized access after the launch of X Money. X is investigating the issue but has not found evidence of successful breaches, advising users to enable two-factor authentication.