2 SEP 2026 — X says attackers mass-triggered password reset forms using publicly available usernames after the launch of X Money, and that it has found no evidence of any breach. Reset spam is not a compromise. It is the setup for one, because it makes the phishing email that follows look like the thing the user just genuinely received.

What X has said

Product engineer Mridul Singhai said the company is actively investigating and has so far found no evidence of any breaches. The method described is mass-triggering of password reset forms using usernames that are public by design.

Users are advised to enable two-factor authentication and specifically Password Reset Protect, found under Settings and privacy, then Security. General counsel James Burnham said the company would stop at nothing to identify, locate and hold criminally accountable those responsible.

X Money is the company's payments service, offering bank cards and other benefits and handling creator payouts, and became widely available around the same period. No figure has been given for how many accounts received reset messages.

No breach foundX's position as of its statement
Public usernamesAll the attacker needed to trigger a reset
Password Reset ProtectThe setting that closes it, off by default
Not disclosedHow many accounts were targeted

What actually happened, mechanically

A password reset form takes an identifier and sends a message. On a platform where handles are public, anyone can submit any handle, and the system does what it was built to do.

The result is a flood of reset emails from the real sender to real accounts, all of them authentic and able to pass any authentication check. No system was entered and no credential was taken.

The attack's value is the anxiety it creates. Thousands of people, having just received an unexpected security message they did not request and do not understand, are now primed to act on the next one that arrives.

Why the follow-up is the actual attack

A phishing email that says someone tried to access your account is ordinarily met with suspicion, because the recipient has no reason to think anything happened.

Send the same email to someone who received four legitimate reset notifications an hour ago and it corroborates itself. The user has independent evidence that something is going on, supplied by the platform, and the fraudulent message is the one offering to explain it.

Timing a payments launch alongside this is unlikely to be coincidence. An account newly attached to a bank card is worth more than one that is not, and the population most likely to have just linked payment details is the one being made anxious.

Public handles are the design decision underneath this

Every social platform makes usernames public, because a handle is how people find and mention each other. That is not a flaw but a design choice, and it means the identifier used to log in is printed on every post a person has ever made.

Most services separate the two. A bank account is reached by a number the customer does not publish; an email account uses an address that is shared but is not usually the whole credential story. A social platform where the login identifier is also the public name has collapsed a distinction the rest of the industry keeps.

Which is why reset abuse recurs on these services and not on others, and why the mitigation has to be a second identifier rather than better rate limiting. Rate limiting slows an attacker down; it does not change the fact that they already know who everyone is.

The recommended setting is the right one

Password Reset Protect requires an additional identifier — an email address or phone number the account holder already registered — before a reset can be initiated. That single change makes the attack impossible, because a public handle is no longer sufficient input.

It is off by default, which is the ordinary trade every platform makes. A reset flow that demands extra information locks out users who have forgotten which address they used, and support cost is a real constraint on security defaults.

Two-factor authentication is separately worth having and does something different. It stops an attacker who already has the password; it does not stop the reset emails, and conflating the two is the most common misreading of advice like this.

One sourcing detail worth flagging

Part of the public characterisation of the incident — that there was no confirmed system breach or mass takeover — is attributed in the reporting to Grok, X's own AI assistant.

That is not an independent confirmation. A platform's chatbot answering questions about its owner's security incident is a statement from the company by another route, and it should be read with the same weight as the company's own words rather than more.

Nothing here suggests the characterisation is wrong, and X's engineer said the same thing directly. The narrower point is that when an outlet cites a platform's assistant as a source about that platform, it adds no independent verification. The underlying technique is the same as in a campaign we reported on that persuades people to paste a command into their own terminal: manufacture a plausible reason for the user to act, then supply the action.