TechNewsReel
Live

X Users Targeted by Surge of Legitimate Password Reset Emails

Attackers are triggering X's own security systems to target accounts, likely seeking 'X money' using legacy data.

TechNewsReel Newsroom · September 1, 2026

Users of X, formerly known as Twitter, are reporting a sudden surge of unsolicited password reset emails, sparking widespread concerns over account security. The influx of security alerts has led many to speculate that the platform is facing a new data breach or a coordinated credential stuffing attack.

According to a report from Yahoo Tech, the emails are legitimate and were sent directly from X's own systems rather than being spoofed by third parties. This confirms that attackers are actively triggering the platform's password recovery mechanism by inputting known user email addresses. Mridul Singhai, an engineer at X, stated that the company is not aware of any new breach. Singhai indicated that attackers appear to be targeting accounts specifically to gain access to "X money."

Historical Context

This wave of activity comes amid a history of security vulnerabilities for the platform. The current phenomenon has reignited discussions regarding previous data breaches in 2022 and 2025. Security analysts suggest that these historical leaks may have provided the datasets that attackers are now using to target accounts. By utilizing lists of emails from past breaches, bad actors can automate requests for password resets in an attempt to find weaknesses or trick users into granting access.

Industry Implications

While X denies a current breach, the scale of the email flood indicates a widespread effort to compromise user accounts. Such attacks highlight a persistent vulnerability in password recovery systems: the reliance on email as a primary trust vector. When attackers can trigger legitimate system emails, it creates a window for social engineering or account takeover if users have reused passwords across multiple services. For the broader industry, this serves as a reminder that even without a fresh breach, "stale" data from years prior remains a potent weapon for coordinated attacks.

What to Watch

Users are advised to remain vigilant and avoid clicking links in unsolicited emails, even those that appear legitimate. It remains to be seen if X will implement stricter rate-limiting on password reset requests to mitigate the flood. While the company maintains that no new data has been leaked, security researchers continue to monitor whether this activity is a precursor to a larger exploit or simply a brute-force attempt using legacy data.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.