Password Reset Issue on X: Thousands of Reports, But Is It an Attack?
Since early August 2026, thousands of X users have reported receiving password reset emails they never requested, along with alerts of logins from unknown locations and, in some cases, temporary account locks for accounts that remained inactive for weeks. The X password reset issue sharply intensified on September 1, 2026, when a particularly massive wave of messages led many to wonder if there was an undisclosed data breach behind it.
Summary
- Key Points
- Wave of unwanted password reset emails hitting X users since August 2026
- X opens an investigation but does not confirm new data breaches
- Origins of the problem: API flaw from 2021-2022 and data leaks from 2023 and 2025
- Botnets and phishing: how X accounts are targeted
- Proton's service disruption complicates the situation for some users
- What users can do to protect their accounts
- FAQ
- Are the unsolicited password reset emails on X a sign of a new data breach?
- What should X users do if they receive unsolicited password reset emails?
- Is there a connection between Proton's email service issues and the difficulties related to X accounts?
- How effective is two-factor authentication against these attacks?
Key Points
- X users have been receiving password reset emails and unwanted login alerts at least since early August 2026, peaking on September 1.
- X has not confirmed any new data breaches but has opened an internal investigation into the matter.
- The likely causes trace back to a flaw in Twitter's API from 2021-2022 and a dataset of 201 million records leaked on BreachForums in 2025.
- A botnet tested over 4.8 million X credentials, confirming 18 compromised accounts in just a 12-minute window.
- Simultaneously, an active phishing campaign since July 2026 mimics real X login alerts to steal passwords.
Wave of unwanted password reset emails hitting X users since August 2026
The emails in question are not fake or forged: they genuinely come from X's official systems, making the situation even more unsettling for those receiving them without having requested them. The phenomenon recalls what happened to Instagram last January, when a similar wave of unsolicited resets coincided with the online appearance of a dataset linked to 17.5 million accounts, according to Forbes. In that case, Meta confirmed a bug that allowed external parties to trigger resets, but denied any breach of its internal systems.
X opens an investigation but does not confirm new data breaches
X has neither admitted nor reported any new breaches, but the company is aware of the problem and is actively monitoring it. Mridul Singhai, an engineer on X's Product Engineering team, publicly apologized for the inconvenience, explaining that, at this time, there is no evidence of compromise of the platform's systems. According to Singhai, attackers seem to believe that now that X Money has become widely available, controlling an X account is worth more, prompting them to attempt unauthorized access during this period.
The most likely cause of the current wave is not a recent attack, but the resurfacing of old data exposures that were never fully resolved. A vulnerability in Twitter's API allowed a malicious actor in January 2022 to associate email addresses and phone numbers with user accounts, generating a dataset covering over 200 million users, now cataloged as a standalone entry on Have I Been Pwned. The site's founder, Troy Hunt, verified that 98% of the email addresses contained in that dataset had already emerged in previous and unrelated breaches.
The situation became more complicated in April 2025, when a hacker using the pseudonym ThinkingOne published a 34-gigabyte file on BreachForums containing 201 million records of X users, including usernames, email addresses, account creation dates, and follower counts, as reported by Fox News. Researchers from SafetyDetectives verified a sample of that database by comparing it with active X profiles, confirming that the email addresses matched real accounts. This is not the first time Twitter and X have faced similar incidents: it ranges from the sale of 33 million credentials in 2016 to a series of documented incidents over time, including a 2023 bug that allowed account takeover with a single click.
Botnets and Phishing: How X Accounts Are Targeted
Neither of the two datasets needs a new cyber attack to continue causing damage: the circulating email addresses alone fuel two ongoing parallel operations. Researchers from Breakglass Intelligence identified in April 2026 an unprotected command and control panel that was executing credential stuffing attacks against X accounts, testing 722,763 credential combinations in a single 12-minute observation window and confirming 18 new compromises. Throughout its entire operation, the botnet has sifted through over 4.8 million X accounts, with two-factor authentication blocking 85.6% of the attempts.
Alongside this, completely independently, a phishing campaign targeting X accounts has been active since July 2026 that does not require any stolen dataset to function. According to The Guardian, scammers send emails that almost faithfully replicate the real "new device" alerts from X, using the same logo, colors, and correct grammar, asking recipients to click a link to secure their account. The link leads to fake pages created to steal passwords or authorize a malicious app: a classic example of botnet credential attacks that do not require a real breach of systems.
The Proton Outage Complicates the Picture for Some Users
Some X users have reported that they are unable to receive emails related to their accounts via Proton, the email service that many use as a recovery address. Proton has confirmed a service disruption starting from September 1, 2026, attributing it to residual hardware failures stemming from an overload issue that occurred the previous week and reduced capacity while technicians activate new infrastructure. Currently, there is no confirmed link between Proton's issues and incidents on X accounts: these are two separate matters, but those using Proton as a recovery mailbox may experience delays in receiving any reset emails.
-- Price
What Can Users Do to Protect Their Account {#What_Can_Users_Do_to_Protect_Their_Account}
Those receiving unsolicited emails should first verify that they truly come from @X.com or @e.X.com, as X never asks for passwords via email. X recommends switching from SMS authentication to an authentication app, using a unique password for the platform, checking active sessions and connected apps, and enabling the "password reset protect" feature in the account security settings, which requires additional verification of the associated email address before sending any reset requests. Equally important is not responding to those who spontaneously offer help in these cases: these are known scams that exploit the fear generated by incidents like this to steal further credentials.
A statistic helps frame the actual extent of the risk: when researchers disabled the control panel of the botnet in April, it confirmed 138 compromises out of 4.8 million attempts, a minimal fraction, but this needs to be multiplied by the approximately 26 billion credential stuffing attempts that, according to industry estimates, target login pages worldwide each month.
FAQ {#FAQ}
Are unsolicited password reset emails on X a sign of a new data breach? {#Are_Unsolicited_Password_Reset_Emails_on_X_a_Sign_of_a_New_Data_Breach}
X has not confirmed any new breach and is still investigating. The emails appear to be linked to old data leaks and ongoing attacks, not to a recent breach of systems.
What should X users do if they receive unsolicited password reset emails? {#What_Should_X_Users_Do_if_They_Receive_Unsolicited_Password_Reset_Emails}
Users should enable two-factor authentication, use unique passwords, check active sessions, enable the "password reset protect" feature, and avoid clicking on suspicious links.
Is there a link between Proton email service issues and difficulties related to X accounts? {#Is_There_a_Link_Between_Proton_Email_Service_Issues_and_Difficulties_Related_to_X_Accounts}
No direct link has been confirmed between Proton's hardware service disruption and security incidents on X accounts.
How effective is two-factor authentication against these attacks? {#How_Effective_is_Two-Factor_Authentication_Against_These_Attacks}
Two-factor authentication has blocked about 85.6% of credential stuffing attempts made by the botnet targeting X accounts.
Content created with the assistance of artificial intelligence and human editorial review.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Bitcoin ETFs: 2026 Flows Finally Return to Positive

Cosmos Hub Recovers 1.227 Million ATOM, Funds Stored in 4/6 Multisig Address

Federal Reserve Plans to Raise Regulatory Thresholds for Large Banks

INDODAX Highlights Strengthening of National Crypto Ecosystem at FEKDI x IFSE 2026 - Fintech World

Treasuries at 21-Year High: Impact on Stocks and Interest Rates

S&P 500 Closes Flat as 328 Stocks Decline

Fed proposes GENIUS Act rules for stablecoin reserves and bank issuers

xStocks adds Ledger hardware wallet support for tokenized shares

John Templeton: "Bull markets are born in pessimism"

Perpetuals on Gold, Oil, and Stocks: $117 Billion Traded in One Month

What Happens When the AI Bubble Bursts? MIT University Responds

IMF Calls for Fewer but Deeper Reforms to Address a More Vulnerable Global Economy

Meta's 'Muse' Sparks High Expectations... "An iPod Moment for AI" (Comprehensive)

大冰要抄底(专注交易) Price Prediction for October

Two men arrested for fraud with fake EURC

Mint launches connected Web3 gaming economy with MNTD rewards

Slow Fog: MemoryOS and OpenClaw Plugin Compromised

Nick Clegg's View on AI: The Real Risk is Power, Not Robots

135,694 Crypto-Millionaires, 92,272 Bitcoin-Millionaires in 2026

CFTC Chair Calls for "Mass Tokenization"! Wall Street Faces Three Barriers to Full On-Chain Adoption

AI: DeepSeek and Kimi Allegedly Redirected Queries to Claude Without Users' Knowledge

Citi Predicts Fed Will Keep Rates Unchanged in October and December, Resume Rate Cuts in June 2027

How to Rewrite Internet Rules When Everyone Has an Indefatigable Agent

Long.xyz Founder Emphasizes Asset Distribution and Scale Growth

PitchBook Predicts Kalshi Valuation Could Reach $42.1 Billion

FedNow readies cross-border support for U.S. banks







