Breaking
INTLTrump threatens Iran with 'biggest attack of them all' amid escalating Strait of Hormuz strikesESTwo minors arrested for the murder of a gardener in Castellnou de BagesUKMaia Bouchier century powers England to record ODI chase win over IrelandINTLDutch police arrest 34 suspects after gangland shooting in rural villageINTLNepal flood death toll exceeds 1,000 as rescuers race to reach trapped workers and identify victimsUKFamily of seven-year-old girl killed in house fire says lives changed foreverDEFederal government sees Russian order behind drone attack on Leipzig/Halle airportCNXi Jinping arrives in Cairo for state visit to EgyptARIran launches a decisive operation against American interests in the regionUKFive held on suspicion of murder after newborn baby stabbed to death in SheffieldINTLTrump threatens Iran with 'biggest attack of them all' amid escalating Strait of Hormuz strikesESTwo minors arrested for the murder of a gardener in Castellnou de BagesUKMaia Bouchier century powers England to record ODI chase win over IrelandINTLDutch police arrest 34 suspects after gangland shooting in rural villageINTLNepal flood death toll exceeds 1,000 as rescuers race to reach trapped workers and identify victimsUKFamily of seven-year-old girl killed in house fire says lives changed foreverDEFederal government sees Russian order behind drone attack on Leipzig/Halle airportCNXi Jinping arrives in Cairo for state visit to EgyptARIran launches a decisive operation against American interests in the regionUKFive held on suspicion of murder after newborn baby stabbed to death in Sheffield
BackX Users Face Surge of Unrequested Password Reset Emails Amid Credential-Stuffing and Phishing Threats
X Users Face Surge of Unrequested Password Reset Emails Amid Credential-Stuffing and Phishing Threats
Developing
Decrypt43 minutes agoTech2 min read

X Users Face Surge of Unrequested Password Reset Emails Amid Credential-Stuffing and Phishing Threats

Quick Look

  • X users are receiving legitimate but unrequested password reset emails from X's own systems, coinciding with login alerts from unfamiliar locations and temporary account lockouts.
  • The activity is linked to credential-stuffing bots exploiting old data leaks and a separate phishing campaign mimicking X's security alerts.
  • Researchers confirm compromised credentials from past breaches are being tested against X accounts, while Proton Mail users report similar reset activity.

AI-generated summary

Why It Matters

X has faced recurring security issues related to credential stuffing and phishing, including a 2022 API vulnerability that exposed over 200 million users' data and a 2023 one-click account takeover bug. Similar incidents occurred on Instagram in January 2024 due to a bug allowing external parties to trigger password reset emails.

Font size

X users have spent the past several weeks getting password reset emails they never asked for, including a massive rush of them just today.

Some X users are also seeing login alerts from unfamiliar locations, and a handful report getting temporarily locked out of accounts they hadn't touched in weeks.

The reset emails are real, not spoofed—they come from X's own systems. So, the emails are legitimate, but they were unrequested from the legitimate owner of the account, which is what has everyone freaking out right now.

It's a familiar setup. Instagram users lived through nearly the same scare in January, when unrequested reset emails coincided with a dataset tied to 17.5 million accounts appearing on a dark-web forum hours earlier, Forbes reported at the time. Meta later confirmed a bug let outside parties trigger the reset emails, while denying any breach of its own systems.

An old flaw that keeps feeding new scares

X hasn't admitted or reported any recent breach, but the company is aware of the situation. In a recent tweet, X engineer Mridul Singhai apologized for the inconvenience and said they are not aware of any new breach, and hackers seem to be looking to control X accounts in an effort to gain access to X money.

It's possible that the recent rush of emails is related to a years-old exposure that may be resurfacing. A vulnerability in Twitter's API allowed an attacker to match email addresses and phone numbers to accounts in January 2022, and the resulting dataset covering more than 200 million users is now cataloged as its own entry on Have I Been Pwned. Site founder Troy Hunt found that 98% of the addresses in that dataset had already surfaced in earlier, unrelated breaches.

A newer file compounds the problem. In April 2025, a hacker using the handle ThinkingOne posted a 34-gigabyte file containing 201 million X user records—screen names, email addresses, account-creation dates, follower counts—on the forum BreachForums, according to Fox News.

Researchers at SafetyDetectives checked a sample against live X profiles and confirmed the emails matched active accounts. Twitter and X have handled versions of this before, from a 2016 sale of 33 million logins to a run of incidents Decrypt has chronicled over the years, including a 2023 bug that let anyone take over an account with one click before a researcher who found it got banned instead of paid.

Bots doing the legwork, and phishing doing the rest

Neither dataset needs a fresh hack to keep causing damage. Circulating email addresses feed two ongoing operations.

Researchers at Breakglass Intelligence found an unsecured command-and-control panel in April 2026 that was actively running stolen credentials against X accounts, testing 722,763 pairs in a single 12-minute observation window and confirming 18 new compromises.

Over its lifetime the botnet had run more than 4.8 million X accounts through the checker, with two-factor authentication blocking 85.6% of the attempts.

Separately, a phishing campaign that has nothing to do with any dataset has been targeting X users since July. Scammers are sending emails that nearly replicate X's real "new device login" alerts—same logo, same colors, correct grammar—asking recipients to click a link to secure their account, The Guardian reported. The links lead to fake pages built to steal a password or authorize a malicious app, and the campaign doesn't require any breach at all to work.

Some X users say they're also seeing unrequested reset activity on the Proton email service around the same time. Proton confirmed the disruption and is working on the issue.

Neither Proton nor any security researcher has confirmed a link, but it’s important in case that is the email you use for your X account.

What to do about it

X's own help documentation confirms it proactively resets passwords for accounts flagged as compromised or targeted by phishing, sending an email to the account's registered address with instructions. If one of those lands without you asking, someone has likely already tried your credentials, or you've been targeted by one of the phishing emails.

Check the sender address before clicking anything. X says it only emails from @X.com or @e.X.com and never asks for a password by email. Beyond that, switch two-factor authentication to an authenticator app, use a password unique to X, and check your account's active sessions and connected apps for anything unfamiliar.

One important thing to do is to check the "password reset protect" box on the “security and account access” option in the X configuration. This adds another layer of security, prompting a verification of the associated email address before a password reset request is sent out.

Also, do not contact anyone offering help. These are well known scams that appear when people mention specific keywords or ask for help on specific security topics. The link below is an example.

One more thing worth knowing if Proton is the inbox tied to your X account: Proton's status page reported a service disruption on September 1, attributing it to residual hardware failures from an overheating incident the week before and reduced capacity while engineers bring additional infrastructure online. It isn't connected to the X activity, but it could delay a reset email reaching you if you need one.

By the time researchers took the April botnet's control panel offline, it had confirmed 138 account compromises out of 4.8 million attempts—a fraction of a percent, but one multiplied across roughly 26 billion credential-stuffing attempts industry researchers estimate hit login pages worldwide each month.

What to Watch

AI outlook — possibilities, not facts

  • X will implement additional security measures such as enhanced rate limiting on password reset requests and broader user alerts about credential-stuffing risks

    Likely · Within weeks

  • Phishing campaigns mimicking X's security alerts will continue to evolve in sophistication, using realistic branding and grammar to deceive users

    Very likely · Within months

Open Questions

  • Whether the current reset email surge is directly linked to the April 2025 BreachForums dataset or the 2022 API leak
  • If X has identified the source of the credential-stuffing botnet command-and-control panel
  • Whether the Proton Mail reset activity is coincidental or connected to X account targeting

Related Topics

This article was originally published by Decrypt.

Related Stories

Switchboard Move Oracle Compromise Disrupts DeFi Apps Across Multiple Networks
Developing·3 hours ago

Switchboard Move Oracle Compromise Disrupts DeFi Apps Across Multiple Networks

Switchboard halted oracle deployments on Aptos, Sui, IOTA, and Movement after reports of a potential compromise in its Move-language implementations. At least three DeFi applications reported losses or freezes: Full Sail confirmed vault fund losses on Sui, Virtue detailed an IOTA price manipulation attack that minted millions in undercollateralized stablecoin and triggered liquidations, and Volo paused access as a precaution. Switchboard advised users to migrate temporarily but has not published a root cause or restoration timetable.

CryptoSlate
2 min read
Fake Claude Desktop App Distributes RevStealer Malware Targeting Crypto and Data
Developing·3 hours ago

Fake Claude Desktop App Distributes RevStealer Malware Targeting Crypto and Data

Cybersecurity firm Morphisec reports that a fake 'Claude Opus 5 Free Desktop' application is distributing RevStealer malware, which steals cryptocurrency, passwords, and browser data by mimicking legitimate user behavior to evade detection. The malware also targets over 50 crypto wallets and system settings, following Kaspersky's discovery of OkoBot, another crypto-focused malware framework.

Cointelegraph
1 min read
More on this topicx