X Users Hit by Password Reset Email Flood

eSecurity Planet · Medium sophistication
Last updated September 3, 2026

Users reported getting repeated, unsolicited password-reset emails from X after the launch of X Money. The emails appear legitimate, but attackers may be using them to confuse users and then send follow-up phishing messages that lead to fake X login pages to steal credentials. There is no confirmed evidence yet that the reset flood has resulted in successful account takeovers.

Key findings

  • Users reported receiving repeated, unsolicited X password-reset emails that appear to be legitimate security messages triggered via account recovery.
  • Attackers may be using public X usernames to trigger repeated reset requests, then following up with phishing designed to steal login credentials.
  • The addition of X Money increases the potential value of compromised X accounts for financial fraud.
  • The article states there is not yet confirmed evidence that these reset attempts led to successful account takeovers.
  • X has not officially acknowledged the issue publicly, but a product engineer reportedly apologized and said the company is investigating.

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, Finance, Social media/Communications, Customer support.
  • Affected industries: Social media, Financial services (payments), Consumers/end users.
  • Attack channels: email.
  • Impersonated: X Security / X Support.

Awareness takeaways

  • Treat unexpected password reset emails as a warning sign; don’t assume a follow-up message is legitimate just because earlier emails were real.
  • Avoid signing in via links in unexpected emails/DMs; go to the official app or type the site address yourself.
  • Enable two-factor authentication so a stolen password alone is less likely to lead to account takeover.
  • Be extra cautious with accounts that now connect to payments; attackers may target them for financial fraud.

Red flags to watch for

  • Unsolicited/unexpected password reset activity and a sudden burst of security emails
  • Follow-up message urges you to click a link to sign in rather than using the official app/site
  • Message appears timed to recent real reset emails to build trust
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Out of nowhere, your inbox blows up with real X password reset emails right after X Money launches. Attackers abuse account recovery using your public X username, then slip in a follow-up email: 'Your account needs to be secured or reset' with a link to a fake X login page. Here’s the trap: because the first reset emails are real, that phishing email feels legit, especially now that X Money makes your X account more valuable for financial fraud. If you get a reset flood, don’t click any email link, open the official X app or type x.com yourself to sign in and check your account.

Similar attacks

Fake WhatsApp/Instagram Sites Abuse HTTPS Padlock

Fake WhatsApp/Instagram Sites Abuse HTTPS Padlock

Researchers reported a phishing setup that clones WhatsApp and Instagram login pages and uses valid HTTPS (TLS) certificates to look legitimate. Victims are lured via WhatsApp messages about “verification,” “pending payments,” or “customer support,” then sent to typosquatted lookalike domains to…

August 11, 2026
Zero-Click Prompts Hijack AI Browsers via Email/X

Zero-Click Prompts Hijack AI Browsers via Email/X

Zenity demonstrated real-world attack chains where hidden instructions in emails or content on X can hijack AI “agentic browsers” (ChatGPT Atlas and the Claude Chrome extension). In the demos, the AI agent can be steered to perform actions in the user’s already logged-in sessions, sending phishing…

August 6, 2026
Apollo Breach Tied to IT Support Impersonation

Apollo Breach Tied to IT Support Impersonation

Apollo Global Management disclosed a data breach after attackers used social engineering to gain unauthorized access to certain cloud platforms over several days in July. The attackers obtained sensitive personal data (including Social Security numbers), highlighting how stolen credentials and…

August 25, 2026
Phish Adds Passkey That Survives Reset

Phish Adds Passkey That Survives Reset

Researchers described iAuthFlow v2, a phishing toolkit that steals a live Google login session and then uses that access to enroll an attacker-controlled passkey. Because passkeys are separate login methods, the attacker can often get back into the account even after the victim changes their…

August 24, 2026
Fake Bank Calls and ClickFix Drive Data Theft

Fake Bank Calls and ClickFix Drive Data Theft

The roundup describes multiple real-world attacks where criminals manipulate people, not just systems, such as fake bank support calls that trick victims into installing phone malware, and “ClickFix” lures that convince Mac users to run malicious commands. It also highlights an AI-assisted…

August 21, 2026
APT Groups Lure Targets Into Fake Zoom/Teams Meets

APT Groups Lure Targets Into Fake Zoom/Teams Meets

This threat trend report describes multiple real-world APT campaigns where attackers rely on social engineering and trusted services (Zoom/Teams, Telegram, webmail, GitHub) to steal credentials and access cloud accounts. Notable examples include fake meeting lures to deliver malware, and abuse of…

August 20, 2026