X Users Hit by Password-Reset Email Flooding

Malwarebytes · Low sophistication
Last updated September 4, 2026

X is investigating a wave of unsolicited password-reset emails and codes being sent to users, which may be attackers trying to take over accounts as X Money becomes more available. X says it has found no evidence of a breach or successful account takeovers so far, but warns the reset-email “flood” could also help scammers hide phishing attempts among legitimate messages.

Key findings

  • Users reported “unexpected password-reset emails and codes” starting September 1.
  • X stated it has “no evidence of any breaches” and “no evidence of a breach or successful account takeovers so far.”
  • The activity appears consistent with bulk password-reset requests (reset flooding), which can be used as cover for scams or to pressure users into unsafe actions.
  • X Money’s rollout may increase attacker interest in X accounts, especially those with payments access or high-value influence.

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, Social media/communications teams, Finance teams, Customer support/helpdesk.
  • Affected industries: Social media / online platforms, Financial services (embedded payments), Consumer internet services.
  • Attack channels: email.
  • Impersonated: X (account security / password reset system).

Awareness takeaways

  • If you get an unexpected password-reset message, don’t click it, go directly to the app/site yourself.
  • Never share password reset codes or MFA/2FA codes, even if someone claims to be ‘support’ or ‘security.’
  • Treat alert ‘floods’ as a warning sign, attackers may be trying to hide a more serious scam in the noise.
  • Enable stronger account protections (reset protection and 2FA) to reduce account-takeover risk.

Red flags to watch for

  • You did not request a password reset but receive repeated reset emails/codes
  • High volume of messages intended to create urgency and confusion
  • Any request to share a reset code or 2FA code
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

On September first, people on X started getting a wave of password‑reset emails and codes they never asked for. X says there’s no evidence of a breach or takeovers so far. This is classic reset flooding: attackers hammer the reset button to spam you, then slip in a fake email or DM saying, 'We saw unusual activity, click here or send us your code to secure your account.' Your red flags: you didn’t request a reset, but you’re flooded with emails or codes. Someone emails or messages you asking for that reset code or your 2FA code. They claim to be X support, security, or helping with X Money access. If you get an unexpected X password‑reset message, ignore the link and any request for codes, open the X app or type x.com yourself if you actually want to check or change your account.

Similar attacks

Fake Tesla Token Presale Kit Steals Crypto

Fake Tesla Token Presale Kit Steals Crypto

Researchers found a turnkey scam kit sold on a cybercrime forum that lets criminals quickly stand up a fake crypto “presale” website styled to look like Tesla. The site uses pressure tactics and a fake investment dashboard to trick people into either handing over their wallet recovery phrase or…

August 12, 2026
Fake FIFA Ticket Sites Steal Cards and OTPs

Fake FIFA Ticket Sites Steal Cards and OTPs

Researchers and the FBI warn that criminals are luring World Cup fans to convincing fake FIFA ticket websites, often via social media ads and shared links. The scam steals payment details in real time during checkout, including card data and one-time passcodes (OTPs), while victims believe they are…

July 16, 2026
X Users Hit by Password Reset Email Flood

X Users Hit by Password Reset Email Flood

Users reported getting repeated, unsolicited password-reset emails from X after the launch of X Money. The emails appear legitimate, but attackers may be using them to confuse users and then send follow-up phishing messages that lead to fake X login pages to steal credentials. There is no confirmed…

September 3, 2026
Fake TikTok Rewards Trap Users in Payout Loop

Fake TikTok Rewards Trap Users in Payout Loop

Scammers are creating TikTok-branded “rewards” websites that promise big cash payouts for simple actions like daily check-ins and small tasks. The sites show large balances and use countdown timers to rush users, but when users try to withdraw, the site keeps adding new requirements (referrals,…

August 17, 2026
Vishing Console + Fake CCleaner Trap Users

Vishing Console + Fake CCleaner Trap Users

This bulletin highlights multiple real-world threats, including voice-phishing (vishing) operations that industrialize account takeovers and a fake CCleaner download site that installs spyware. The items provide concrete, repeatable lures (a vishing-driven takeover workflow and a lookalike software…

August 17, 2026
Fake WhatsApp/Instagram Sites Abuse HTTPS Padlock

Fake WhatsApp/Instagram Sites Abuse HTTPS Padlock

Researchers reported a phishing setup that clones WhatsApp and Instagram login pages and uses valid HTTPS (TLS) certificates to look legitimate. Victims are lured via WhatsApp messages about “verification,” “pending payments,” or “customer support,” then sent to typosquatted lookalike domains to…

August 11, 2026