Summary
- Since early August, users of X have been receiving unsolicited password reset emails, login notifications, and account lockouts.
- X has not confirmed a new data breach; experts attribute these incidents to a flaw in the API from 2021-2022, a dataset of 201 million records from 2025, an active botnet, and a phishing campaign that began in July.
- Proton, a service some X users utilize for recovery emails, is experiencing a separate service disruption due to hardware issues, which could impact those linked to their accounts.
Over the past few weeks, X users have faced a surge of password reset emails they did not request, with a particularly high volume arriving today.
Additionally, some users are receiving login alerts from unfamiliar locations and a few have reported being temporarily locked out of accounts that hadn't been accessed in weeks.
Myriad: What’s the release date for OpenAI's GPT-6? Make your prediction here.The emails are genuine, originating from X's systems, but they are being sent without user requests, leading to widespread concern.
Is anyone else experiencing this???? pic.twitter.com/JOGCPo74VU
— Molly (@bigmagicdao) September 1, 2026
Someone has been trying aggressively to reset my X password.. I have 2FA but I’m still on edge..
Anyone else dealing with this? pic.twitter.com/5Jar5LSbp5
— cap.eth (@TheCapHimself) September 1, 2026
This situation mirrors a similar incident that occurred with Instagram in January, when users received unexpected reset emails following the appearance of a dataset involving 17.5 million accounts on a dark web forum. Meta later acknowledged that a bug had allowed unauthorized parties to trigger these emails, though they denied any breach of their systems.
Old Vulnerability Resurfacing
While X has not reported any recent breaches, they are aware of the situation. In a tweet, X engineer Mridul Singhai expressed regret for the inconvenience, clarifying that they have not identified any new breaches and that attackers seem to be attempting to gain control of X accounts for access to X money.
It seems attackers believe they can gain unauthorized access to accounts now that @XMoney is widely available. We are actively investigating and currently have no evidence of breaches.
We apologize for the multiple emails and appreciate your patience… https://t.co/zf1pRWbqBX
— Mridul Singhai (@singhai) September 1, 2026
The recent wave of emails might be connected to an old vulnerability that has resurfaced. In January 2022, a flaw in Twitter's API allowed attackers to link email addresses and phone numbers to accounts, resulting in a dataset of over 200 million users cataloged on Have I Been Pwned. Troy Hunt, the site's founder, reported that 98% of the addresses had already been exposed in previous breaches.
Found 211,524,284 unique email addresses, it appears to be as described.
— Troy Hunt (@troyhunt) January 5, 2023
A more recent dataset exacerbates the issue. In April 2025, a hacker named ThinkingOne released a 34-gigabyte file containing 201 million X user records, including screen names, email addresses, account creation dates, and follower counts on BreachForums, as reported by Fox News.
Researchers from SafetyDetectives verified that the emails matched active X accounts. X has dealt with similar issues in the past, including a 2016 incident involving 33 million logins and various incidents chronicled by Decrypt over the years, including a 2023 bug that allowed account takeovers with a single click before a researcher who discovered it was banned instead of rewarded.
Ongoing Threats from Bots and Phishing Scams
Both datasets continue to cause harm without the need for a new hack. The circulating email addresses support two ongoing operations.
Researchers at Breakglass Intelligence uncovered an unsecured command-and-control panel in April 2026 that was actively testing stolen credentials against X accounts, confirming 18 new compromises within a single 12-minute observation of 722,763 pairs.
Throughout its existence, the botnet has tested over 4.8 million X accounts, with two-factor authentication blocking 85.6% of attempts.
In addition, a phishing campaign unrelated to any dataset has targeted X users since July. Scammers are sending emails that closely mimic X's legitimate "new device login" alerts—utilizing the same logo, colors, and correct grammar—urging recipients to click a link to secure their account, as reported by The Guardian. These links lead to fraudulent pages designed to capture passwords or authorize malicious applications, and the campaign can function without any prior breach.
Some X users have also noted unrequested reset activity on the Proton email service around the same time. Proton has acknowledged the problem and is working to resolve it.
We’re aware that some users are experiencing issues connecting to Proton services. We apologize for the inconvenience.
Our team is investigating and updates will be provided on https://t.co/jqlWh1Ah7W
— Proton Support (@ProtonSupport) September 1, 2026
Neither Proton nor any security expert has verified a connection, but it is noteworthy if that email service is associated with your X account.
Recommended Actions
X's help documentation confirms that it proactively resets passwords for accounts flagged as compromised or targeted by phishing, sending an email to the registered address with instructions. If you receive such an email without prior request, it likely indicates someone has attempted to use your credentials or you have been targeted by phishing.
Before clicking on any links, verify the sender's address. X states it only sends emails from @X.com or @e.X.com and never requests passwords via email. Additionally, consider switching to an authenticator app for two-factor authentication, using a distinct password for X, and reviewing your account's active sessions and connected applications for anything suspicious.
It's also advisable to enable the "password reset protect" option in the “security and account access” section of X's settings. This feature adds an extra layer of security by requiring verification of the associated email address before sending out a password reset request.
Avoid engaging with anyone offering assistance in response to these issues, as such scams often arise when users mention specific keywords or seek help with security concerns. Below is an example of such a scam.
Have you been receiving X password reset requests today? That indicates your X account is not adequately secured. Want to fix it properly?
Call @opsek_io https://t.co/VNFpLa8O5t— Pablo Sabbatella (@PabloSabbatella) September 1, 2026
Lastly, if Proton is linked to your X account, be aware that Proton's status page reported a service disruption on September 1, related to residual hardware failures from an overheating incident the previous week, which could delay the arrival of any reset emails you may need.
By the time researchers shut down the April botnet's control panel, it had confirmed 138 account compromises out of 4.8 million attempts—a small fraction, yet still significant given the estimated 26 billion credential-stuffing attempts that researchers believe hit login pages globally each month.
