A large number of abnormal password reset emails have appeared.
Coinpaper
2h ago
Ai Focus
X has recently received a large number of abnormal password reset emails. The platform claims no new data breaches have been detected, but researchers point to old datasets, credential stuffing, and phishing activities as possible causes.
Helpful
No.Help

Recently, a large number of X users have reported receiving password reset emails that they did not request. Some also saw alerts about logging in from unfamiliar locations, and a few accounts were temporarily locked. These emails came from X's official system, not from forged sender addresses, which has once again raised concerns about the security of accounts on the platform.

X claims no new leaks have been found.

Engineer X, Mridul Singhai, stated on a social media platform that the team has noticed the relevant situation and has not found any new evidence of data leakage at this time. According to him, the attackers may be attempting to control the accounts in order to further access features related to X Money.

This means that the large number of emails at present may not necessarily come from a new intrusion incident; it could also be a chain reaction resulting from the repeated exploitation of old data.

Old data is still being repeatedly utilized.

Researchers mentioned that the issue may be related to the continued spread of data leaked from the Twitter API vulnerability in early 2022. This vulnerability allowed attackers to match email addresses and phone numbers with accounts, affecting over 200 million users, and the relevant data was later included in the Have I Been Pwned dataset.

In April 2025, another file containing approximately 201 million user records from X was circulated on hacker forums. Public reports indicate that this file included information such as usernames, email addresses, account creation times, and the number of followers. After sampling and verification by researchers, it was confirmed that some of the email addresses matched still-active X accounts.

Password cracking and phishing attacks are carried out simultaneously.

In April of this year, security researchers discovered that a poorly protected control panel was being used to conduct bulk testing of X account credentials. Within a 12-minute observation period, the system tested 722,763 sets of account passwords and confirmed that 18 accounts were compromised.

According to the researchers, this bot network has initiated detections on over 4.8 million X accounts in total. Two-factor authentication has blocked most of these attempts, with an interception rate of about 85.6%.

Meanwhile, another round of phishing activities that began in July is also targeting users of X. The fraudulent emails closely mimic X's "new device login" notifications, enticing recipients to click on links that lead to forged pages with the aim of stealing passwords or inducing them to authorize malicious applications.

Users can check three settings.

X Help documentation indicates that the platform will proactively trigger password resets for accounts that are identified as potentially compromised or targets of phishing attempts, and send explanatory emails to the registered email addresses. Therefore, if a user receives such an email without having taken any action, it usually means that someone may have attempted to use the account credentials, or that the user has become a target of phishing.

  • Does the sender's address come from @X.com or @e.X.com?
  • Whether to enable two-factor authentication based on the verifier App.
  • Is there any anomaly with the current login session and the connected applications?

In addition, the options “password reset protect” in the X settings can add an email verification step before password reset, further enhancing account security.

Additional information:Some users reported that they also observed abnormal reset activities in the Proton email account during the same period. Proton has confirmed a service interruption on September 1st, but there is currently no evidence to suggest a direct link between this and the abnormal email incidents related to X.

Tip
$0
Like
0
Save
0
Views 18
HQYC reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
Anthropic releases Claude Fable 5.1, with significantly improved benchmark scores
Anthropic Launches Claude Fable 5.1; the new model has seen significant improvements in scientific research and end-user coding tests compared to its predecessor, and has already been integrated with Claude API as well as several other cloud platforms.
Coinpaper
·2026-09-02 04:10:12
6
Anthropic releases Fable 5.1: Reducing costs and relaxing restrictions
Anthropic releases Fable 5.1 and Mythos 5.1; the new versions reduce costs, minimize misjudgment limitations, and promote high-privacy local deployment services.
TechCrunch
·2026-09-02 03:58:08
11
Ethereum: Bitcoin rebounds after falling below $77,000; Oil prices put pressure on the crypto market
The US-Iran conflict drives up oil prices and US Treasury yields; Bitcoin briefly fell below $77,000, and the net inflow of ETF in spot markets failed to reverse the short-term downward trend.
Coinpaper
·2026-09-02 03:20:16
20
web3: Apple Completes the Handover of Leadership, John Ternus Takes on the Role of CEO
Apple completes management transition, John Ternus takes over from CEO, and Tim Cook is reappointed as Executive Chairman.
TechCrunch
·2026-09-02 03:06:46
16
web3: US court dismisses all allegations against Solana parties in Pump.fun case
A U.S. court dismissed all charges against parties related to Solana in the Pump.fun class action, and the case continues to proceed around the allegations regarding the issuance of R tokens by the operator of Pump.fun.
SolanaFloor
·2026-09-02 02:14:04
22
View More