Recently, a large number of X users have reported receiving password reset emails that they did not request. Some also saw alerts about logging in from unfamiliar locations, and a few accounts were temporarily locked. These emails came from X's official system, not from forged sender addresses, which has once again raised concerns about the security of accounts on the platform.
X claims no new leaks have been found.
Engineer X, Mridul Singhai, stated on a social media platform that the team has noticed the relevant situation and has not found any new evidence of data leakage at this time. According to him, the attackers may be attempting to control the accounts in order to further access features related to X Money.
This means that the large number of emails at present may not necessarily come from a new intrusion incident; it could also be a chain reaction resulting from the repeated exploitation of old data.
Old data is still being repeatedly utilized.
Researchers mentioned that the issue may be related to the continued spread of data leaked from the Twitter API vulnerability in early 2022. This vulnerability allowed attackers to match email addresses and phone numbers with accounts, affecting over 200 million users, and the relevant data was later included in the Have I Been Pwned dataset.
In April 2025, another file containing approximately 201 million user records from X was circulated on hacker forums. Public reports indicate that this file included information such as usernames, email addresses, account creation times, and the number of followers. After sampling and verification by researchers, it was confirmed that some of the email addresses matched still-active X accounts.
Password cracking and phishing attacks are carried out simultaneously.
In April of this year, security researchers discovered that a poorly protected control panel was being used to conduct bulk testing of X account credentials. Within a 12-minute observation period, the system tested 722,763 sets of account passwords and confirmed that 18 accounts were compromised.
According to the researchers, this bot network has initiated detections on over 4.8 million X accounts in total. Two-factor authentication has blocked most of these attempts, with an interception rate of about 85.6%.
Meanwhile, another round of phishing activities that began in July is also targeting users of X. The fraudulent emails closely mimic X's "new device login" notifications, enticing recipients to click on links that lead to forged pages with the aim of stealing passwords or inducing them to authorize malicious applications.
Users can check three settings.
X Help documentation indicates that the platform will proactively trigger password resets for accounts that are identified as potentially compromised or targets of phishing attempts, and send explanatory emails to the registered email addresses. Therefore, if a user receives such an email without having taken any action, it usually means that someone may have attempted to use the account credentials, or that the user has become a target of phishing.
- Does the sender's address come from @X.com or @e.X.com?
- Whether to enable two-factor authentication based on the verifier App.
- Is there any anomaly with the current login session and the connected applications?
In addition, the options “password reset protect” in the X settings can add an email verification step before password reset, further enhancing account security.
Additional information:Some users reported that they also observed abnormal reset activities in the Proton email account during the same period. Proton has confirmed a service interruption on September 1st, but there is currently no evidence to suggest a direct link between this and the abnormal email incidents related to X.











