X is investigating a large-scale attempt to access user accounts through its password-recovery workflow, in which attackers used public usernames to trigger unsolicited password-reset emails. The activity emerged after the broad launch of X Money, the platform’s payments service, and reportedly targeted hundreds of thousands of users.
X said it disrupted the campaign and had found no evidence of successful breaches, mass account takeovers, or account compromises. The U.S. Department of Justice is working with X to identify the sophisticated cybercriminals involved; users are advised to enable two-factor authentication while X’s security and legal teams pursue the operators.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
X said it was investigating unsolicited password-reset emails sent to numerous users, which attackers appeared to trigger at scale using public usernames in an attempt to gain unauthorized account access after X Money's broad launch. X reported no evidence of successful breaches or mass account takeovers and advised users to enable two-factor authentication.
U.S. Attorney General Todd Blanche said sophisticated cybercriminals targeted hundreds of thousands of X users through the platform's password-recovery process and that X disrupted the attempt. The U.S. Department of Justice began working with X to identify those responsible; no successful compromises or attribution were disclosed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
5 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcemalwarebytes.com
Open sourcecyberveille.ch
Open sourceteiss.co.uk
Open sourcetechcrunch.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.