Attackers are reportedly targeting X users following the launch of X Money. Several users have reported receiving unsolicited password reset emails, prompting concerns about potential account takeovers. An X representative said the company is investigating the activity but has so far found no evidence that any accounts were successfully compromised.
On Tuesday, X product engineer Mridul Singhai said the company was investigating complaints from users about a large number of password reset attempts.
“Attackers appear to believe that, now that @XMoney is widely available, they can gain unauthorized access to accounts,” he wrote. “We are actively investigating the issue and, so far, have found no evidence of any breaches. We apologize for the multiple emails and appreciate your patience as we work to resolve this.”
X Money is the company’s newly launched payments service, which includes a bank card and other features. For X, the service could make it easier for creators to receive payments directly through the platform, further expanding the company’s digital economy.
However, the introduction of financial services also creates a potentially attractive target for cybercriminals, which X believes may be behind the recent password reset activity.
As of the time of writing, X had not published details about the incident through one of its official company accounts and had not responded to a press inquiry seeking additional information.
X general counsel James Burnham, however, issued a strongly worded warning. “The legal and security teams @X will stop at nothing to identify, locate, and hold criminally accountable any person anywhere on or off earth who attempts to victimize our platform’s users,” he wrote.
While the activity continues, X users have been warning one another about the password reset attempts and encouraging others to enable two-factor authentication if they have not already done so.
X’s AI chatbot Grok has also responded to some users with instructions for enabling two-factor authentication. The chatbot additionally confirmed that attackers appear to be “mass-triggering” the password reset form by using publicly available usernames.
“No confirmed system breach or mass takeovers,” Grok said.



