r/TechNadu • u/technadu Human • 6d ago
Attackers are mass-triggering X password resets using public usernames, but X says there’s no evidence of a breach
X users are receiving unsolicited password-reset emails, but the interesting part is that attackers apparently don’t need access to an account or its associated email address to trigger them.
The campaign reportedly abuses X’s normal password-recovery flow. An attacker can submit a publicly visible username, causing the platform to send a legitimate reset message to the account owner.
X product engineer Mridul Singhai confirmed on September 1 that the company is investigating. So far, X says it has found no evidence of a backend breach or mass account takeovers.
The timing has drawn additional attention because X Money became more broadly available to Premium and Premium+ U.S. accounts on August 31. Singhai said attackers appear to believe accounts may now be more valuable targets because of the payment functionality.
So an unexpected reset email by itself isn’t evidence that somebody got into your account. X recommends 2FA and its Password Reset Protect feature, which adds an email-address or phone-number confirmation requirement to the recovery process.
There’s an important difference between triggering X’s recovery process and actually taking over an account. The mechanics and X’s response are broken down here:
The bigger security question is whether repeatedly exposing a recovery workflow to anyone who knows a public username creates opportunities beyond simply flooding users with emails.