Users of X (formerly Twitter) have been receiving, over the past few weeks, password reset emails they never requested, including a large flood of them just today.
Some X users are also seeing login alerts from unfamiliar locations, and some report having been temporarily locked out of accounts they had not accessed for weeks.
The reset emails are genuine, not spoofed — they come from X's own systems. So the emails are legitimate, but they were not requested by the account's rightful owner, which is causing panic at the moment.
It is a familiar scenario. Instagram users went through a similar scare in January, when unsolicited reset emails coincided with a dataset, relating to 17.5 million accounts, appearing on a dark web forum hours earlier, Forbes reported at the time. Meta later confirmed that a bug allowed third parties to trigger the reset emails, though it denied any breach of its own systems.
An old flaw that keeps causing new scares
X has not admitted to or reported any recent breach, but the company is aware of the situation. In a recent tweet, X engineer Mridul Singhai apologised for the inconvenience and said the company had no knowledge of any new attack, and that the hackers appeared to be trying to take control of X accounts in an effort to gain access to X Money.
It is possible that the recent flood of emails is linked to a years-old exposure resurfacing. A vulnerability in Twitter's API allowed an attacker to associate email addresses and phone numbers with accounts back in January 2022, and the resulting dataset, covering more than 200 million users, is now catalogued as its own entry on Have I Been Pwned. The site's founder, Troy Hunt, found that 98% of the addresses in that dataset had already appeared in earlier, unrelated leaks.
A more recent file compounds the problem. In April 2025, a hacker using the pseudonym ThinkingOne posted a 34-gigabyte file containing 201 million X user records — usernames, email addresses, account creation dates, follower counts — on the forum BreachForums, according to Fox News.
Researchers at SafetyDetectives checked a sample against active X profiles and confirmed that the emails matched active accounts. Twitter and X have dealt with versions of this before, from a sale of 33 million logins in 2016 to a string of incidents Decrypt has covered over the years, including a 2023 bug that allowed anyone to take over an account with a single click before the researcher who found it was banned rather than paid.
Bots doing the dirty work and phishing doing the rest
Neither dataset needs a new hack to keep causing damage. The email addresses in circulation feed two ongoing operations.
Researchers at Breakglass Intelligence found an unsecured command-and-control panel in April 2026 that was actively running stolen credentials against X accounts, testing 722,763 pairs in a single 12-minute observation window and confirming 18 new breaches.
Over its existence, the botnet ran more than 4.8 million X accounts through the checker, with two-factor authentication blocking 85.6% of attempts.
Separately, a phishing campaign unrelated to either dataset has been targeting X users since July. Scammers are sending emails that replicate X's genuine "new device login" alerts almost perfectly — same logo, same colours, correct grammar — asking recipients to click a link to secure their account, The Guardian reported. The links lead to fake pages designed to steal a password or authorise a malicious app, and the campaign requires no breach at all to work.
Some X users say they are also seeing unsolicited reset activity on the Proton email service around the same time. Proton confirmed the outage and is working on the issue.
Neither Proton nor any security researcher has confirmed a link, but it is worth noting in case that is the email address you use for your X account.
What to do about it
X's own help documentation confirms that it proactively resets passwords for accounts flagged as compromised or targeted by phishing, sending an email to the account's registered address with instructions. If one of these emails arrives without you having requested it, it is likely that someone has already tried to use your credentials, or that you have been targeted by one of the phishing emails described above.
Check the sender's address before clicking anything. X states that it only sends emails from @X.com or @e.X.com and never asks for a password by email. In addition, switch two-factor authentication to an authenticator app, use a unique password for X, and check your account's active sessions and connected apps for anything unusual.
One important step is to tick the "password reset protect" box under "security and account access" in X's settings. This adds another layer of security, requiring verification of the associated email address before a password reset request is sent.
Also, do not contact anyone offering help. These are known scams that appear when people mention specific keywords or ask for help on specific security topics. The link below is one example.
One more thing worth knowing if Proton is the inbox linked to your X account: Proton's status page reported a service outage on 1 September, attributing it to residual hardware failures from an overheating incident the previous week and to reduced capacity while engineers bring additional infrastructure online. It is not connected to the X activity, but it could delay the arrival of a reset email, should you need one.
By the time researchers took down the April botnet's control panel, it had confirmed 138 account compromises out of 4.8 million attempts — a fraction of a per cent, but one that scales up across roughly 26 billion credential-stuffing attempts that, according to industry researchers' estimates, hit login pages worldwide every month.
* Translated and edited with permission from Decrypt.
Looking for a wallet with strong returns but without the market's ups and downs? MB's Tokenised Fixed Income offers assets with returns of up to 18% a year, controlled risk and total security for your investments. Find out more!




