X is investigating reports of mass password reset attempts targeting users following the launch of its new payments service, X Money.
The social media platform said it had so far found no evidence that attackers successfully breached accounts, despite numerous users reporting unsolicited password reset emails.
X product engineer Mridul Singhai said on Tuesday that the company was investigating complaints linked to the password reset attempts.
“Attackers appear to believe that, now that @XMoney is widely available, they can gain unauthorized access to accounts,” Singhai wrote.
“We are actively investigating the issue and, so far, have found no evidence of any breaches. We apologize for the multiple emails and appreciate your patience as we work to resolve this.”
The incident comes shortly after the wider rollout of X Money, the company’s payments service, which includes a bank card and other financial features designed to enable transactions and make it easier for creators and users to receive payments through the platform.
The introduction of financial services could make X accounts more attractive targets for cybercriminals seeking access to payment-related information or funds.
While X has not provided technical details about the source of the password reset attempts, the company said attackers appear to be mass-triggering password reset requests using publicly available usernames.
X has not issued a detailed statement through its main official corporate accounts as of the time of reporting.
The company’s General Counsel, James Burnham, said X’s legal and security teams were pursuing those responsible.
“The legal and security teams @X will stop at nothing to identify, locate, and hold criminally accountable any person anywhere on or off earth who attempts to victimize our platform’s users,” he said.
Users have also been warning one another about the attempted attacks and encouraging account holders to enable two-factor authentication as an additional layer of protection.
X’s AI chatbot, Grok, has also responded to some user complaints by providing steps for enabling two-factor authentication and confirming that attackers were “mass-triggering” password reset requests.
The chatbot said there had been “no confirmed system breach or mass takeovers.”
The company said its investigation remains ongoing.















