X Data Breach? Users Are Getting Flooded With Password Reset Emails Nobody Requested

X engineers have acknowledged the issue, but have not confirmed a new data breach of its systems.

By Jose Antonio Lanz

6 min read

X users have spent the past several weeks getting password reset emails they never asked for, including a massive rush of them just today.

Some X users are also seeing login alerts from unfamiliar locations, and a handful report getting temporarily locked out of accounts they hadn't touched in weeks.

Myriad: When will OpenAI release GPT-6? Click to make your prediction.

The reset emails are real, not spoofed—they come from X's own systems. So, the emails are legitimate, but they were unrequested from the legitimate owner of the account, which is what has everyone freaking out right now.

It's a familiar setup. Instagram users lived through nearly the same scare in January, when unrequested reset emails coincided with a dataset tied to 17.5 million accounts appearing on a dark-web forum hours earlier, Forbes reported at the time. Meta later confirmed a bug let outside parties trigger the reset emails, while denying any breach of its own systems.

An old flaw that keeps feeding new scares

X hasn't admitted or reported any recent breach, but the company is aware of the situation. In a recent tweet, X engineer Mridul Singhai apologized for the inconvenience and said they are not aware of any new breach, and hackers seem to be looking to control X accounts in an effort to gain access to X money.

It's possible that the recent rush of emails is related to a years-old exposure that may be resurfacing. A vulnerability in Twitter's API allowed an attacker to match email addresses and phone numbers to accounts in January 2022, and the resulting dataset covering more than 200 million users is now cataloged as its own entry on Have I Been Pwned. Site founder Troy Hunt found that 98% of the addresses in that dataset had already surfaced in earlier, unrelated breaches.

A newer file compounds the problem. In April 2025, a hacker using the handle ThinkingOne posted a 34-gigabyte file containing 201 million X user records—screen names, email addresses, account-creation dates, follower counts—on the forum BreachForums, according to Fox News.

Researchers at SafetyDetectives checked a sample against live X profiles and confirmed the emails matched active accounts. Twitter and X have handled versions of this before, from a 2016 sale of 33 million logins to a run of incidents Decrypt has chronicled over the years, including a 2023 bug that let anyone take over an account with one click before a researcher who found it got banned instead of paid.

Bots doing the legwork, and phishing doing the rest

Neither dataset needs a fresh hack to keep causing damage. Circulating email addresses feed two ongoing operations.

Researchers at Breakglass Intelligence found an unsecured command-and-control panel in April 2026 that was actively running stolen credentials against X accounts, testing 722,763 pairs in a single 12-minute observation window and confirming 18 new compromises.

Over its lifetime the botnet had run more than 4.8 million X accounts through the checker, with two-factor authentication blocking 85.6% of the attempts.

Separately, a phishing campaign that has nothing to do with any dataset has been targeting X users since July. Scammers are sending emails that nearly replicate X's real "new device login" alerts—same logo, same colors, correct grammar—asking recipients to click a link to secure their account, The Guardian reported. The links lead to fake pages built to steal a password or authorize a malicious app, and the campaign doesn't require any breach at all to work.

Some X users say they're also seeing unrequested reset activity on the Proton email service around the same time. Proton confirmed the disruption and is working on the issue.

Neither Proton nor any security researcher has confirmed a link, but it’s important in case that is the email you use for your X account.

What to do about it

X's own help documentation confirms it proactively resets passwords for accounts flagged as compromised or targeted by phishing, sending an email to the account's registered address with instructions. If one of those lands without you asking, someone has likely already tried your credentials, or you've been targeted by one of the phishing emails.

Check the sender address before clicking anything. X says it only emails from @X.com or @e.X.com and never asks for a password by email. Beyond that, switch two-factor authentication to an authenticator app, use a password unique to X, and check your account's active sessions and connected apps for anything unfamiliar.

One important thing to do is to check the "password reset protect" box on the “security and account access” option in the X configuration. This adds another layer of security, prompting a verification of the associated email address before a password reset request is sent out.

Also, do not contact anyone offering help. These are well known scams that appear when people mention specific keywords or ask for help on specific security topics. The link below is an example.

One more thing worth knowing if Proton is the inbox tied to your X account: Proton's status page reported a service disruption on September 1, attributing it to residual hardware failures from an overheating incident the week before and reduced capacity while engineers bring additional infrastructure online. It isn't connected to the X activity, but it could delay a reset email reaching you if you need one.

By the time researchers took the April botnet's control panel offline, it had confirmed 138 account compromises out of 4.8 million attempts—a fraction of a percent, but one multiplied across roughly 26 billion credential-stuffing attempts industry researchers estimate hit login pages worldwide each month.

Get crypto news straight to your inbox--

sign up for the Decrypt Daily below. (It’s free).

Recommended News