, , ,

Cybercriminals Target X Accounts Following Launch of X Money Payment Service

Social media platform X is currently investigating a widespread wave of unsolicited password reset requests targeting its users. The surge in unauthorized access attempts comes immediately after the official rollout of X Money, the platform’s new digital payment and banking service. Security teams are actively monitoring the situation, though they emphasize that no system breaches or successful account takeovers have been detected so far.

The issue came to light after numerous users reported receiving unexpected password reset emails. X product engineer Mridul Singhai addressed the situation, explaining that malicious actors appear to be targeting accounts under the assumption that the launch of X Money makes them lucrative targets. Singhai apologized for the influx of automated emails and assured users that the company is working diligently to resolve the issue. Meanwhile, X’s general counsel, James Burnham, issued a stern warning, stating that the platform’s legal and security divisions will aggressively pursue and prosecute anyone attempting to compromise user security.

According to technical assessments, attackers are exploiting public usernames to mass-trigger the platform’s password reset forms. X’s artificial intelligence chatbot, Grok, has been actively assisting users by providing instructions on how to secure their profiles. Security experts and the platform itself are urging users to enable two-factor authentication (2FA) and activate “Password Reset Protect” within their security settings to safeguard their accounts from potential unauthorized access.

Key Takeaways

  • X is investigating a massive wave of unsolicited password reset emails targeting users following the launch of its X Money payment service.
  • Platform engineers and AI assistant Grok confirm that while attackers are mass-triggering reset forms, there is currently no evidence of successful system breaches.
  • Users are strongly advised to enable two-factor authentication and Password Reset Protect to secure their accounts against unauthorized access.

Editor’s Analysis & Impact

The launch of X Money represents a pivotal step in X’s transition toward becoming an “everything app,” but it also elevates the platform’s profile as a high-value target for cybercriminals. By integrating financial services, including bank cards and creator payments, X has inadvertently incentivized bad actors who view user accounts as direct gateways to financial assets. This incident highlights a classic fintech challenge: rapid feature deployment must be matched by robust, proactive security measures. While X’s defense mechanisms appear to have held during this initial wave, the reputational risk is significant. To build long-term trust in its financial ecosystem, X must not only secure its backend infrastructure but also educate its user base on basic security hygiene, such as multi-factor authentication, to prevent social engineering and credential stuffing attacks.

Frequently Asked Questions

Q: Why am I receiving unsolicited password reset emails from X?
A: Attackers are using public usernames to mass-trigger X's password reset form in an attempt to gain unauthorized access, likely motivated by the recent launch of the X Money payment service.

Q: Has my X account been hacked?
A: X's security team has stated there is no evidence of successful system breaches or account takeovers. However, receiving these emails means your username is being targeted, and you should take steps to secure your account.

Q: How can I protect my X account from these reset attempts?
A: You should immediately enable two-factor authentication (2FA) and turn on "Password Reset Protect" in your X account's security and privacy settings.

AI Disclosure: This article is based on verified data and official reports. Our Team and AI have cross-referenced every financial detail with primary sources to ensure total accuracy.