CyberRakshakLabs | Threat Intelligence & Cyber Awareness
Thousands of X users have recently reported receiving unexpected password-reset emails, even though they never requested a password reset.
The timing has raised concerns because the activity follows the wider rollout of X Money, X's new payment service.
X product engineering has confirmed that the company is investigating the activity. Importantly, X has stated that it has not found evidence of a breach so far.
So what is actually happening?
The current evidence points toward attackers potentially mass-triggering password-reset requests against X usernames.
That distinction is extremely important.
π΄ 1. A PASSWORD-RESET EMAIL DOES NOT MEAN YOU WERE HACKED
This is the first thing users need to understand.
If you receive:
Reset your X password
it does not automatically mean:
β Your password was stolen
β Your email was hacked
β Your X account was compromised
β X's database was breached
X's password-recovery process allows a reset request to be initiated using information such as a public X username. X then sends the reset communication to the account's registered email address.
This means an attacker may be able to generate a reset email without already controlling your account.
2. WHAT ATTACKERS APPEAR TO BE DOING
The reported activity can be simplified as:
Public X username
β
Automated password-reset request
β
X sends legitimate reset email
β
Victim receives unexpected message
β
Attacker hopes the victim reacts
The technical action may be relatively simple.
The social-engineering opportunity is much more interesting.
An attacker can create confusion:
Someone is trying to hack my account!
The victim becomes anxious.
Then a second message may arrive:
Your X account has been compromised. Click here to secure it.
And that's where the real phishing attack can begin.
3. THE SECOND-STAGE PHISHING RISK
This is the part users should be particularly careful about.
Imagine receiving:
π§ Password reset request
Then:
π§ Security alert
Then:
π§ Account verification required
Then:
π Fake X login page
The attacker doesn't necessarily need to compromise X.
They can attempt to make you voluntarily provide the credentials.
This is classic social engineering:
Trigger β Panic β Urgency β Fake Recovery β Credential Theft
4. WHY THE TIMING MATTERS
X has recently expanded the availability of X Money, which introduces payment-related functionality to the platform.
That potentially increases the value of certain accounts.
Attackers may be particularly interested in accounts belonging to:
Cryptocurrency users
Traders
Influencers
Businesses
Creators
Public figures
Accounts connected to financial activity
X itself said attackers appear to believe that the wider availability of X Money creates an opportunity to gain unauthorised access to accounts.
Important:
That is X's current assessment of the attackers' apparent motivationβnot proof that X Money itself was compromised.
5. WHY HIGH-VALUE X ACCOUNTS ARE ATTRACTIVE
A compromised X account can be more valuable than just its follower count.
An attacker may use a compromised account to:
π£ Spread phishing
Send malicious links to followers.
π° Promote financial scams
Post fake investment or crypto offers.
πͺ Target cryptocurrency users
Impersonate trusted accounts.
π’ Hijack communications
Post fraudulent announcements.
π Conduct further social engineering
Use the victim's identity to target colleagues or contacts.
Therefore:
Account takeover can become a force multiplier.
6. THE PASSWORD RESET EMAIL ITSELF MAY BE LEGITIMATE
This is an interesting security distinction.
A victim may receive a genuine X-generated email, but the event can still be part of a malicious campaign.
Why?
Because the attacker may have triggered the legitimate recovery mechanism.
So the email may genuinely originate from X.
That doesn't mean:
The person requesting the reset is legitimate.
This is why blindly trusting an email because it appears to come from a legitimate service is dangerous.
7. HOW TO VERIFY THE MESSAGE
X's official guidance says X emails come from:
@X.com
or
@e.X.com
X also states that it will never ask for your X password by email and warns users about suspicious emails and links.
But don't rely only on the sender address.
Attackers can create convincing phishing messages.
Better approach:
Don't use the email to investigate the account.
Instead:
Open the X application directly
or
Type X.com into your browser yourself.
Then check:
Account security
Login activity
Connected applications
Two-factor authentication
Password settings
8. DON'T CLICK THE RESET LINK JUST BECAUSE YOU RECEIVED IT
If you did not request a password reset:
Don't interact with the email.
Don't:
β Click the link
β Reply
β Enter your password
β Enter an OTP
β Download attachments
β Call a phone number included in the message
Instead, open X independently.
X itself advises users to be cautious about unexpected emails and says it will not ask users to download software or sign in to a non-X website.
9. ENABLE PASSWORD RESET PROTECT
One of the most useful protections to enable is:
Password Reset Protect
This adds an additional requirement before a password reset can be initiated.
According to current reporting and X's support guidance, this can require confirmation of the account's email address or phone number before initiating the reset process.
This can reduce the effectiveness of automated reset attempts based only on publicly known usernames.
10. ENABLE TWO-FACTOR AUTHENTICATION
Password security alone isn't enough.
Use:
π Authentication app
or
π Security key/passkey where supported
as an additional authentication factor.
X itself recommends two-factor authentication as an additional protection layer for account security.
11. CHECK YOUR CONNECTED APPLICATIONS
A compromised account doesn't always involve password theft.
Third-party applications may have account access.
Go to your X security settings and review connected applications.
Remove anything you:
Don't recognise
No longer use
Don't trust
X specifically recommends revoking access to unfamiliar third-party applications when an account may have been compromised.
12. SECURE THE EMAIL ACCOUNT BEHIND X
Your X account is only as secure as the email account associated with it.
If someone controls your email account, they may potentially control password-reset workflows for other services as well.
Therefore:
Secure both:
X account
Recovery email account
Use:
π Strong unique passwords
π MFA
π Login alerts
π Recovery-code protection
13. WHAT IF YOU ACTUALLY CLICKED THE LINK?
The response depends on what happened.
If you only opened the page:
Close it.
Don't enter anything.
Update your browser if necessary.
If you entered your X password:
π¨ Change your X password immediately.
Do it directly through Xβnot through the email.
If you entered an OTP:
Treat the account as potentially compromised.
If you approved a third-party application:
Immediately revoke that application's access.
If suspicious posts or DMs appear:
Follow X's compromised-account recovery procedure.
14. ATTACK CHAIN
CURRENTLY REPORTED/LIKELY MODEL
Public X Username
β
Automated Reset Request
β
Legitimate X Reset Email
β
Victim Confusion
β
Potential Follow-up Phishing
β
Credential / OTP Theft
β
Account Takeover
β
Crypto / Financial / Phishing Abuse
β οΈ The final stages represent a potential attack scenario, not confirmation that this exact chain has occurred for every recipient.
π¬ CYBERRAKSHAKLABS TECHNICAL ANALYSIS
Stage Technique / Risk
Target Discovery Public X usernames
Initial Activity Automated password-reset requests
Delivery Legitimate X reset email
Social Engineering Fear / urgency
Potential Second Stage Phishing
Credential Theft Fake login page
MFA Theft OTP/social engineering
Persistence Third-party application access
Impact Account takeover
Secondary Impact Fraud / phishing / financial scams
π¨ WHAT IS CONFIRMED?
β Confirmed
X users are reporting unsolicited password-reset emails.
X says it is investigating the activity.
X has stated that it has not found evidence of a breach so far.
Attackers appear to be targeting accounts using the password-reset mechanism.
β οΈ NOT CONFIRMED
β X database breach
β Mass account takeover
β User password database leak
β X Money infrastructure compromise
β Confirmed theft of user credentials
There is currently no evidence establishing these claims.
π‘οΈ CYBERRAKSHAKLABS RESPONSE CHECKLIST
If you receive an unexpected X password-reset email:
1οΈβ£ DON'T PANIC
Receiving the email doesn't prove you're hacked.
2οΈβ£ DON'T CLICK
Don't use the email's link.
3οΈβ£ OPEN X DIRECTLY
Use the official app or manually enter X.com.
4οΈβ£ ENABLE PASSWORD RESET PROTECT
Add an additional barrier to reset requests.
5οΈβ£ ENABLE 2FA
Prefer stronger authentication options where available.
6οΈβ£ REVIEW CONNECTED APPS
Remove anything suspicious.
7οΈβ£ CHECK LOGIN ACTIVITY
Look for unfamiliar sessions/devices.
8οΈβ£ SECURE YOUR EMAIL
Your recovery email is part of your security perimeter.
9οΈβ£ CHANGE PASSWORD IF NECESSARY
Especially if you entered credentials into a suspicious website.
π MONITOR
Watch for unexpected:
Posts
DMs
Follows
Account changes
Password changes
π§ THE BIGGER CYBERSECURITY LESSON
This incident demonstrates a powerful concept:
A security notification can itself become part of an attack.
Users are trained to react immediately when they see:
Your account is under attack!
Attackers understand this psychology.
They can use a real security eventβor manufacture oneβto create panic.
The victim then becomes easier to manipulate.
π₯ CYBERRAKSHAKLABS SECURITY FORMULA
DON'T PANIC β DON'T CLICK β VERIFY DIRECTLY β HARDEN β MONITOR
When an unexpected security alert arrives:
STOP
Don't react emotionally.
VERIFY
Check directly inside the service.
HARDEN
Enable stronger authentication and reset protection.
MONITOR
Watch for suspicious account activity.
π FINAL TAKEAWAY
An unexpected password-reset email is a security signal, not proof of compromise.
Treat it seriouslyβbut don't let fear make your security decision for you.
The safest recovery link is the one you access yourself.
Open the official application.
Verify the event.
Secure the account.
And never surrender your credentials because an email tells you:
Act now.
π‘οΈ CyberRakshakLabs
Think Before You Click. Stay Aware. Stay Secure.
DON'T PANIC β DON'T CLICK β VERIFY DIRECTLY β HARDEN β MONITOR
When an unexpected security alert arrives, verify it inside the official service instead of following the message's instructions.