X users are being hit with a wave of legitimate password-reset emails, login alerts and account lockouts they never requested, triggering fears of a fresh data breach even as the company says it has found no evidence of a new compromise.
Reports of the unusual activity have circulated since early August, with some users receiving password-reset messages directly from X’s systems despite never initiating a reset. Others have reported unfamiliar login alerts and temporary lockouts affecting accounts they had not used in weeks.
The emails themselves appear to be genuine rather than spoofed. The problem is that someone else appears to be triggering the requests.
X has not disclosed a new breach of its systems. In a recent post, X engineer Mridul Singhai apologized for the disruption and said the company was not aware of any new breach, while warning that hackers appear to be attempting to take over X accounts to gain access to X Money.
That leaves a more unsettling possibility: attackers may not need to breach X at all. They could be using previously exposed account information, stolen credentials and phishing campaigns to identify and target users, while X’s own security systems generate the legitimate emails that arrive in their inboxes.
Old X Data Could Be Fueling New Account-Takeover Attempts
One possible source of that information dates back to a vulnerability in Twitter’s API that was exploited around 2021 and 2022.
The flaw allowed attackers to match email addresses and phone numbers with X accounts, helping create a massive dataset containing more than 200 million users. The database is now cataloged by Have I Been Pwned, whose founder Troy Hunt found that 98% of the email addresses had already appeared in earlier, unrelated breaches.
The significance of the old exposure is not necessarily that the same attackers are behind today’s reset requests. Rather, the leaked information could still help criminals identify which email address is connected to a particular X account and make those accounts easier to target.
A separate dataset surfaced in April 2025, when a hacker using the handle ThinkingOne reportedly posted a 34-gigabyte file containing 201 million X user records on BreachForums, according to Fox News. The records reportedly included screen names, email addresses, account-creation dates and follower counts.
Researchers at SafetyDetectives later checked a sample of the information against live X profiles and found that the email addresses matched active accounts. Together, such datasets can give attackers a roadmap to X users without requiring another vulnerability in the platform itself.
Credential Stuffing and Phishing Add to the Threat
The old data is only one part of the problem.
Researchers at Breakglass Intelligence discovered an unsecured command-and-control panel in April 2026 that was being used to test stolen credentials against X accounts. During a 12-minute observation window, the system tested 722,763 credential pairs and confirmed 18 successful compromises.
Over its lifetime, researchers said the botnet had run more than 4.8 million X accounts through its checker, while two-factor authentication blocked 85.6% of the attempts. At the same time, another campaign has been targeting X users through phishing emails since July.
The messages closely imitate X’s legitimate “new device login” alerts, using the platform’s branding, colors and polished language to make them appear authentic, The Guardian reported. Recipients are then urged to click a link to secure their accounts. Those links lead to fake pages designed to steal passwords or trick users into authorizing malicious applications. Unlike attacks based on leaked datasets, this campaign does not require a breach of X to succeed.
The combination creates a particularly dangerous environment. An attacker with old account data can identify potential targets, credential-stuffing campaigns can test whether stolen passwords still work, and phishing messages can exploit users who are already alarmed by unexpected security notifications.
There has also been confusion surrounding Proton, which some X users rely on as their recovery email provider. Proton confirmed a separate service disruption on September 1 caused by residual hardware failures following an overheating incident the previous week and reduced capacity while additional infrastructure was brought online.
Neither Proton nor security researchers have established a connection between that disruption and the X account activity. For users relying on Proton for X recovery emails, however, the outage could complicate the process of receiving legitimate security messages.
The Reset Email May Be the Warning, Not the Breach
X’s own help documentation says the platform can proactively reset passwords for accounts it identifies as compromised or targeted by phishing. In those cases, X sends instructions to the email address registered to the account.
That means receiving an unexpected reset email does not, by itself, prove that an attacker has breached X or gained access to the user’s email account. It can instead be a sign that someone is actively targeting the X account.
Users should verify the sender before interacting with any security message. X says legitimate emails come from addresses ending in @X.com or @e.X.com and that it will never request a password by email.
Users should also consider moving two-factor authentication to an authenticator app, using a password that is unique to X, and reviewing active sessions and connected applications for unfamiliar activity. X also offers a “password reset protect” option under its security and account-access settings. Enabling the feature adds another verification step before a password-reset request can be completed.
Users should be particularly wary of anyone offering unsolicited assistance through social media. Attackers frequently monitor public discussions about security problems and use them to identify people who may be vulnerable to follow-up scams. The scale of credential attacks also shows why the current activity deserves attention. By the time researchers took the April botnet’s command-and-control panel offline, it had confirmed 138 account compromises from 4.8 million attempts.
That is a tiny success rate — but at the scale of automated credential attacks, even a small percentage can translate into thousands of compromised accounts. For X users, the unsettling password-reset email may therefore be less evidence of a new breach than a warning that someone, somewhere, is already trying to get inside.