Newsroom
2 September, 2026 / News / AI / Tags: password, emails, reset, email, singhai

Thousands of users received unexpected password recovery messages on Tuesday as the platform expands its payments service, with engineers finding no evidence of compromised systems
X users across the platform reported a sudden wave of unsolicited password-reset emails and confirmation codes on September 1, 2026. The messages, which originated from X’s own systems rather than spoofed senders, arrived without any request from account holders. Some individuals received multiple notices in short succession, with reports of as many as eight emails arriving within three minutes or up to ten over several hours.
The volume of reports included prominent cryptocurrency industry figures and multiple staff members at news organizations. In some cases, the emails reached addresses not widely associated with the accounts in public records. X allows anyone to initiate a password recovery process simply by entering a public username, after which the platform automatically sends a code or link to the registered email or phone number. An unsolicited message therefore does not by itself prove that passwords or account details have been exposed.
X Product Engineering team member Mridul Singhai addressed the reports directly. He confirmed that the company had begun examining the activity and stated that its initial review had turned up no evidence of any breach of internal systems.
Singhai linked the timing of the attempts to the broader availability of X Money, the platform’s peer-to-peer payment service. The feature, which relies on infrastructure from Cross River Bank, became available to eligible Premium and Premium+ subscribers with U.S. accounts. It supports instant transfers, deposit accounts offering annual yields of up to 6 percent, and a Visa debit card. Deposits held at participating FDIC-insured banks can qualify for standard insurance coverage, with a cash-sweep program potentially extending aggregate protection in certain cases. Officials at X and the bank have not announced support for cryptocurrencies within the service.
The company has not disclosed the number of accounts affected, the origin of the requests, or whether the activity stemmed from an automated campaign. Official accounts operated by X Support and X Money did not issue separate statements at the time of the initial reports.
X provides a setting called Password reset protection that can limit the ability of outsiders to trigger recovery emails using only a username. When enabled, the feature requires the requester to supply the email address or phone number already linked to the account before any reset code is sent. The platform also supports two-factor authentication through text messages, authenticator applications, and physical security keys, depending on account type and subscription status.
Reset codes sent by email remain valid for 60 minutes. Completing a password change logs the account out of all other active sessions. X’s official guidance advises users who receive repeated unsolicited resets to activate both Password reset protection and two-factor authentication. Legitimate messages from the company come only from addresses ending in @x.com or @e.x.com, contain no attachments, and never request a password by email or direct message.
Users are encouraged to open the X application or type the platform address directly into a browser rather than clicking links in unexpected emails. Anyone who may have entered credentials on an unfamiliar site should change the password through the official interface, secure the linked email account, and revoke access for any unrecognized third-party applications.
Reports of unexpected password-reset emails and login alerts had circulated among some users for several weeks before the sharp increase on September 1. Separate research has pointed to older datasets circulating online, including material tied to a 2021-2022 API vulnerability that matched email addresses and phone numbers to accounts, as well as a 2025 collection of roughly 201 million records. Credential-stuffing activity and phishing campaigns that mimic legitimate X login alerts have also been observed. None of these elements has been tied by the company to a new compromise of its current systems.
No widespread account takeovers have been confirmed in connection with the latest wave of emails. The platform has previously faced large-scale account issues, including a 2020 incident involving social engineering of staff that affected a limited number of high-profile accounts. In the current case, the activity appears to rely on publicly available usernames and X’s own recovery form rather than internal access.
X continues to investigate the reports while advising users to strengthen their account settings. The expansion of financial features on the platform has increased the potential value of compromised accounts, according to the engineering response, which may explain the renewed focus by external parties.









