Attackers appear to be targeting X users following the launch of X Money, after several users reported receiving unsolicited password reset emails.
An X representative said the company was actively investigating the reports but had found no evidence that the attempted attacks had resulted in successful account compromises.
On Tuesday, X product engineer Mridul Singhai confirmed that the company was looking into users’ complaints about the wave of password reset requests.
“Attackers appear to believe that, now that @XMoney is widely available, they can gain unauthorized access to accounts,” he wrote. “We are actively investigating the issue and, so far, have found no evidence of any breaches. We apologize for the multiple emails and appreciate your patience as we work to resolve this.”
X Money is X’s newly launched payments service, offering users a bank card and other financial benefits. The service is also expected to make it easier for creators to receive payments on the platform, further expanding X’s digital economy.
However, the introduction of a financial service could also attract malicious actors seeking to exploit users and their accounts, which X says may be the case in the latest incident.
As of the time of writing, X had yet to publish details about the incident on any of its official company accounts and had not responded to a press inquiry seeking comment.
However, X’s general counsel, James Burnham, issued a strongly worded warning, saying the company’s legal and security teams would “stop at nothing” to identify, locate and hold criminally accountable anyone, anywhere, who attempts to target users of the platform.
As the attacks continue, X users have been warning one another about the issue and urging others to enable two-factor authentication if they have not already done so, as an additional layer of account protection.
X’s chatbot, Grok, has also responded to some posts by providing instructions for enabling two-factor authentication. In some of its responses, Grok confirmed that attackers were “mass-triggering” password reset requests using publicly available usernames.

