Massive wave of X password reset emails sparks phishing fears

Users are reporting a surge of unsolicited password reset emails from X, triggering concerns that attackers are exploiting the platform's recent financial integration. While the company denies any system-wide breach, product engineers have acknowledged that the influx of notifications may be a diversion for more sophisticated phishing attempts.

Today, 18:48
1,203 0
Massive wave of X password reset emails sparks phishing fears

X product engineer Mridul Singhai confirmed the company is investigating the deluge of automated alerts, stating there is currently no evidence of unauthorized account access. The timing of these notifications follows the rollout of X Money, a feature allowing Premium users to conduct peer-to-peer transfers and hold funds. Security experts warn that the presence of financial data makes these accounts high-value targets for bad actors.

Beyond the initial automated emails, reports suggest a secondary layer of deception. Users are receiving follow-up messages disguised as official security warnings from the platform. These emails direct recipients to fraudulent links designed to harvest login credentials. Singhai admitted this tactic is plausible and urged users to verify the sender's address, specifically looking for the 'x.com' domain and the blue BIMI authentication check mark.

To maintain account security, experts recommend avoiding links contained within suspicious emails entirely. Instead, users should navigate directly to the official X mobile application or manually type the URL into a browser to perform any password updates. Vigilance against urgent demands for action remains the primary defense against these credential-harvesting schemes.

Share

Comments (0)

Leave a comment

No comments yet. Be the first!