Following the launch of X Money, X’s new payments service, the social media platform has become the target of a coordinated attack campaign. Since early this week, numerous users have reported receiving unsolicited password reset emails, prompting X to issue a public statement on September 1, 2026. X product engineer Mridul Singhai confirmed the company is actively investigating the issue but has found no evidence of any successful breaches so far.
“Attackers appear to believe that, now that @XMoney is widely available, they can gain unauthorized access to accounts,” Singhai wrote in a post on X. “We are actively investigating the issue and, so far, have found no evidence of any breaches. We apologize for the multiple emails and appreciate your patience as we work to resolve this.”
Also read: This startup is fuel-injecting hydrogen to make cargo ships more efficient
What is X Money and why is it a target?
X Money is X’s newly launched payments service, which includes a bank card and other financial benefits. The service is designed to make it easier for creators to collect payments directly on the platform, further integrating a digital economy into X’s ecosystem. With money changing hands, the platform has become a more attractive target for bad actors looking to steal funds or personal financial information.
This is not the first time X has faced security challenges. In 2020, a major Bitcoin scam compromised high-profile accounts, and in 2022, a former employee was accused of spying for Saudi Arabia. The platform has since invested in security measures, but the launch of a payments feature introduces new risks and attack vectors.
Also read: Microsoft tests fix for hours-long Outlook and Exchange Online outage
What X is doing in response
X’s general counsel, James Burnham, issued a strongly worded warning to potential attackers: “The legal and security teams @X will stop at nothing to identify, locate, and hold criminally accountable any person anywhere on or off earth who attempts to victimize our platform’s users.”
Meanwhile, X’s AI chatbot, Grok, has been responding to user posts about the issue, confirming that attackers are “mass-triggering” the password reset form using public usernames. Grok also reiterated that there is “no confirmed system breach or mass takeovers” and advised users to enable Password Reset Protect via Settings and privacy > Security and account access.
As of the time of writing, X has not posted an official update on its company account or responded to press inquiries. However, the company’s engineering team is actively working on the issue.
How users can protect their accounts
In the meantime, users are taking to the platform to warn each other and share security tips. The most recommended actions include:
- Enable two-factor authentication (2FA) if not already enabled.
- Enable Password Reset Protect, which requires additional verification before a password reset can be completed.
- Avoid clicking any links in unsolicited password reset emails.
- Use a strong, unique password for your X account and change it regularly.
These steps can significantly reduce the risk of account compromise, even if attackers are attempting to trigger password resets en masse.
What to watch for next
As X continues its investigation, users should remain vigilant for any further suspicious activity. The company has not yet disclosed whether it has identified the attackers or their methods, but the legal threats from Burnham suggest that X is treating this as a serious criminal matter.
For now, the key takeaway is that no breaches have been confirmed, and the platform’s security team is actively monitoring the situation. Users who receive unsolicited password reset emails should not panic but should take the recommended security precautions to protect their accounts.
Disclaimer: This article is for informational purposes only and does not constitute financial advice. Cryptocurrency and digital payment services are volatile and carry inherent risks. Always conduct your own research before making financial decisions.