A large-scale attempt to reset passwords targeting user accounts occurred shortly after the scope of use for X Money, X (Twitter)'s payment service, was expanded. However, no evidence has been found so far that account takeovers or intrusions into X's systems actually succeeded.
TechCrunch reported on Sept. 1 that many X users said they repeatedly received password reset emails they did not request. Mridul Singhai (미르둘 싱하이), a product engineer at X, said, "As X Money begins to be widely offered, attackers appear to have judged they could gain unauthorized access to accounts." He said the company is investigating the matter. He added that no evidence of an actual breach has been found so far.
X Money is a financial service that X recently launched in the United States. Users can make transfers and pay bills through linked accounts, and X also offers an X Card that can be used at Visa merchants. X plans to use X Money accounts in the future to pay creator earnings. However, its official page says the service is currently limited to some users in the United States who are 18 or older.
The attack is believed to have triggered large numbers of X password reset requests using publicly available usernames rather than stealing passwords directly. Receiving a reset email does not in itself mean an account has been hacked. To actually change a password, someone would need access to additional authentication information such as the email address or phone number linked to the account.
James Burnham (제임스 번햄), X's head of legal, said, "Our legal and security teams will identify the attackers targeting users and hold them accountable."
X is recommending that users enable password reset protection and set up two-factor authentication if unwanted reset requests continue. Two-factor authentication can use an authentication app or a security key.