X Money rollout linked to password-reset attacks

| September 4, 2026
The logo for the company X (formerly Twitter). The logo is the letter X

X says attackers may be targeting accounts because its X Money payments service is now more widely available.

The company is investigating a wave of unsolicited password-reset emails sent to users. While their arrival alongside the wider X Money rollout has fueled account-takeover concerns, X says it has found no evidence of a breach or successful account takeovers so far.

X users began reporting unexpected password-reset emails and codes on September 1. In a public post, X product engineer Mridul Singhai said:

“Attackers appear to believe that, now that @XMoney is widely available, they can gain unauthorized access to accounts.”

Singhai said X was actively investigating, apologized for the repeated emails, and added that the company had found “no evidence of any breaches.”

X Money gives eligible US users access to financial services within X, including interest-bearing accounts, a Visa debit card, and peer-to-peer payments. Cross River Bank provides the banking infrastructure behind the service.

This could make some X accounts more attractive targets, particularly accounts with payment access, high follower counts, business use, or valuable social-engineering potential.

The activity itself appears consistent with attackers submitting password-reset requests in bulk against X accounts. Requesting a password reset is not the same as resetting a password, however, and neither automatically means that an account has been taken over. X’s recovery process requires access to the email address or phone number associated with the account before someone can complete the reset.

There is no evidence that anyone has accessed X Money accounts or funds. Nor has X confirmed that X Money caused the password-reset activity. The timing is notable, but it does not prove a technical connection between the two.

Earlier this year, we saw a flood of Instagram password-reset emails, showing that similar activity can happen on platforms without payment services.

It could be a cover for something more serious. Even if an attacker cannot complete a reset, large volumes of legitimate-looking reset messages can provide useful cover for scams.

Reset flooding can also be a nuisance tactic. Repeated messages may pressure someone into changing their password unnecessarily, obscure more important security notifications, or encourage them to disable security controls in an attempt to stop the alerts.

How to stay safe

If you receive an X password-reset email that you did not request:

  • Do not click links or enter codes from unexpected messages. Open the X app or type x.com into your browser yourself if you want to inspect or change account settings.
  • Do not share reset codes or two-factor authentication codes. Support staff, advertisers, and “security teams” will not contact you unexpectedly to ask for them.
  • Turn on password-reset protection. X says this setting requires additional account information, such as an email address or phone number, before it will send a reset link or code. It is available under Settings and privacy > Account > Security > Password reset protection.
  • Use two-factor authentication, preferably an authenticator app or security key where available. This adds another verification step if someone obtains or guesses your password.
  • Use a unique, strong password. If you use your X password anywhere else, change it through X’s settings, not through a link in an email.
  • Watch for signs of an actual account takeover. These include unfamiliar posts, direct messages, profile changes, login alerts, or unknown apps connected to your account.
  • Stay alert for phishing. The strongest immediate consumer risk may not be a flaw in X itself, but phishing that imitates the reset process. A fake message can look especially convincing when genuine reset emails are arriving around the same time.
  • Use protection. An up-to-date, real-time anti-malware solution with web protection can warn you about malicious and fraudulent sites.

If you’re unsure whether a message is real, use Malwarebytes Scam Guard to check it and get advice about what to do next.


Scammers don’t need to hack you. They just need you to click once. 

Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.

About the author

Pieter Arntz

Malware Intelligence Researcher

Was a Microsoft MVP in consumer security for 12 years running. Can speak four languages. Smells of rich mahogany and leather-bound books.