X said it is investigating widespread unsolicited password-reset emails after attackers appeared to mass-trigger resets using public usernames, while reporting no evidence of a platform breach.
The Details:
• X Money link: Product engineer Mridul Singhai said attackers may see X Money’s wider availability as an incentive to seek unauthorized account access.
• No confirmed breach: X said its investigation had found no evidence of compromised systems or widespread account takeovers.
• Reset mechanism: X’s account-recovery process can be initiated with a public username, prompting X to send a reset message to the account’s registered email.
• User protection: Users should enable Password Reset Protect and two-factor authentication, and avoid clicking unexpected reset links.