X Warns of Mass Password Reset Attacks Targeting New Money Feature
AI-generated from multiple sources. Verify before acting on this reporting.
SAN FRANCISCO — Social media platform X disclosed on Thursday that malicious actors are launching a coordinated campaign to hijack user accounts by mass-triggering password reset emails, a surge in activity coinciding with the recent rollout of its new financial service, X Money.
The company stated that attackers are exploiting the timing of the launch, believing that widespread adoption of the payment feature makes compromised accounts more lucrative. By flooding users with automated reset requests, the attackers aim to trick recipients into clicking malicious links or entering credentials on fraudulent sites, thereby gaining unauthorized access to their profiles and linked financial data.
X Money, which allows users to send, receive, and store funds within the application, is backed by FDIC-insured accounts through a partnership with Cross River Bank. The integration of banking capabilities has elevated the stakes for account security, as successful breaches could now lead to direct financial theft rather than just identity misuse or content manipulation.
In a statement released early Thursday morning, X confirmed it had detected the anomaly and was actively working to mitigate the threat. The platform is implementing additional safeguards, including enhanced rate limiting on reset requests and multi-factor authentication prompts for users attempting to change account credentials shortly after receiving a reset notification.
The attack vector relies heavily on social engineering. Victims who receive unsolicited password reset emails may be pressured into acting quickly, fearing they have lost access to their accounts. Once an attacker gains entry, they can potentially alter recovery information, lock out the legitimate owner, and attempt to transfer funds from the X Money wallet.
Security experts note that while phishing campaigns are common, the specific targeting of a newly launched financial product represents a strategic shift in how cybercriminals prioritize high-value targets. The timing suggests the attackers were monitoring the platform's development cycle to strike when user engagement with financial tools was at its peak.
X has urged all users to remain vigilant and not to click on links in unexpected emails, even if they appear to originate from the company. The platform advises users to verify any security alerts directly through the official application or website rather than via email links. Additionally, users are encouraged to enable two-step verification immediately if they have not already done so.
As of Thursday afternoon, X has not disclosed the number of accounts successfully compromised or the total volume of reset emails generated by the attackers. The company indicated that it is continuing to monitor traffic patterns and will provide further updates as the situation develops. Questions remain regarding whether the attackers have established a foothold in any specific user segments or if the campaign is purely opportunistic.
The incident underscores the growing intersection between social media security and financial crime, prompting renewed scrutiny of how platforms safeguard user assets during rapid feature expansions.