Wave of unsolicited password reset requests hits thousands of X accounts

A widespread wave of unsolicited password reset emails has targeted thousands of accounts on X (formerly Twitter), including high-profile crypto personalities, journalists, and everyday users. Many users have reported receiving up to 8 to 10 automated reset emails in rapid succession.

What Is Actually Happening?

  • No Direct Breach Detected: Receiving a password reset email from X does not mean your account, password, or connected email address has been compromised.

  • Abuse of Public Username Recovery: By default, X allows anyone who knows a public @handle to submit a “Forgot Password” request. The platform automatically dispatches an official reset link to the email address on file.

  • Attacker Motives: Automated botnets and bad actors trigger these mass requests for credential stuffing reconnaissance, user harassment, or to cause panic in hopes that targets will fall for follow-up phishing attempts.

Critical Defense: Enable Password Reset Protect

By default, X sends reset links without requiring identity confirmation from the person submitting the request. Enabling Password Reset Protect forces anyone requesting a reset to enter the full email address or phone number tied to the account before an email can be triggered.

1.Navigate to Security Settings:

Open X, go to Settings and Privacy (or Settings and support), and select Security and account access.

2.Open the Security Sub-Menu:

Select Security from the options list to view authentication and account defense settings.

3.Enable Password Reset Protect:

Scroll to the Additional password protection section and check the box for Password reset protect. Confirm your current account password if prompted.

4.Review Active Sessions & 2FA:

Under Security – Two-factor authentication, ensure 2FA is set to a dedicated Authentication App or Hardware Security Key rather than SMS. Then, inspect Apps and sessions to revoke access for any unrecognized devices or legacy third-party tools.

PSA Action Checklist

  • Do not click links in unprompted reset emails, even if they appear legitimate.

  • Never share 2FA codes or verification links over direct message or third-party forms.

  • Use a unique password: If your X password is shared across other services, update it immediately via a password manager.

Want SEW higher in your Google results?Add as a preferred source

More in Analytics

View more

Start the conversation by posting the first comment

Join the conversation

Posting publicly · your email is never shown