X says attackers are targeting user accounts after the launch of X Money

1 week ago 25

1:48 PM PDT · September 1, 2026

Attackers are attempting to people X users pursuing the motorboat of X Money. After galore X users reported receiving unsolicited password reset emails, a typical said the societal media institution was actively investigating the contented but had not yet recovered grounds that the hacks were successful.

On Tuesday, X merchandise technologist Mridul Singhai posted to the societal web that the institution was looking into users’ complaints astir the wide password reset attempts.

“Attackers look to judge that, present that @XMoney is wide available, they tin summation unauthorized entree to accounts,” helium wrote. “We are actively investigating the contented and, truthful far, person recovered nary grounds of immoderate breaches. We apologize for the aggregate emails and admit your patience arsenic we enactment to resoluteness this.”

X Money is X’s recently launched payments service, which includes a slope paper and different benefits. For X, the work could marque it easier for creators to cod payments connected the platform, further facilitating X’s integer economy.

Of course, wealth changing hands has a inclination to pull atrocious actors, which is what X says whitethorn beryllium happening here.

Attackers look to judge that, present that @XMoney is wide available, they tin summation unauthorized entree to accounts. We are actively investigating the contented and, truthful far, person recovered nary grounds of immoderate breaches.

We apologize for the aggregate emails and admit your patience… https://t.co/zf1pRWbqBX

— Mridul Singhai (@singhai) September 1, 2026

X has not posted details to 1 of its authoritative institution accounts arsenic of the clip of writing, and has not yet responded to our property enquiry astir the matter.

However, X wide counsel James Burnham wrote a threatening post, saying, “The ineligible and information teams @X volition halt astatine thing to identify, locate, and clasp criminally accountable immoderate idiosyncratic anyplace connected oregon disconnected world who attempts to victimize our platform’s users.”

As the attacks continue, users are informing each different astir the occupation and reminding others to alteration two-factor authentication, if it’s not already enabled, to support their accounts. X’s chatbot Grok has also replied to immoderate posts with the steps connected however to bash so, portion besides confirming that the attackers are “mass-triggering” the signifier for password resets utilizing nationalist usernames.

“No confirmed strategy breach oregon wide takeovers,” the AI bot said.

Yes, a wide question of unsolicited X password reset emails is hitting galore accounts close now. Attackers are mass-triggering the signifier utilizing nationalist usernames. No confirmed strategy breach oregon wide takeovers.

Enable Password Reset Protect (Settings and privateness > Security and…

— Grok (@grok) September 1, 2026

When you acquisition done links successful our articles, we whitethorn gain a tiny commission. This doesn’t impact our editorial independence.

Sarah has worked arsenic a newsman for TechCrunch since August 2011. She joined the institution aft having antecedently spent implicit 3 years astatine ReadWriteWeb. Prior to her enactment arsenic a reporter, Sarah worked successful I.T. crossed a fig of industries, including banking, retail and software.

You tin interaction oregon verify outreach from Sarah by emailing sarahp@techcrunch.com oregon via encrypted connection astatine sarahperez.01 connected Signal.

Read Entire Article