Cybersecurity

X Says Hackers Targeted Accounts After Money Debut

Published 1 min readBy NewUJ Editorial Desk

Updated new information added

X Says Hackers Targeted Accounts After Money Debut
Photo: NewUJ
0 0
XWhatsAppTelegramLinkedIn

X users reported a sudden wave of unwanted password-reset emails, unfamiliar login alerts, and temporary account lockouts starting September 1, 2026, just as the platform's new X Money payments feature became widely available.

X product engineer Mridul Singhai said attackers appear to believe that with X Money now live, they can gain unauthorized access to accounts. "We are actively investigating the issue and, so far, have found no evidence of any breaches," Singhai said, explaining that attackers were mass-triggering the password-reset form using public usernames rather than exploiting a new vulnerability. X general counsel James Burnham said the company's legal and security teams would "stop at nothing to identify, locate, and hold criminally accountable" those responsible.

Outside researchers who examined the activity traced it to a combination of older security gaps rather than a single fresh breach: a 2021-2022 API flaw that let attackers match emails to accounts, a 201-million-record user dataset that leaked in 2025 and has circulated on hacking forums, an active botnet testing stolen credentials, and a phishing campaign that has been running since July 2026. The botnet tested roughly 4.8 million accounts and confirmed 138 compromises, a rate of about 0.003%.

Two-factor authentication blocked an estimated 85.6% of the unauthorized login attempts, according to the researchers' findings. X Money, which uses banking infrastructure from Cross River Bank, rolled out this week to Premium and Premium+ subscribers in the US. X is urging users who have not already done so to enable two-factor authentication on their accounts.

Sources

Report / request removal

Related

Comments

No comments yet. Be the first.