X Says Hackers Targeted Accounts After Money Debut

X users reported a sudden wave of unwanted password-reset emails, unfamiliar login alerts, and temporary account lockouts starting September 1, 2026, just as the platform's new X Money payments feature became widely available.
X product engineer Mridul Singhai said attackers appear to believe that with X Money now live, they can gain unauthorized access to accounts. "We are actively investigating the issue and, so far, have found no evidence of any breaches," Singhai said, explaining that attackers were mass-triggering the password-reset form using public usernames rather than exploiting a new vulnerability. X general counsel James Burnham said the company's legal and security teams would "stop at nothing to identify, locate, and hold criminally accountable" those responsible.
Outside researchers who examined the activity traced it to a combination of older security gaps rather than a single fresh breach: a 2021-2022 API flaw that let attackers match emails to accounts, a 201-million-record user dataset that leaked in 2025 and has circulated on hacking forums, an active botnet testing stolen credentials, and a phishing campaign that has been running since July 2026. The botnet tested roughly 4.8 million accounts and confirmed 138 compromises, a rate of about 0.003%.
Two-factor authentication blocked an estimated 85.6% of the unauthorized login attempts, according to the researchers' findings. X Money, which uses banking infrastructure from Cross River Bank, rolled out this week to Premium and Premium+ subscribers in the US. X is urging users who have not already done so to enable two-factor authentication on their accounts.
Sources
- Mridul Singhai on XPrimary source
- TechCrunchSecondary
- BeInCrypto (via Yahoo Tech)Secondary
- The Daily HodlSecondary
Related
OpenAI Agent Breached Medicare Portal; Australia Told 84 Days Later
996 Zyxel Switches Looted in 48 Countries; Patch Due Sept. 24
Attacks on WordPress RCE Flaw Rose Tenfold After Sept. 22 Fix
Arista VeloCloud Zero-Day at CVSS 10.0; Patch Due Sept. 25
Check Point: VPN Flaw Under Attack Since Sept. 12, Patch by Sept. 25
Malware Lets 4 AI Models Vote on Its Next Attack Move
Microsoft Shuts Down AI Phishing Service That Hit 12,000 Inboxes
F5 Patches Exploited BIG-IP Flaw; CISA Deadline Is Sept. 25
Trending now
- Two New Islands Rise by Anak Krakatau After 25-Hour Eruption
- New Gut Bacterium C. immunis Cut Visceral Fat in Obese Mice
- Meta's 100-Gram VR Glasses Cost $1,299.99, Ship Spring 2027
- Kurihara, 11, One Win From Youngest Asian Games Medal
- Yu Zidi, 13, Wins Third Asian Games Gold in 4:28.56 400 IM
- Haaland Passes Ronaldo and Zlatan With 64th Norway Goal
- Claude Leads 26% of Anthropic's AI R&D, Up From 1% in March
- SEC Grants 5-Year Exemption for Tokenized Stock Trading
Comments
No comments yet. Be the first.