X Examines Surge in Password Reset Emails, Finds No Evidence of Security Breach
X has started looking into a surge of unexpected password reset emails and confirmation codes, although its preliminary assessment indicates no signs of a breach to the platform’s systems.
Summary
- X users have reported receiving unsolicited password-reset notifications.
- No evidence of a breach was found during the company’s initial review.
- X recommends that users enable two-factor authentication and Password reset protection.
- The email activity coincided with the expansion of X Money to eligible users in the U.S.
X finds no breach in preliminary password-reset assessment
Mridul Singhai, a member of X’s Product Engineering team, announced on Tuesday that the company was investigating reports from users who received unrequested password-reset emails and codes. At the time of his statement, Singhai noted that X had not identified any compromise in its internal systems.
Numerous account holders noted that these messages arrived without any actions undertaken by them to alter their login information. Some users also mentioned receiving multiple password reset requests, raising concerns that unknown individuals might be attempting to gain control over their accounts.
Receiving an unsolicited password reset message does not necessarily indicate that an account’s password has been compromised or that unauthorized access has occurred. X permits anyone to initiate the recovery process by inputting an account username, email address, or phone number, after which a confirmation code is sent to the registered contact.
Nevertheless, users should not disclose a reset code or approve any password change that they did not request. Singhai urged users to activate two-factor authentication and refrain from clicking on links in unexpected emails.
He noted that attackers seem to assume that greater access to X Money could enhance the value of controlling X accounts. The company has not specified who might be behind the requests, nor disclosed the number of accounts affected or whether the activity originated from an automated source.
X security settings can restrict reset requests
According to X’s published account security guidelines, users can enable Password Reset Protection within the Security section of their account settings. Once activated, this feature necessitates additional identifying information before X sends a password-reset link or confirmation code.
Depending on the information associated with an account, users may need to provide an email address, phone number, or both. This requirement makes it more challenging for an unauthorized person to initiate repeated reset requests using just a public username.
Two-factor authentication provides an additional verification step during login. X currently supports text messages, authentication apps, and physical security keys, although the available options may vary based on account type and subscription level.
As per the platform’s password recovery instructions, reset codes sent via email are valid for 60 minutes. Completing a password reset will log the account out of all active X sessions, whereas changing a password from an existing session will keep the session used for the change active.
X specifically recommends that individuals who persistently receive unsolicited reset emails enable both Password Reset Protection and two-factor authentication. The security page also instructs users to ensure that the login page utilizes the x.com domain before entering their account credentials.
Instead of clicking on an email link, account holders can open the X app or type the platform’s address directly into a web browser to check their settings. X states that its legitimate emails originate from addresses ending in @x.com or @e.x.com, do not include attachments, and never request recipients to provide their password via email, direct message, or reply.
Users who have entered their credentials on unfamiliar websites should change their password via X, secure their linked email account, and revoke access for any unrecognized third-party apps, as advised by the company’s guidelines. A new password should also be distinct from those used for other services.
X Money expands access across the United States
The reports regarding reset emails surfaced as X broadened access to X Money for Premium and Premium+ subscribers in the U.S. This service allows eligible users to send money to one another directly through the social platform and relies on Cross River Bank for its banking infrastructure.
As previously reported by crypto.news, the X Money launch features deposit accounts, instant transfers, and a Visa debit card. The service also offers annual yields of up to 6%, while eligible X Card purchases can earn 3% cash back.
Cross River is responsible for holding customer deposits and facilitating X Money’s connections to the banking networks employed for transfers. Deposits directly held at a member bank of the Federal Deposit Insurance Corporation qualify for standard FDIC insurance of up to $250,000, subject to regulatory guidelines.
X Money also implements a cash sweep program to distribute funds across participating insured banks. Qualified customers may attain collective pass-through FDIC coverage of up to $10 million; however, X Payments is neither a bank nor an FDIC-insured institution.
The payment service incorporates passkeys for authentication and equips customers with tools to establish transaction limits and additional approval requirements. Visa offers security and risk management solutions for purchases made with the X Card.
Initial access was restricted to select Premium+ users when the payment service commenced utilizing Cross River’s infrastructure in June. Eventually, X extended access to Premium subscribers as it expanded throughout the U.S.
Despite Cross River’s previous collaborations with Ripple, neither X nor the bank has announced support for XRP or any other cryptocurrency within X Money. Currently, the service operates by transferring U.S. dollars through traditional banking and card networks.
X has also considered stablecoin creator payments
X’s financial strategies go beyond user-to-user transfers. In August, the company was exploring the possibility of USDC payments and other stablecoins for creator rewards, as per sources familiar with the discussions.
As of that report, no specific token, blockchain network, or launch date had been determined. Furthermore, X had not clarified whether creators would automatically receive stablecoins or if they would have the option to choose them as an alternative to bank payments.
These discussions preceded the platform’s planned transition from its Revenue Sharing program to Original Content Rewards on September 8. According to X’s stated eligibility criteria, creators need a minimum of 500 verified followers and 500,000 impressions on their Home Timeline from verified users over the past 90 days.
X has not confirmed the potential incorporation of digital assets into X Money. The platform’s payment service currently remains available only to eligible U.S. subscribers, and no timetable has been established for access by free accounts or users outside the country.
