The social media platform X announced on Tuesday that it is investigating reports of a significant number of users receiving unsolicited password reset emails, raising alarms about potential security vulnerabilities just as the company seeks to expand its financial services footprint.
Users across the platform began reporting last week that they had received password change verification codes and reset links despite not initiating any such requests. The timing of the incident coincides with the recent rollout of X Money, the company’s ambitious entry into the digital payments space, prompting speculation among cybersecurity experts about possible coordinated attacks targeting the platform’s growing financial ecosystem.
“We’re aware that some users may be receiving unsolicited password reset emails,” X’s Safety account posted. “Our teams are actively investigating the source of these messages and whether they represent an automated system behavior issue or a potential external threat.” The company declined to provide specific details about the number of affected accounts or the technical nature of the investigation.
Password reset attacks represent one of the most common vectors for unauthorized account access. In typical scenarios, attackers flood a platform with automated reset requests, hoping that some percentage of users will click on malicious links disguised as legitimate password recovery emails. Alternatively, the requests could indicate that bad actors are systematically testing stolen username and password combinations obtained from data breaches on other platforms, a technique known as credential stuffing.
Cybersecurity researchers have long warned about the risks associated with integrating financial services into social media platforms. X Money, which allows users to send and receive money through the platform, creates new incentives for malicious actors to target user accounts. Access to a connected bank account or payment method could transform a compromised social media profile from a nuisance into a profitable enterprise for cybercriminals.
The incident comes amid ongoing scrutiny of X’s security practices. Since Elon Musk’s acquisition of the company in late 2022, the platform has undergone substantial workforce reductions, including cuts to trust and safety teams responsible for content moderation and security infrastructure. While the company has maintained that core security functions remain intact, outside experts have repeatedly expressed concerns about the implications of reduced staffing on the platform’s ability to respond to emerging threats.
“Every platform that handles sensitive user data, and especially financial information, becomes a more attractive target after announcing payment capabilities,” explained Marcus Chen, a cybersecurity analyst at Digital Threat Institute. “The timing of this password reset issue is concerning from a threat intelligence perspective because it aligns with the natural window when bad actors would be probing for vulnerabilities.”
Independent security researchers monitoring the situation have observed patterns consistent with automated attacks, though they caution against premature conclusions. Several security firms have noted increased dark web chatter about tools specifically designed to exploit social media platforms with integrated payment features.
X has advised users who receive unexpected password reset emails to ignore the messages and refrain from clicking any links contained within them. The company recommends that users enable two-factor authentication as an additional layer of security, though critics note that the platform’s two-factor options have faced criticism for requiring phone numbers, which can be vulnerable to SIM-swap attacks.
For users who have already clicked on suspicious links or entered credentials on what may have been fraudulent pages, X’s guidance is clear: change passwords immediately, review connected applications and payment methods, and monitor accounts for unauthorized transactions. The platform has not confirmed whether any financial accounts have been compromised as a result of the ongoing email issue.
The investigation into the unsolicited password reset emails remains active, with X coordinating with external security firms to determine the scope and origin of the activity. Users have been encouraged to report any suspicious activity directly through the platform’s help channels. As the company works to solidify its position in the competitive digital payments market, the incident underscores the challenges inherent in building consumer trust in financial services built on social media infrastructure.
Industry observers will be watching closely for any subsequent announcements from X regarding the results of its investigation, particularly whether the company determines the emails resulted from a technical glitch, a deliberate attack, or some combination of factors. The outcome could have significant implications for the platform’s broader strategy of expanding beyond social media into financial services.









