In brief
X users have been posting since early August about password reset emails, login alerts, and account lockouts they never triggered.
X has not admitted or reported a new data breach; researchers trace the activity to a 2021-2022 API flaw, a 2025 dataset of 201 million records, an active botnet, and a phishing campaign running since July.
Proton, which some X users rely on as a recovery email, is separately dealing with a service disruption tied to a hardware failure, unrelated but relevant if that's the inbox tied to your account.
X users have spent the past several weeks getting password reset emails they never asked for, including a massive rush of them just today.Some X users are also seeing login alerts from unfamiliar locations, and a handful report getting temporarily locked out of accounts they hadn't touched in weeks.Myriad: When will OpenAI release GPT-6? Click to make your prediction.The reset emails are real, not spoofed—they come from X's own systems. So, the emails are legitimate, but they were unrequested from the legitimate owner of the account, which is what has everyone freaking out right now.It's a familiar setup. Instagram users lived through nearly the same scare in January, when unrequested reset emails coincided with a dataset tied to 17.5 million accounts appearing on a dark-web forum hours earlier, Forbes reported at the time. Meta later confirmed a bug let outside parties trigger the reset emails, while denying any breach of its own systems.An old flaw that keeps feeding new scaresX hasn't admitted or reported any recent breach, but the company is aware of the situation. In a recent tweet, X engineer Mridul Singhai apologized for the inconvenience and said they are not aware of any new breach, and hackers seem to be looking to control X accounts in an effort to gain access to X money.









