cryptopolitan.com03 September 2026 19:08, UTC
Attorney General Todd Blanche has said that the Justice Department is going after the cyber criminals who bombarded X users with unrequested password-reset emails this week.
The platform maintains that no accounts were compromised because the attack was disrupted in time.
Password reset attack on X
On September 2, 2026, Attorney General Todd Blanchewrote on Xthat “hundreds of thousands of X users” were affected by a coordinated attempt to hijack accounts through the password-recovery flow. He credited the company with stopping the attack in time and preventing user accounts from being compromised.
Blanche added that investigators are “working closely with X to track down the criminals.”
The attack first came to light on September 1, when users began posting about receiving waves of reset messages. Some inboxes reportedly collectedabout ten emailsin a short window around 9:30 a.m. Eastern.
The messages appeared to genuinely come from the company as they were sent from the official email (info@x.com) and carried the six-digit code needed to finish a reset. Despite this, X engineer Mridul Singhai said the company found no sign of a breach. He also apologized for the volume of emails.
Singhai linked the attack to X Money, Elon Musk’s payment product that opened to the public in July, suggesting attackers “believe that, now that @XMoney is widely available, they can gain unauthorized access to accounts.”
Has X been hacked before?
X’s data has been loose for years following an incident in April 2025 in which a self-described data enthusiast using the handle “ThinkingOne” posted a 34GBfile with 201,186,753 X records, including names, email addresses, usernames and follower counts.
The vulnerability exploited by ThinkingOne came from a 2022 bug-bounty report that let attackers search for users using their email or phone number.
Due to that history, there is speculation that X’s most recent attackers used a technique called credential stuffing, where automated tools test stolen username-password pairs against a login system.
Credential stuffing reportedly accounts for 31% of social media hacks, with more than 24 billion stolen pairs in circulation. Researchers who found one X-focused botnet watched it test 722,763 credentials in a 12-minute stretch.
U.S. authorities have been cracking down on cybercrime and have increased their focus on hacking. In late August, the DOJ and FBI announced court-authorized seizures of two hacking platforms, QScan and QTRouter, that a China state-sponsored group used against targets including NASA, the Federal Reserve and the U.S. Senate.
Days later, on September 2, authorities working with CrowdStrike and the Shadowserver Foundationdismantled Sality, a Russia-based botnet that had reportedly infected more than 11 million devices over a 23-year run.
