The U.S. Justice Department has opened an investigation into a coordinated password-reset attack that sent large numbers of unsolicited emails to users of X this week, according to Attorney General Todd Blanche. Blanche said “hundreds of thousands of X users” were affected, while the company said it stopped the activity before any accounts were taken over.
The incident surfaced after users reported repeated password-reset messages arriving in quick succession. X said the emails were legitimate system messages triggered through its account-recovery process, but added that it found no evidence of a broader platform breach.
Attack emerged through X’s recovery flow
Blanche said on September 2 that attackers tried to hijack accounts by abusing X’s password-recovery system. He credited the company with interrupting the campaign in time and said investigators were “working closely with X to track down the criminals.”
Reports of the attack began circulating a day earlier, on September 1, when users posted that they had received waves of reset emails. Some inboxes reportedly collected around ten messages within a short period near 9:30 a.m. Eastern.
X says no breach was detected
The reset emails appeared authentic because they were sent from info@x.com and included the six-digit code needed to complete a password change. That raised concern among users that attackers may have gained deeper access to the platform.
X engineer Mridul Singhai said the company found no sign of a breach and apologized for the volume of emails. He connected the campaign to X Money, Elon Musk’s payment product that opened to the public in July, saying attackers may believe that wider availability of the service creates an opportunity to gain unauthorized access to accounts.
Older data exposure fuels suspicion around tactics
Concern around the latest incident has been shaped by X’s earlier data-security problems. In April 2025, a self-described data enthusiast using the name ThinkingOne published a 34GB file containing 201,186,753 X records, including names, email addresses, usernames and follower counts.
That dataset was tied to a flaw originally disclosed in a 2022 bug-bounty report that allowed users to be looked up by email address or phone number. Against that backdrop, there has been speculation that the new attackers may have relied on credential stuffing, an approach in which automated tools test stolen username and password combinations against login systems.
The source article notes that credential stuffing accounts for 31% of social media hacks, with more than 24 billion stolen credential pairs said to be in circulation. In one previously observed X-focused botnet, researchers saw 722,763 credentials tested in a 12-minute span.
Part of a broader U.S. cybercrime crackdown
The DOJ’s response to the X incident comes amid a wider push by U.S. authorities against hacking operations. In late August, the Justice Department and FBI announced court-authorized seizures of QScan and QTRouter, two hacking platforms described as tools used by a China state-sponsored group.
According to authorities, that group targeted organizations including NASA, the Federal Reserve and the U.S. Senate. On September 2, officials working with CrowdStrike and the Shadowserver Foundation also dismantled Sality, a Russia-based botnet that had reportedly infected more than 11 million devices over 23 years.
What is confirmed so far
At this stage, the confirmed facts are limited: X says the password-reset wave was real, the emails came from its official address, and the company detected no breach of user accounts. The Justice Department, meanwhile, says it is actively pursuing those responsible.
Whether the attackers relied on old data, credential stuffing, or another method has not been established in the reported facts. The next confirmed step is the ongoing DOJ investigation being conducted in coordination with X.
Source: Cryptopolitan