Close Menu
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
  • Home
  • News
    • Politics
    • Legal & Courts
    • Tech & Big Tech
    • Campus & Education
    • Media & Culture
    • Global Free Speech
  • Opinions
    • Debates
  • Video/Live
  • Community
  • Freedom Index
  • About
    • Mission
    • Contact
    • Support
Trending

X Kills Nitter And Xcancel, The Last Ways To Read Tweets Without Elon Watching

18 minutes ago

Kalshi Says It’s a Prediction Market. The 9th Circuit Says It’s Gambling.

19 minutes ago

Bitcoin enters ‘Rektember’ as rate-hike risk combines with seasonality to threaten rally

46 minutes ago
Facebook X (Twitter) Instagram
Facebook X (Twitter) Discord Telegram
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
Market Data Newsletter
Tuesday, September 1
  • Home
  • News
    • Politics
    • Legal & Courts
    • Tech & Big Tech
    • Campus & Education
    • Media & Culture
    • Global Free Speech
  • Opinions
    • Debates
  • Video/Live
  • Community
  • Freedom Index
  • About
    • Mission
    • Contact
    • Support
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
Home»Cryptocurrency & Free Speech Finance»X Data Breach? Users Are Getting Flooded With Password Reset Emails Nobody Requested
Cryptocurrency & Free Speech Finance

X Data Breach? Users Are Getting Flooded With Password Reset Emails Nobody Requested

News RoomBy News Room2 hours agoNo Comments6 Mins Read2 Views
Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email VKontakte Telegram
X Data Breach? Users Are Getting Flooded With Password Reset Emails Nobody Requested
Share
Facebook Twitter Pinterest Email Copy Link

Listen to the article

0:00
0:00

Key Takeaways

Playback Speed

Select a Voice

In brief

  • X users have been posting since early August about password reset emails, login alerts, and account lockouts they never triggered.
  • X has not admitted or reported a new data breach; researchers trace the activity to a 2021-2022 API flaw, a 2025 dataset of 201 million records, an active botnet, and a phishing campaign running since July.
  • Proton, which some X users rely on as a recovery email, is separately dealing with a service disruption tied to a hardware failure, unrelated but relevant if that’s the inbox tied to your account.

X users have spent the past several weeks getting password reset emails they never asked for, including a massive rush of them just today.

Some X users are also seeing login alerts from unfamiliar locations, and a handful report getting temporarily locked out of accounts they hadn’t touched in weeks.

Myriad: When will OpenAI release GPT-6? Click to make your prediction.

The reset emails are real, not spoofed—they come from X’s own systems. So, the emails are legitimate, but they were unrequested from the legitimate owner of the account, which is what has everyone freaking out right now.

It’s a familiar setup. Instagram users lived through nearly the same scare in January, when unrequested reset emails coincided with a dataset tied to 17.5 million accounts appearing on a dark-web forum hours earlier, Forbes reported at the time. Meta later confirmed a bug let outside parties trigger the reset emails, while denying any breach of its own systems.

An old flaw that keeps feeding new scares

X hasn’t admitted or reported any recent breach, but the company is aware of the situation. In a recent tweet, X engineer Mridul Singhai apologized for the inconvenience and said they are not aware of any new breach, and hackers seem to be looking to control X accounts in an effort to gain access to X money.

Attackers appear to believe that, now that @XMoney is widely available, they can gain unauthorized access to accounts. We are actively investigating the issue and, so far, have found no evidence of any breaches.

We apologize for the multiple emails and appreciate your patience… https://t.co/zf1pRWbqBX

— Mridul Singhai (@singhai) September 1, 2026

It’s possible that the recent rush of emails is related to a years-old exposure that may be resurfacing. A vulnerability in Twitter’s API allowed an attacker to match email addresses and phone numbers to accounts in January 2022, and the resulting dataset covering more than 200 million users is now cataloged as its own entry on Have I Been Pwned. Site founder Troy Hunt found that 98% of the addresses in that dataset had already surfaced in earlier, unrelated breaches.

Found 211,524,284 unique email addresses, looks to be pretty much what it’s been described as

— Troy Hunt (@troyhunt) January 5, 2023

A newer file compounds the problem. In April 2025, a hacker using the handle ThinkingOne posted a 34-gigabyte file containing 201 million X user records—screen names, email addresses, account-creation dates, follower counts—on the forum BreachForums, according to Fox News.

Researchers at SafetyDetectives checked a sample against live X profiles and confirmed the emails matched active accounts. Twitter and X have handled versions of this before, from a 2016 sale of 33 million logins to a run of incidents Decrypt has chronicled over the years, including a 2023 bug that let anyone take over an account with one click before a researcher who found it got banned instead of paid.

Bots doing the legwork, and phishing doing the rest

Neither dataset needs a fresh hack to keep causing damage. Circulating email addresses feed two ongoing operations.

Researchers at Breakglass Intelligence found an unsecured command-and-control panel in April 2026 that was actively running stolen credentials against X accounts, testing 722,763 pairs in a single 12-minute observation window and confirming 18 new compromises.

Over its lifetime the botnet had run more than 4.8 million X accounts through the checker, with two-factor authentication blocking 85.6% of the attempts.

Separately, a phishing campaign that has nothing to do with any dataset has been targeting X users since July. Scammers are sending emails that nearly replicate X’s real “new device login” alerts—same logo, same colors, correct grammar—asking recipients to click a link to secure their account, The Guardian reported. The links lead to fake pages built to steal a password or authorize a malicious app, and the campaign doesn’t require any breach at all to work.

Some X users say they’re also seeing unrequested reset activity on the Proton email service around the same time. Proton confirmed the disruption and is working on the issue.

We’re aware some users are having trouble connecting to Proton services. We apologize for the inconvenience.

Our team is investigating, updates will be shared on https://t.co/jqlWh1Ah7W

— Proton Support (@ProtonSupport) September 1, 2026

Neither Proton nor any security researcher has confirmed a link, but it’s important in case that is the email you use for your X account.

What to do about it

X’s own help documentation confirms it proactively resets passwords for accounts flagged as compromised or targeted by phishing, sending an email to the account’s registered address with instructions. If one of those lands without you asking, someone has likely already tried your credentials, or you’ve been targeted by one of the phishing emails.

Check the sender address before clicking anything. X says it only emails from @X.com or @e.X.com and never asks for a password by email. Beyond that, switch two-factor authentication to an authenticator app, use a password unique to X, and check your account’s active sessions and connected apps for anything unfamiliar.

One important thing to do is to check the “password reset protect” box on the “security and account access” option in the X configuration. This adds another layer of security, prompting a verification of the associated email address before a password reset request is sent out.

Also, do not contact anyone offering help. These are well known scams that appear when people mention specific keywords or ask for help on specific security topics. The link below is an example.

One more thing worth knowing if Proton is the inbox tied to your X account: Proton’s status page reported a service disruption on September 1, attributing it to residual hardware failures from an overheating incident the week before and reduced capacity while engineers bring additional infrastructure online. It isn’t connected to the X activity, but it could delay a reset email reaching you if you need one.

By the time researchers took the April botnet’s control panel offline, it had confirmed 138 account compromises out of 4.8 million attempts—a fraction of a percent, but one multiplied across roughly 26 billion credential-stuffing attempts industry researchers estimate hit login pages worldwide each month.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.

Read the full article here

Fact Checker

Verify the accuracy of this article using AI-powered analysis and real-time sources.

Get Your Fact Check Report

Enter your email to receive detailed fact-checking analysis

5 free reports remaining

Continue with Full Access

You've used your 5 free reports. Sign up for unlimited access!

Already have an account? Sign in here

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Telegram Copy Link
News Room
  • Website
  • Facebook
  • X (Twitter)
  • Instagram
  • LinkedIn

The FSNN News Room is the voice of our in-house journalists, editors, and researchers. We deliver timely, unbiased reporting at the crossroads of finance, cryptocurrency, and global politics, providing clear, fact-driven analysis free from agendas.

Related Articles

Media & Culture

X Kills Nitter And Xcancel, The Last Ways To Read Tweets Without Elon Watching

18 minutes ago
Media & Culture

Kalshi Says It’s a Prediction Market. The 9th Circuit Says It’s Gambling.

19 minutes ago
Cryptocurrency & Free Speech Finance

Bitcoin enters ‘Rektember’ as rate-hike risk combines with seasonality to threaten rally

46 minutes ago
Cryptocurrency & Free Speech Finance

SEC Proposes New Standards for US Transfer Agents

52 minutes ago
Cryptocurrency & Free Speech Finance

Cathie Wood’s Ark Invest Buys $37 Million in Bitcoin and Payments Firm Block

53 minutes ago
Media & Culture

Free Speech Unmuted: The Process Is The Punishment: ABC v. FCC with Stuart Benjamin

1 hour ago
Add A Comment
Leave A Reply Cancel Reply

Editors Picks

Kalshi Says It’s a Prediction Market. The 9th Circuit Says It’s Gambling.

19 minutes ago

Bitcoin enters ‘Rektember’ as rate-hike risk combines with seasonality to threaten rally

46 minutes ago

SEC Proposes New Standards for US Transfer Agents

52 minutes ago

Cathie Wood’s Ark Invest Buys $37 Million in Bitcoin and Payments Firm Block

53 minutes ago
Latest Posts

Free Speech Unmuted: The Process Is The Punishment: ABC v. FCC with Stuart Benjamin

1 hour ago

Guidance on public photography should be shared with everyone in the UK not just asylum seekers. Photo: Getty Images for Unsplash+ Asylum seekers in the UK are being misled by the Home Office over laws about photographing people in public places and are being threatened that their asylum claims might be refused and could be kicked out of the country. On 19 August, the Home Office issued a poster entitled “Do not photograph or film people in public” as part of a series of guidance over consequences of behaviour for those seeking asylum. The poster is part of a nine-page booklet that aims to help asylum seekers understand what is expected of them when living in the UK and covers issues such as sexual consent and domestic abuse. The release of the booklet is controversial because the guidance it contains applies to everyone in the UK and not just asylum seekers. Its publication now could be seen as a politically motivated sop to those who want to crack down on all immigration, even though Britain is legally bound to admit genuine refugees. In the introduction, the Home Office says, “We understand that coming to a new country can be difficult, and that laws and customs here may be different from your home country.” The poster says, “In the UK, you should not take pictures or videos of someone without their permission. This includes taking pictures or videos in public spaces, like streets of parks, or in private spaces, like at home.” However, the poster is misleading. There is a common misconception that photographing people in public places without their consent is illegal. It is not. There are some situations where there are restrictions, for example where photography is restricted by law, such as outside military facilities where photography is prohibited because of national security concerns. Photography is also not permitted where an individual has a reasonable expectation of privacy, such as in the changing room of a clothes shop. Many commercial, privately owned spaces also have rules regarding photography. Sheffield’s Meadowhall shopping centre, for example, says filming and photography is not permitted unless authorised. Where there are no restrictions, consent is not required by law but many legitimate street photographers follow codes of conduct where they might seek consent. The Royal Society of Photographers, for example, recommends that “particular care should be taken when photographing children and vulnerable people, with consideration given to consent, safeguarding, privacy and the potential impact of making or sharing an image”. It adds, “Photographers should also consider how images of identifiable people are subsequently used, especially where their use could imply endorsement or raise concerns about commercial exploitation.” Repeated photography of a person without their consent could be illegal if it crosses into harassing behaviour that is likely to cause alarm or intimidation. This is banned by the Protection from Harassment Act 1997. Photographers must also not share pictures of a sexual nature, for example upskirting, without the subject’s permission. This is banned under the Criminal Justice and Courts Act 2015. When asked about the poster, a Home Office spokesperson said: “We expect everyone who comes to the UK to abide by our laws. If they do not, they will face consequences, including the refusal of their asylum claim and removal from the UK.” They added, “These resources were produced for asylum seekers so there can be no possible misunderstanding of what we expect. The poster is designed to communicate two separate messages: Firstly, that individuals should not take photographs of others without their consent. Secondly, that sharing photographs or videos of a sexual nature without someone’s permission is a serious criminal offence.” There are subtle indications that the Home Office knew that what it was publishing was incorrect. Looking at the poster closely, it appears that the word “should” has been added later, suggesting that it previously said “must” – the font used is subtly different (see below). The information contained in a new Home Office poster is incorrect The Home Office did not respond to our request for comment when we asked about this. The spokeperson said of the poster, “It does not suggest that you can go to prison for taking someone’s photo in public.” There are nuances of English grammar at play here. One person who commented on the BPPA’s statement on Instagram said, “It doesn’t say there’s a legal requirement not to? It says you shouldn’t which to be quite frank is good, if simplified, advice for asylum speakers for whom English is not a first language.” However the heading of the poster is unequivocal. It says, “Do not”. Anyone, even those using English as a second language, would be unlikely to misconstrue that. The original wording still appears to be on the Home Office website. In the booklet’s introduction it says: “In the UK, we respect people’s privacy. This means you must not take photographs or videos of someone without their consent.” (emphasis mine). Photographers and photojournalists and their unions have been quick to call on the Home Office to clarify the poster. The British Press Photographers’ Association (BPPA) has commented on the document. It said, “Recently issued Home Office guidance that states permission is needed to photograph people in public is incorrect and harmful. There is no legal requirement to seek permission when photographing in public. The BPPA hopes an immediate correction will be issued.” Séamus Dooley, NUJ assistant general secretary, said: “This communication not only runs the risk of misleading asylum seekers, it could also have serious consequences for our members – particularly photographers and videographers who regularly carry out their work in public places. It also spreads public confusion that could serve to inhibit public interest journalism. Press photographers and other lens-based journalists perform a legitimate and important function in reporting and recording events in public spaces. “The union is very concerned that the spread of inaccurate information around the right to photograph and film people in public without permission could expose our members to increased hostility and harassment as well as wrongful accusations of criminality and unjustifiable stops by the police. This would undermine journalists’ right to report and the public’s right to know. READ MORE

2 hours ago

Robinhood's new crypto network is printing cash, and it's sending Arbitrum's token soaring

2 hours ago

Subscribe to News

Get the latest news and updates directly to your inbox.

At FSNN – Free Speech News Network, we deliver unfiltered reporting and in-depth analysis on the stories that matter most. From breaking headlines to global perspectives, our mission is to keep you informed, empowered, and connected.

FSNN.net is owned and operated by GlobalBoost Media
, an independent media organization dedicated to advancing transparency, free expression, and factual journalism across the digital landscape.

Facebook X (Twitter) Discord Telegram
Latest News

X Kills Nitter And Xcancel, The Last Ways To Read Tweets Without Elon Watching

18 minutes ago

Kalshi Says It’s a Prediction Market. The 9th Circuit Says It’s Gambling.

19 minutes ago

Bitcoin enters ‘Rektember’ as rate-hike risk combines with seasonality to threaten rally

46 minutes ago

Subscribe to Updates

Get the latest news and updates directly to your inbox.

© 2026 GlobalBoost Media. All Rights Reserved.
  • Privacy Policy
  • Terms of Service
  • Our Authors
  • Contact

Type above and press Enter to search. Press Esc to cancel.

🍪

Cookies

We and our selected partners wish to use cookies to collect information about you for functional purposes and statistical marketing. You may not give us your consent for certain purposes by selecting an option and you can withdraw your consent at any time via the cookie icon.

Cookie Preferences

Manage Cookies

Cookies are small text that can be used by websites to make the user experience more efficient. The law states that we may store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies, we need your permission. This site uses various types of cookies. Some cookies are placed by third party services that appear on our pages.

Your permission applies to the following domains:

  • https://fsnn.net
Necessary
Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
Statistic
Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
Preferences
Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
Marketing
Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.