Something is happening on X. Over the past several weeks, users have been flooding forums and social media with reports of unexpected password reset emails arriving without warning. The messages are legitimate, originating from X's official systems. But the users never requested them.

An August 2026 thread on Reddit's r/Twitter community has become a clearinghouse for these reports, with users describing similar symptoms: password reset prompts for accounts they haven't touched, security alerts for login attempts from unfamiliar locations, and in some cases, temporary lockouts triggered by repeated failed authentication.

The pattern is familiar. Earlier this year, Instagram users experienced an almost identical wave of unrequested password reset emails. Forbes reported at the time that the surge appeared linked to a database of 17.5 million Instagram accounts that had been published on a dark web forum just hours before the attacks began. Meta eventually acknowledged the issue, stating it had fixed a flaw that allowed external parties to trigger reset emails.

The X Data Exposure That Never Went Away

X has not confirmed any new breach. But the platform has a recent history that makes it a ripe target. In early 2025, a data analyst using the handle "ThinkingOne" released a dataset containing over 200 million X user records on a popular hacker forum. According to Fox News, the leaked data included names, email addresses, usernames, locations, follower counts, and profile information. The breach traced back to a vulnerability first identified in X's bug bounty program in January 2022, which allowed attackers to query user data using only an email address or phone number.

Advertisement

That vulnerability was patched, but the data never disappeared. Security researchers at Safety Detectives partially verified the authenticity of the dataset by cross-referencing samples with public X profiles. The 2025 leak did not include passwords or financial information, but that distinction matters less than it might seem. With email addresses in hand, attackers don't need passwords to cause problems.

Credential Stuffing at Industrial Scale

The most likely explanation for what users are experiencing is credential stuffing: automated attacks that test stolen username-password pairs from unrelated breaches against X's login systems. Security researchers uncovered a particularly brazen example in April 2026, when Breakglass Intelligence analysts discovered an exposed command-and-control panel for a botnet specifically targeting X accounts. During a 12-minute observation window, the botnet tested 722,763 credentials and confirmed 18 new account compromises. Lifetime statistics showed the operation had already tested more than 4.8 million accounts.

The scope of the credential stuffing problem extends far beyond any single platform. According to recent industry data, credential stuffing now accounts for 31% of all social media hacks, and there are currently over 24 billion stolen credential pairs circulating in underground databases. Attackers are testing these credentials at a rate of roughly 26 billion attempts per month globally.

What X Users Should Do Now

X's own documentation confirms that it will proactively reset passwords for accounts that appear compromised or targeted by phishing. When this happens, the platform sends an email to the account's registered address with instructions. If you've received one of these emails without requesting it, someone is likely attempting to access your account.

Advertisement

The standard advice applies: enable two-factor authentication using an authenticator app rather than SMS, use a unique password that you haven't used anywhere else, and review your account's active sessions for any devices you don't recognize. X Premium subscribers receive priority support if their accounts are compromised, though response times remain slow even for paying customers. After the platform's 2023 restructuring, recovery times reportedly stretched from days to weeks for standard accounts.

X has not issued any public statement about the current wave of password reset reports. The company does not operate phone support, live chat, or a public-facing security communications channel. Its official support handle, @XSupport, rarely responds to individual cases.

Whether the current reports represent a coordinated campaign, fallout from older data exposures, or something else entirely remains unclear. What is clear is that X accounts are being targeted at scale, and the broader trend of sophisticated account-takeover attacks shows no signs of slowing. For users, the calculus is straightforward: if you haven't secured your X account with unique credentials and two-factor authentication, the window to do so before someone tests your email against a stolen credential list is narrowing.