< Back to situation

[REVISION HISTORY]

Security and account access issues on X

Updated 3 times since CLSTR started tracking revisions of this situation.

What changed

2026-09-04 08:26 UTC → 2026-09-04 19:33 UTC · added removed

Security incidents involving user accounts on the social media platform X have emerged, involving both individual phishing attacks and large-scale automated attempts. One instance involved a ‘Vote Link Phishing Scam’ where a user lost access to their account after clicking a malicious link. The attacker changed the registered email address and triggered an account suspension. The user subsequently sought legal recourse through the Grievance Appellate Committee, alleging that X’s automated systems failed to provide an effective redressal process. Following the launch of the ‘X Money’ payments service, the platform faced a wave of unsolicited password-reset emails. Attackers used public usernames to trigger the reset process at scale. X product engineer Mridul Singhai stated that attackers appear to be targeting accounts due to the new availability of X Money, though the company noted there was no evidence of successful breaches or system compromises at that time. In conjunction with these security concerns, X announced a transition for all U.S. creator payouts from Stripe to X Money. This change affects payments from the Original Content Rewards Program and user subscriptions, moving from a bi-weekly schedule to a system intended to provide instant access to funds. Creators located outside the United States will continue to use Stripe. As the situation developed, U.S. Attorney General Todd Blanche noted that the Justice Department is working with X to track down criminals responsible for attempts to hijack hundreds of thousands of accounts. A massive wave of unauthorized password-reset requests targeting hundreds of thousands of accounts began on September 1, 2026. Attorney General Blanche confirmed the coordinated attack but noted X successfully interrupted the wave by September 2. While no evidence of internal database breaches has been found, the expansion into financial services has drawn criticism from U.S.

Versions

  1. 2026-09-04 19:33 UTC Security and account access issues on X
  2. 2026-09-04 08:26 UTC Security and account access issues on X
  3. 2026-09-02 20:30 UTC Security and account access issues on X
  4. 2026-09-02 10:34 UTC Security and account access issues on X

Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.