Post

X Money Rollout Linked to Password-Reset Attacks

X Money Rollout Linked to Password-Reset Attacks

X Money Rollout Linked to Password-Reset Attacks 🚨

X has reported that attackers may be targeting accounts as its X Money payments service becomes more widely available. The company is currently investigating a surge of unsolicited password-reset emails sent to users. While these emails coincide with the broader rollout of X Money, raising concerns about potential account takeovers, X has found no evidence of a breach or successful account takeovers thus far.

Users began reporting unexpected password-reset emails and codes on September 1. In a public statement, X product engineer Mridul Singhai mentioned, “Attackers appear to believe that, now that @XMoney is widely available, they can gain unauthorized access to accounts.” Singhai reassured users that the company has found “no evidence of any breaches.”

X Money offers eligible US users access to various financial services, including interest-bearing accounts, a Visa debit card, and peer-to-peer payments. This makes certain X accounts more attractive targets, especially those with payment access, high follower counts, business use, or valuable social-engineering potential. The observed activity aligns with attackers submitting password-reset requests in bulk against X accounts. However, requesting a password reset does not equate to resetting a password, nor does it automatically indicate that an account has been compromised. X’s recovery process necessitates access to the email address or phone number linked to the account before a reset can be completed.

There is currently no evidence that anyone has accessed X Money accounts or funds. Furthermore, X has not confirmed that the X Money rollout caused the password-reset activity. While the timing is noteworthy, it does not establish a technical connection between the two events. It is possible that this activity serves as a cover for more serious issues. Even if an attacker cannot complete a reset, a high volume of legitimate-looking reset messages can facilitate scams. Additionally, reset flooding can act as a nuisance tactic, pressuring users into changing their passwords unnecessarily, obscuring more critical security notifications, or prompting them to disable security measures in an attempt to stop the alerts.

If you receive an X password-reset email that you did not request, it is crucial to follow security best practices:

  • Do not click links or enter codes from unexpected messages.
  • Instead, open the X app or type x.com into your browser to inspect or change account settings.
  • Do not share reset codes or two-factor authentication codes. X emphasizes that support staff, advertisers, and security teams will not contact you unexpectedly to request these codes.
  • Enable password-reset protection, which requires additional account information, such as an email address or phone number, before X sends a reset link or code. This setting can be found under Settings and privacy > Account > Security > Password reset protection.
  • Use two-factor authentication, preferably through an authenticator app or security key, as this adds another verification step if someone obtains or guesses your password.
  • Create a unique, strong password.
  • Stay vigilant for signs of an actual account takeover, including unfamiliar posts, direct messages, profile changes, login alerts, or unknown apps connected to your account.
  • Be cautious of phishing attempts, as fake messages can appear especially convincing when genuine reset emails are being sent out simultaneously.

For more details, you can read the full article here.

This post is licensed under CC BY 4.0 by the author.