Loader
Advertisement

X's new payments app X Money hit by mass hacking attempt

Workers install lighting on an "X" sign atop the company headquarters, formerly known as Twitter, in downtown San Francisco, on Friday, July 28, 2023.
Workers install lighting on an "X" sign atop the company headquarters, formerly known as Twitter, in downtown San Francisco, on Friday, July 28, 2023. Copyright  AP Photo/Noah Berger
Copyright AP Photo/Noah Berger
By Indrabati Lahiri
Published on
Share Comments Add Euronews on Google
Share Close Button

Unsolicited password reset emails have hit X users after the launch of X Money, with the platform warning that hackers could be behind a wider phishing attempt.

X has revealed that hackers could be trying to attack users after the launch of X Money.

ADVERTISEMENT
ADVERTISEMENT

This follows several X users receiving surprise password reset emails. Although the social media giant has been looking into the issue, there is no evidence so far that these attack attempts were successful.

It is believed that attackers could be mass-triggering the form for password resets using public usernames

An X user discussing the recent breach attempt

X Money, the platform's payments service, launched on an invite-only basis in July before expanding to all Premium and Premium+ subscribers on 31 August.

It allows users to hold money, make and receive payments, as well as carry out peer-to-peer transfers, all on the X platform.

As such, any access that attackers may get to these users' accounts could have significant financial implications.

The company's general counsel, James Burnham, highlighted that "the legal and security teams @X will stop at nothing to identify, locate, and hold criminally accountable any person anywhere on or off earth who attempts to victimize our platform's users."

This has led to a flood of users taking to the platform to both spread awareness that this is happening and also remind others to use two-factor authentication, if they aren't already, for an added layer of protection.

Glen Bradley urges users to enable two-factor authentication to prevent attacks

The social media platform's Grok chatbot has also chimed in, replying to some posts with practical measures users can take to do so.

Could this be hiding a more dangerous phishing attack?

Although receiving an email for a supposed password change request doesn't automatically mean your account has been breached, especially if you have multi-factor authentication, some users are concerned that this latest incident could be hiding a wider phishing attempt.

Several users have also claimed that follow-up phishing emails have been sent out, along with these password reset confirmation emails. These have been framed as legitimate emails coming from X, which has added to the confusion and fear.

An X user warning about the potential of a wider phishing attack

These emails have been urging users to change their passwords, which is an expected follow-up after a security breach. However, they include a fake X link for users to do so, which can trick them into providing their login credentials to attackers.

As such, this is more likely to be an elaborate multi-step hacking and phishing attempt than previously expected.

X Money has already faced scrutiny for its reliance on partner banks like Cross River Bank, due to past regulatory enforcement actions against the bank, as well as the underlying reasoning behind the promotional 6% yield on deposits, compared to federal benchmarks.

Go to accessibility shortcuts
Share Comments Add Euronews on Google

Read more