Attorney General Todd Blanche has said that the Justice Department is going after the cyber criminals who bombarded X users with unrequested password-reset emails this week.The platform maintains that no accounts were compromised because the attack was disrupted in time. Password reset attack on XOn September 2, 2026, Attorney General Todd Blanche wrote on X that “hundreds of thousands of X users” were affected by a coordinated attempt to hijack accounts through the password-recovery flow. He credited the company with stopping the attack in time and preventing user accounts from being compromised. Blanche added that investigators are “working closely with X to track down the criminals.” The attack first came to light on September 1, when users began posting about receiving waves of reset messages. Some inboxes reportedly collected about ten emails in a short window around 9:30 a.m. Eastern. The messages appeared to genuinely come from the company as they were sent from the official email (info@x.com) and carried the six-digit code needed to finish a reset. Despite this, X engineer Mridul Singhai said the company found no sign of a breach. He also apologized for the volume of emails. Singhai linked the attack to X Money, Elon Musk’s payment product that opened to the public in July, suggesting attackers “believe that, now that @XMoney is widely available, they can gain unauthorized access to accounts.”Has X been hacked before? X’s data has been loose for years following an incident in April 2025 in which a self-described data enthusiast using the handle “ThinkingOne” posted a 34GB file with 201,186,753 X records, including names, email addresses, usernames and follower counts. The vulnerability exploited by ThinkingOne came from a 2022 bug-bounty report that let attackers search for users using their email or phone number.Due to that history, there is speculation that X’s most recent attackers used a technique called credential stuffing, where automated tools test stolen username-password pairs against a login system. Credential stuffing reportedly accounts for 31% of social media hacks, with more than 24 billion stolen pairs in circulation. Researchers who found one X-focused botnet watched it test 722,763 credentials in a 12-minute stretch.U.S. authorities have been cracking down on cybercrime and have increased their focus on hacking. In late August, the DOJ and FBI announced court-authorized seizures of two hacking platforms, QScan and QTRouter, that a China state-sponsored group used against targets including NASA, the Federal Reserve and the U.S. Senate. Days later, on September 2, authorities working with CrowdStrike and the Shadowserver Foundation dismantled Sality, a Russia-based botnet that had reportedly infected more than 11 million devices over a 23-year run.Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free.