HUNDREDS OF THOUSANDS OF X USERS TARGETED: U.S. DOJ Hunts Hackers Behind Massive Password-Recovery Attack
WASHINGTON — The U.S. Justice Department has joined forces with Elon Musk’s social-media platform X to track down cybercriminals behind an attempted attack targeting the password-recovery process of hundreds of thousands of X users.
U.S. Attorney General Todd Blanche said Wednesday that “sophisticated cyber criminals” attempted to exploit X’s account-recovery system, but the platform disrupted the operation before it could succeed on the scale apparently intended. Authorities have not publicly identified the attackers, disclosed their location or explained exactly how the operation was carried out.
The incident centers on password recovery, a process commonly used when users select “forgot password” or otherwise attempt to regain access to an account. Such systems can become attractive targets because successful manipulation may provide attackers with a path toward account takeover.
DOJ launches pursuit
Blanche said the Justice Department is working with X to identify and pursue those responsible. However, officials have so far released few technical details, meaning it remains unclear whether attackers successfully gained control of individual accounts or accessed users’ private information.
X had not immediately responded to Reuters’ request for comment when the report was published.
The latest incident comes as governments and technology companies confront a rapidly evolving cyber-threat environment, including increasingly sophisticated attacks involving artificial intelligence, ransomware and automated tools.
The White House has also been expanding federal efforts to coordinate cybersecurity defenses. In July, it launched the GOLD EAGLE initiative, designed to bring government agencies, AI developers and critical-infrastructure operators together to identify, validate and prioritize cybersecurity vulnerabilities more quickly.
Why password recovery is such a critical target
A password-reset system is effectively another doorway into an online account. If criminals can manipulate the recovery process, they may attempt to bypass the normal login process even without knowing a victim’s original password.
X itself recommends users strengthen their accounts by using unique passwords, enabling two-factor authentication and activating password-reset protection, which can require an associated email address or phone number when a reset is requested.
X also advises users who receive suspicious password-reset messages they did not request to take immediate steps to secure their accounts. The platform says users should change their passwords, secure the email account linked to X and consider two-factor authentication if they suspect compromise.
A warning sign in the wider cyber war
The attack is particularly significant because it arrives amid a broader escalation in cyber threats.
In August, the Justice Department and FBI announced the seizure of infrastructure allegedly operated by QTFY, a China-linked state-sponsored hacking group that U.S. officials said had targeted sensitive American networks, including systems associated with NASA, the Federal Reserve, the Department of Energy, the Justice Department and the U.S. Senate.
Separately, more than 100 major technology companies warned in August that AI-enabled cyberattacks could become substantially more widespread as increasingly capable AI systems become available.
The X incident therefore highlights a growing concern for social-media users: attackers do not necessarily need to “break” a platform directly. Instead, they can look for weaknesses around authentication, recovery systems, users and connected services.
What X users should do now
While authorities have not said that every account targeted in the latest incident was compromised, users can take precautions immediately:
- Enable two-factor authentication.
- Use a unique password for X.
- Turn on password-reset protection.
- Be suspicious of unexpected password-reset emails or messages.
- Never enter login information through links from unknown sources.
- Review account activity and connected applications for anything unfamiliar.
X says users who notice unauthorized posts, messages, account changes or other suspicious activity should change their password immediately and secure the email account associated with their profile.
For now, the biggest unanswered question is who was behind the attempted attack—and how far the hackers intended to go.
The Justice Department’s involvement signals that U.S. authorities are treating the incident as more than a routine platform-security problem. The investigation could ultimately reveal whether the campaign was an isolated criminal operation or part of a larger effort to exploit social-media accounts at scale.
WWC ONE MEDIA MJE