Wave of Unsolicited Password Reset Requests Hits X Users: How to Protect Your Account from Takeovers
A growing number of users on the social media platform X (formerly Twitter) are reporting that they have suddenly received unexpected notifications and emails requesting password resets. In some cases, users received multiple requests within a short span of time, sparking heightened concern over potential coordinated attacks by third parties attempting unauthorized account takeovers.
According to user reports, many have received emails asking “Reset your password?” despite having made no such request themselves. Some incidents have reportedly escalated to full account takeovers, where unauthorized parties altered registered email addresses and passwords. Security experts and users alike are urging people not to click any links within suspicious emails and to ignore the unsolicited reset prompts.
To prevent unauthorized access, users are strongly advised to review and tighten their account security settings on X. Two particularly effective countermeasures are enabling “Password reset protection” and configuring “Two-Factor Authentication (2FA).”
Under default settings, password reset procedures can often be initiated simply by providing an account username. However, activating “Password reset protection” requires the full registered email address or phone number before a reset request can be submitted, thereby preventing third parties from triggering reset procedures arbitrarily.
Users can strengthen their account security by navigating to X's settings menu (Settings and privacy > Security and account access > Security) and checking the following settings:
- Enable Two-Factor Authentication: Set up multi-factor authentication using an authenticator app or a hardware security key.
- Turn on Password Reset Protection: Enable the feature to require additional personal verification information for reset requests (if not visible on the mobile app, it can be adjusted via a web browser).
- Review Connected Apps and Active Sessions: Periodically review linked third-party applications and logged-in devices to identify any suspicious or unrecognized access.
Compromised social media accounts pose serious risks, ranging from the exposure of personal data to misuse for payment fraud or impersonation scams. Anyone who receives suspicious notifications should avoid interacting with them carelessly and immediately review their account security settings and update passwords.
The Context
In Japan, X (formerly Twitter) remains one of the most widely used social media platforms for both personal communication and real-time news dissemination, making Japanese user accounts high-value targets for cybercriminals. Malicious actors frequently attempt account takeovers using automated credential stuffing, phishing schemes, and unauthorized password resets to hijack accounts with large followings. Once compromised, these accounts are often repurposed for cryptocurrency scams, phishing campaigns, or fraudulent promotions, highlighting the critical importance of multi-factor authentication and proactive account safeguarding.
Comments
Post a Comment