Attorney General Todd Blanche puts hacker groups on alert after X cyber attack

- Attorney General Todd Blanche said that the Justice Department is pursuing the cyber criminals behind a password-reset attack that flooded X users with reset emails.
- X reportedly disrupted the attack before accounts were captured.
- The DOJ has been running a string of cyber takedowns, including seizures of China-linked hacking tools and a Russian botnet.
Attorney General Todd Blanche has said that the Justice Department is going after the cyber criminals who bombarded X users with unrequested password-reset emails this week.
The platform maintains that no accounts were compromised because the attack was disrupted in time.
Password reset attack on X
On September 2, 2026, Attorney General Todd Blanche wrote on X that “hundreds of thousands of X users” were affected by a coordinated attempt to hijack accounts through the password-recovery flow. He credited the company with stopping the attack in time and preventing user accounts from being compromised.
Blanche added that investigators are “working closely with X to track down the criminals.”
The attack first came to light on September 1, when users began posting about receiving waves of reset messages. Some inboxes reportedly collected about ten emails in a short window around 9:30 a.m. Eastern.
The messages appeared to genuinely come from the company as they were sent from the official email ([email protected]) and carried the six-digit code needed to finish a reset. Despite this, X engineer Mridul Singhai said the company found no sign of a breach. He also apologized for the volume of emails.
Singhai linked the attack to X Money, Elon Musk’s payment product that opened to the public in July, suggesting attackers “believe that, now that @XMoney is widely available, they can gain unauthorized access to accounts.”
Has X been hacked before?
X’s data has been loose for years following an incident in April 2025 in which a self-described data enthusiast using the handle “ThinkingOne” posted a 34GB file with 201,186,753 X records, including names, email addresses, usernames and follower counts.
The vulnerability exploited by ThinkingOne came from a 2022 bug-bounty report that let attackers search for users using their email or phone number.
Due to that history, there is speculation that X’s most recent attackers used a technique called credential stuffing, where automated tools test stolen username-password pairs against a login system.
Credential stuffing reportedly accounts for 31% of social media hacks, with more than 24 billion stolen pairs in circulation. Researchers who found one X-focused botnet watched it test 722,763 credentials in a 12-minute stretch.
U.S. authorities have been cracking down on cybercrime and have increased their focus on hacking. In late August, the DOJ and FBI announced court-authorized seizures of two hacking platforms, QScan and QTRouter, that a China state-sponsored group used against targets including NASA, the Federal Reserve and the U.S. Senate.
Days later, on September 2, authorities working with CrowdStrike and the Shadowserver Foundation dismantled Sality, a Russia-based botnet that had reportedly infected more than 11 million devices over a 23-year run.
If you're reading this, you’re already ahead. Stay there with our newsletter.
FAQs
What happened to X users this week?
Starting September 1, 2026, X users received waves of unrequested password-reset emails carrying genuine six-digit codes, and Attorney General Todd Blanche said the following day it was a coordinated attack that X disrupted before accounts could be taken over.
Is X's password-reset attack linked to a new data breach?
X has not confirmed any new breach, and engineer Mridul Singhai said the company found no evidence of one, though a 2025 leak of over 200 million X records and credential-stuffing techniques give attackers material to work with.
What has the DOJ done about hackers recently?
Beyond the X pledge, the Justice Department and FBI seized the China-linked QScan and QTRouter hacking platforms on August 26, 2026, and on September 2 helped dismantle Sality, a Russia-based botnet that had infected more than 11 million devices.
Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Hannah Collymore
Hannah is a writer and editor with nearly a decade of blog writing and event reporting experience in the crypto space. At Cryptopolitan, Hannah contributes to the news page, reporting and analyzing the latest developments in DeFi, RWA, crypto regulation, AI and frontier tech industries. She graduated from Arcadia university with a degree in Business Administration.
















