The US Justice Department has joined Elon Musk-owned X in trying to identify cybercriminals behind a large-scale attack that targeted the password-recovery system of hundreds of thousands of users on the social media platform.
US Attorney General Todd Blanche said the attempted cyberattack took place this week and involved what he described as sophisticated cybercriminals. X was able to disrupt the operation before the attackers could fully carry it out, according to Reuters.
The exact number of accounts targeted has not been disclosed beyond “hundreds of thousands”, and authorities have not said whether any user accounts were successfully taken over.
The Justice Department is now working with X to trace those responsible.
Algoritha Security Launches ‘Make in India’ Cyber Lab for Educational Institutions
What Is a Password-Recovery Attack?
Most online platforms have a “forgot password” option for users who lose access to their accounts.
Normally, the platform verifies the user through an email address, phone number, authentication code or another identity check before allowing the password to be changed.
Attackers can try to abuse this recovery process instead of directly cracking a password.
For example, a criminal may repeatedly trigger password resets, attempt to manipulate recovery mechanisms, exploit weaknesses in verification systems or use stolen personal information to convince a platform that they are the genuine account owner.
If successful, the attacker can potentially reset the password and lock the real user out.
This makes account-recovery systems an attractive target because even a strong password becomes less useful if criminals can bypass it through the recovery process.
Hundreds of Thousands of X Accounts Targeted
The scale of the attempted operation makes the incident significant.
According to Reuters, hundreds of thousands of X users were targeted during the attack.
Blanche said X managed to disrupt the operation, but neither the Justice Department nor the company has publicly explained exactly how the attackers attempted to exploit the password-recovery system.
It is therefore not yet clear whether the campaign involved an undisclosed technical vulnerability, automated recovery requests, stolen credentials, social engineering or a combination of different techniques.
There is also no public indication so far that passwords or other sensitive information belonging to hundreds of thousands of users were actually stolen.
That distinction matters. Being targeted in an attempted attack does not automatically mean that an account was compromised.
US Authorities Now Hunting the Attackers
The involvement of the US Justice Department moves the incident beyond an internal security investigation at X.
Federal investigators can potentially examine digital infrastructure, financial trails, server records and other evidence connected with the attackers. International cooperation could also become necessary if the people or infrastructure behind the operation are located outside the United States.
The department has not publicly identified any hacking group or individual as being responsible.
That leaves several important questions unanswered, including who organised the campaign, what they hoped to obtain and whether particular categories of X users were deliberately selected.
The motive could become especially important.
A compromised social media account can be valuable for several reasons. Criminals can use established accounts to spread cryptocurrency scams, impersonate victims, send malicious links or approach the victim’s contacts.
Accounts belonging to government officials, journalists, business executives or other prominent individuals can carry additional value because taking control of them can enable convincing impersonation or misinformation.
Cybercriminals Increasingly Target Identity, Not Just Passwords
The X incident highlights a wider security problem facing major online platforms.
Modern account security is no longer simply about keeping passwords secret. Criminals increasingly look for alternative routes into accounts, including stolen session tokens, compromised email accounts, phishing, SIM-related attacks and weaknesses in account-recovery procedures.
Recovery systems present a difficult challenge for technology companies.
They must be easy enough for genuine users to regain access when they lose their password or phone, while remaining difficult for criminals pretending to be those users.
The investigation comes as governments and companies are also confronting increasingly sophisticated cyberattacks involving automation and artificial intelligence.
The White House said in July that it was establishing a coordination group involving AI developers and critical-infrastructure operators to share information about cybersecurity vulnerabilities discovered by AI systems.
For platforms with hundreds of millions of users, even an attack that succeeds against only a small percentage of targeted accounts can create serious consequences.
The fact that X says it disrupted this campaign is therefore important. But until investigators reveal how the attackers attempted to manipulate the recovery system, users will have limited information about whether they need to take additional protective measures.
What this means for you: If you receive an unexpected password-reset email or verification code for X — or any other online account — do not approve it or share the code with anyone. Use a unique password and enable two-factor authentication wherever possible. Unexpected recovery messages can also be an early warning that someone is attempting to gain access to your account.