Quick summary
The user community of social network X (formerly Twitter) is facing a security attack …
The incident stems from the fact that a series of accounts suddenly received notifications requesting password resets in their email inboxes…
NordVPN's Findings and the Reality of a Wave of Unusual Password Reset Emails According to the latest analysis reports from the company…
The X social media user community (formerly Twitter) is facing a widespread cyberattack after the security firm NordVPN issued an urgent warning report. The incident originated from the fact that a series of accounts suddenly received password reset notifications in their personal inboxes without having made any prior requests, raising deep concerns about personal data security.
1. NordVPN’s Findings and the Reality of a Surge in Unusual Password Reset Emails
According to the latest analytical reports from the cybersecurity company NordVPN, data containing more than 5 million email addresses linked to X social media accounts may have been leaked externally. This security incident is believed to be the direct cause of the recent surge of emails requesting password changes or resets flooding users’ inboxes.

NordVPN discovers that more than 5 million X account emails may have been leaked
Many accounts report that they are continuously receiving spam emails requesting access recovery, even though they have not performed any unusual login activity or forgotten any security information. This situation suggests that attackers may be using leaked email lists to trigger mass automatic password reset requests in order to cause disruption or prepare for account takeover phishing campaigns. Representatives of X have now issued their first responses to acknowledge and address the incident.
2. Emergency Defensive Measures to Protect X Accounts from the Risk of Takeover
Facing an attack that carries a high risk of information compromise, X users need to proactively implement protective measures immediately to safeguard their personal data. The foremost safety principle is to absolutely not click on any link appearing in unusual password reset emails sent to your inbox, as these may be fake phishing links designed to mimic the official interface and steal login credentials.

You should install 2FA to protect your account
In addition, enabling two-factor authentication (2FA) immediately is mandatory for all users to build a strong defensive barrier. When 2FA is activated through dedicated apps such as Google Authenticator or a physical security key instead of relying only on SMS codes, attackers will not be able to access the account even if they have the email address or intentionally obtain your password.
Source: https://emacrypto.com/canh-bao-an-ninh-hon-5-trieu-email-tai-khoan-x-nghi-bi-ro-ri-va-lan-song-spam-dat-lai-mat-khau/

