X users received unrequested password reset emails that were real and came from X’s own systems, and X acknowledged the issue without confirming a new data breach. X said it is actively investigating a possible data exposure and has found no evidence of any breaches so far.
The situation follows a January 2022 Twitter API vulnerability affecting over 200 million users, a Have I Been Pwned entry listing 211,524,284 unique email addresses, and an April 2025 BreachForums post of a 34‑GB file containing 201 million X user records.
A vulnerability in Twitter’s API in January 2022 allowed matching email addresses and phone numbers to Twitter accounts, and led to a dataset described as covering over 200 million users. That vulnerability permitted the association of contact details with account records. The dataset resulting from that vulnerability was reported and examined in 2022 and 2023.
Have I Been Pwned contains an entry that catalogs the data and lists 211,524,284 unique email addresses. The dataset has been reported by Troy Hunt on Have I Been Pwned. Analysis of the listing found that 98% of the addresses had surfaced in earlier breaches.
These items—the January 2022 API vulnerability, the Have I Been Pwned entry and the 98% overlap statistic—are all documented elements of prior exposures of contact information tied to Twitter/X accounts. They constitute the recorded background referenced in coverage of subsequent account-related incidents.
In January, Instagram experienced a security scare tied to 17.5 million accounts during which users received unrequested password reset emails. Forbes reported that a bug allowed the unrequested reset emails to be sent. The reports described the incident as originating from a platform-side fault rather than from external email spoofing. Coverage noted the scale of affected accounts and the role of the bug in triggering the reset messages.
X users were also sent unrequested password reset emails that were real and originated from X’s own systems, and X acknowledged the issue while saying it was investigating a possible data exposure without confirming a new data breach. X said it has found no evidence of any breaches so far. Both the Instagram incident and the X activity involved unsolicited reset emails connected to a software bug or a potential exposure. The thematic similarity is that users in both cases received account-reset communications linked to platform-side issues rather than external email spoofing.
X has acknowledged the unrequested password reset emails, said it is actively investigating a possible data exposure, and reported that investigators have found no evidence of any breaches to date. The company has referenced links to historical exposures documented in earlier incidents — including the January 2022 Twitter API vulnerability and datasets cataloged in Have I Been Pwned and related postings — and said it is possible the recent rush of reset emails relates to a years‑old data exposure even though it has not confirmed a new breach.


