The U.S. is pursuing the hackers who attempted to attack hundreds of thousands of X accounts

Deputy Attorney General Todd Blanche.Photo © Facebook/The United States Department of Justice

The United States Department of Justice announced this Wednesday that it is working with X, Elon Musk's platform, to identify those responsible for a targeted attack against hundreds of thousands of user accounts, as the social network expands its financial services with X Money.

Deputy Attorney General Todd Blanche reported that the attempt to hijack accounts was thwarted before the attackers could take control of the profiles, and he assured that authorities will pursue those responsible.

"This week, sophisticated cybercriminals attempted a password recovery attack against hundreds of thousands of X users. X thwarted the attack to prevent accounts from being compromised," explained Blanche in a statement published on the platform itself.

"The Department of Justice will stop at nothing in its pursuit of cyber fraud and scammers. There is no refuge for those who perpetrate their criminal schemes from behind a screen," he added.

The first signs of the attack appeared on Tuesday, when numerous users began receiving unsolicited emails to reset their passwords.

According to a report from TechCrunch, Mridul Singhai, a product engineer at X, explained that attackers used public usernames to trigger massive password reset requests.

The company suspects that the launch of X Money, its new financial service, may have made the platform's accounts a more attractive target.

"The attackers seem to believe that now that X Money is widely available, they can gain unauthorized access to accounts. So far, we have not found any evidence of any breach," Singhai noted.

X Money incorporates features such as instant payments, free ATM withdrawals, and a card offering 3% cash back. Accounts linked to the service are backed by Cross River Bank, an institution insured by the Federal Deposit Insurance Corporation (FDIC).

So far, X maintains that there is no evidence of a security breach or a massive account takeover.

X's legal advisor, James Burnham, stated that the company's legal and security teams will seek to identify those responsible, regardless of the country from which they operated.

The surge in password change requests also prompted users of X to start alerting one another. Among the main recommendations are not to click on suspicious links received via email and to enable two-factor authentication to add an extra layer of security to accounts.

Related videos:

Filed under:

CiberCuba Editorial Team

A team of journalists committed to reporting on Cuban current affairs and topics of global interest. At CiberCuba, we work to deliver truthful news and critical analysis.