Security1 distinct publisher2 min readPublished
Attorney General Todd Blanche says criminals worked X's password-recovery system against hundreds of thousands of accounts this week and that X stopped them. The technique is the part still undisclosed.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Account recovery exists to admit people who cannot authenticate. That is the function it is built for: forgot-password features, account-recovery forms, and the other mechanisms meant to get a legitimate user who has lost access back in [6]. Attackers go at weaknesses in those processes to obtain access to accounts [7].
Run the numbers on the scale figure. Read "hundreds of thousands" at its floor, 200,000, and take the window as the week Blanche described [1]. That works out to roughly 28,600 accounts a day, sustained for seven days [12]. If the run was two days rather than seven, it is 100,000 a day [12]. Nobody hand-works a recovery form at that rate. Someone was scripting requests against an endpoint and cycling identifiers.
Everything on the record comes from one place: a statement by the Attorney General, posted on the platform involved [1]. The statement does not name an actor, does not give a location, and does not describe a technique [4]. The publisher sets the incident against a broader rise in AI-driven attacks and ransomware [10], and Blanche linked the X attempt to neither [4]. Automation at volume is automation at volume until someone shows the tooling.
Without the technique, the checkable thing on your own stack is rate. How many recovery initiations per identifier, per source address, per hour does your flow accept before anything objects, and does anyone read that counter. That question survives whatever X turns out to have patched or throttled.
The department announced an operation days earlier against QTFY, which US authorities describe as a Chinese cyberespionage platform that had targeted US institutions including the Senate, the Federal Reserve and NASA [8][9]. Different victims, different objective. Filing both under one heading is how the specific lesson here goes missing: the X attempt reached for consumer accounts in bulk through the one door designed to open without credentials [1][6].
Ranked by verification strength, evidence, and original report placement.
Attorney General Todd Blanche said in a statement posted on X on Wednesday that sophisticated cyber criminals attempted a password-recovery attack on hundreds of thousands of X users that week.
The Justice Department is working closely with X to identify those responsible for the attempted attack, and Blanche said authorities would pursue those involved even when the activity is conducted remotely.
Blanche did not disclose additional technical details, including how the attackers attempted to exploit the recovery system, whether any individual accounts were compromised, or where the suspected criminals were operating from.
Blanche provided no breakdown of how many accounts were actually affected or whether any users suffered losses.
A password-recovery attack generally targets the systems users rely on when they have forgotten their login credentials, including forgot-password features, account-recovery forms, and other mechanisms designed to help legitimate users regain access.
Attackers may attempt to exploit weaknesses in account-recovery processes to obtain access to accounts.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 2, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
DOJ seizes QScan and QTRouter: somebody else's camera was the return address7 distinct publishers
invest
X's stablecoin creator payouts would be a plumbing decision, not a crypto bet3 distinct publishers
security
FBI names Nanjing contractor behind 300-victim Check Point Quantum Gateway campaign1 distinct publisher
invest
"An inadvertent error is not fraud": Cook turns removal attempt two into a test of "for cause"1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One post, one outlet
Every load-carrying fact — the scale, the technique category, the successful disruption — comes from a single social-media statement by Todd Blanche, relayed by a single publisher. The quote is reproduced faithfully, which is why this is not lower, but X has not spoken, no researcher has looked at the traffic, and the DOJ released nothing an outsider could verify.
No verified impact to count
There is nothing here to measure. "Hundreds of thousands" describes attempts, not outcomes, and Blanche declined to say how many accounts were actually affected or whether anyone lost anything — so the only quantities available are an unverified target count and a categorical claim that nothing was captured.
Big number, hollow middle
The framing carries more weight than the disclosure does: a mass-takeover attempt on a major platform, announced with prosecutorial flourish, resting on one figure and no mechanism. The overstatement is modest rather than severe because The Cyber Express itself names what is missing twice, and because the arithmetic behind the number is at least internally plausible for automated abuse of recovery endpoints.
Everyone gains from this telling
Follow who benefits. The Justice Department gets to announce a save — "we will stop at nothing" — on the very platform it is protecting, days after publicising the QTFY takedown. X gets credited with defeating an attack while never having to describe what happened. And the story lands in a security-trade outlet whose closing section sells generalised AI-threat anxiety. No party in the chain has a reason to volunteer the technical detail that is missing.
Consistent, but untested
The claims are simple, quoted directly and not contradicted anywhere in our coverage, so little is likely to be wrong on its face. What holds the score down is that nothing has been tested: one publisher, one primary voice, and the two questions that would change the story's meaning — how the recovery flow was worked and whether any account actually fell — remain open.