has X admitted a data breach yet? cause one def happened. i'm getting phishing emails to my connected email which has never happened before.

Aug 25, 2026 · 11:27 PM UTC

34
18
550
186,967
Sort replies: Relevant Recent Liked
Replying to @nic_carter
with @xmoney now live, i think the phishing attempts will dramatically increase — especially as they roll-out expanded financial offerings
3
958
Replying to @nic_carter
Mechahitler probably going rogue and posting everyone's info on the dark web on its own.
3
974
Replying to @nic_carter
there's precedent. a january 2022 bug report showed you could submit an email and get back the account attached to it. twitter patched it, confirmed it in august, and by then 5.4 million records were already listed for sale. your inbox finds out before the disclosure does.
605
Replying to @nic_carter
You don’t use that email for ANYTHING else?
745
Replying to @nic_carter
Yeah, got bamboozled by one myself this morning. Lost access to my account I’ve had since 2014, real bummed about it
1,341
Replying to @nic_carter
The leak is not a bug. They leak your email as a feature.
Anons who verified on X: Are you aware that these settings are defaulted as "on"? Make sure to uncheck them.
2
25
8,051
Replying to @nic_carter
I get this garbage all the time.
9
3,902
Replying to @nic_carter
Timing is the clearest signal here. If phishing targets an address that existed exclusively within one platform's ecosystem, coincidence becomes unlikely. Worth mapping whether affected accounts share a connected email, and whether the pattern skews toward recent signups or older accounts. That distinction narrows the source considerably.
1
3
3,726
Replying to @nic_carter
NONSTOP
4
2,552
Replying to @nic_carter
I've gotten a couple, first one a few weeks ago. It was pretty convincing too because it contained my X username in the subject line. I keep telling myself to set up unique email addresses per account but it's super time consuming to change each one.
1
1
3,656
Replying to @nic_carter
Same here—phishing emails hitting the connected address out of nowhere. X really needs to confirm if there’s been a breach.
1
493
Replying to @nic_carter
I'm not.
1
2,473
Replying to @nic_carter
Same
812
Replying to @nic_carter
It's a feature. part of X Premium. You're welcome
19
2,772
Replying to @nic_carter
Yes I’m getting Google telling me every single one of my passwords was exposed to a leak and to change them all. And I’m like brother - I’m not going to so QUIT ASKING. Lol
2
2,230
Replying to @nic_carter
honestly it's probably just a credential scrape rolling through old api leaks
2
1,009
Replying to @nic_carter
Recently got an email about this myself...
1
926
Replying to @nic_carter
I give my email to everyone and get very few phishing emails 🤷‍♂️
1
1,624
Replying to @nic_carter
Are you using Gmail for that? How do you know your Google account hasn’t been compromised the phishing may be part of a long-term automated attack. Don’t ordinary phishing emails go to spam, how are you even seeing them unless this is spear phishing targeting you specifically.
BITCOIN HOLDER LOSES $750K IN BTC AFTER GOOGLE ACCOUNT HACK A longtime Bitcoin holder reportedly lost roughly $750,000 less than 12 hours after moving his BTC to a major Australian exchange. According to a close friend, hackers had compromised his Google account for roughly three months, gaining access to his email and cloud-backed Google Authenticator credentials. They waited for him to deposit BTC on an exchange. When he finally did, the attackers accessed the account and withdrew everything. The exchange believed it was the legitimate owner and approved the withdrawal. The victim reportedly woke at 3 a.m. to a notification saying his withdrawal had been approved. One major security takeaway is to disable cloud backup on Google Authenticator. If your Google account is compromised, synced authentication codes can become another point of attack. Hardware security keys such as YubiKeys offer stronger protection because authentication still requires possession of the physical key. Setting up two keys provides a backup if one is lost.
1
2,013
Replying to @nic_carter
unique alias per service is the only way to know who leaked. an email only x had is damning evidence
34
Replying to @nic_carter
Are you truly just an etf guy? Don’t hold your own keys? Sorry about your email issue.
12
Replying to @nic_carter
Stripe.
40
Replying to @nic_carter
200M+ twitter records dropped on a hacking forum in early 2023. scraped in 2021 by abusing an API that linked emails to profiles.
855
Replying to @nic_carter
“whoops”
409
Replying to @nic_carter
could easily just be someone who works there leaked it
174
Replying to @nic_carter
That’s no bueno
874