The U.S. Justice Department is working with X to identify those behind an attempted password-recovery attack that targeted hundreds of thousands of users on September 3, 2026.
US Attorney General Todd Blanche stated in a post on X that "sophisticated cyber criminals" attempted the attack, but the platform was able to disrupt it. The attack involved attempts to gain access to online accounts by exploiting the password-recovery process.
Why It Matters
The joint investigation shows ongoing efforts to secure digital platforms against large-scale automated attacks. By targeting the password-recovery mechanism, the perpetrators sought to bypass traditional security measures, affecting hundreds of thousands of users.
Timeline
On August 26, 2026, the Justice Department and FBI announced court-authorized domain seizures to deny malicious cyber actors access to two complementary hacking platforms known as “QScan” and “QTRouter,” used to target U.S. critical infrastructure and other sensitive networks. On September 3, 2026, US Attorney General Todd Blanche stated in a post on X that "sophisticated cyber criminals" attempted the attack, but the platform was able to disrupt it. Also on September 3, 2026, the U.S. Justice Department began working with X to identify those behind the attempted password-recovery attack that targeted hundreds of thousands of users.
What's New
Later reporting indicates that the Justice Department and FBI announced court-authorized domain seizures on Wednesday, August 26, 2026, to deny malicious cyber actors access to two complementary hacking platforms known as “QScan” and “QTRouter,” used to target U.S. critical infrastructure and other sensitive networks. Additional details show that X’s chatbot Grok confirmed that attackers are mass-triggering the password reset form using public usernames. Contextual information identifies the United States Department of Justice as a United States federal executive department.
forum Comments (0)
No comments yet. Be the first to comment.