BT Email customers reported receiving hundreds of unsolicited password reset messages over the weekend, with one user claiming to have been sent more than 1,000 codes, according to a September 16, 2026 report from The Register. The British telecommunications company has acknowledged the problem and launched an investigation, though the root cause remains unclear. BT maintains that customer email accounts remain secure despite the flood of PIN messages.

Complaints started surfacing on BT's community forums over the weekend, with users describing sudden waves of PIN messages delivered within minutes despite never requesting password resets. One customer told The Register they got roughly 300 password reset emails across 24 hours, typically arriving in clusters of approximately 50 within a single minute before pausing for several hours. Another user reported between 50 and 70 PIN texts "in the space [of] a few minutes," while others cited figures exceeding 100, 500, and in one case surpassing 1,000 messages. The messages arrived via both email and SMS, according to customer reports.

A BT moderator acknowledged the issue on the company's community forum, advising customers who received multiple password reset PIN messages to "ignore them and remain vigilant for any unusual activity with further messages or unexpected calls." The company stated that customers' email accounts are secure and that recipients don't need to take action. In an updated statement on September 17, 2026, BT said it had "implemented a number of mitigations to prevent further password reset messages from being sent" and was contacting affected customers to tell them to disregard the PINs they'd received. The telco characterized the problem as affecting "a small number of customers."

The exact cause behind the PIN deluge hasn't been determined. The Register asked BT whether the messages stemmed from external password-reset attempts, a system fault, or another source entirely, but the company said only that it's investigating. The publication also questioned what rate limiting BT applies to password reset requests, given accounts of hundreds of PINs arriving within minutes, and whether any evidence of malicious activity had been found. At least one customer claimed someone gained access to their account during the barrage, saying they lost access to both their email and BT ID overnight but managed to request a PIN before the person accessing the account could change the attached phone number—though that account hasn't been independently verified and it isn't clear if the alleged takeover connects to the wider PIN flood.

BT says it continues to monitor the situation and has advised customers not to take further action beyond ignoring the unsolicited messages. The company hasn't disclosed how many users were affected or whether it plans additional safeguards to prevent similar incidents. For now, the question of whether this represents a deliberate attack on the password recovery system, a technical malfunction, or something else remains unanswered. The telco's handling of rate limits and authentication safeguards will likely face scrutiny as customers seek assurance that their accounts remain protected. Enterprises relying on legacy email infrastructure may find themselves weighing the trade-offs between operational continuity and the security posture of aging authentication systems, particularly when incident transparency remains limited.