Microsoft X Account Hijacked for Crypto Scam
Microsoft's X account with 13 million followers was hijacked to push a Clippy-themed crypto token, and the company has yet to explain how.
Microsoft's official X account, with more than 13 million followers, was taken over on Thursday and used to promote a cryptocurrency impersonating Clippy, the animated paperclip assistant from older versions of Office. The incident was confirmed by the company, which said it is still investigating how the intrusion occurred.
The episode highlights the risks facing high-profile corporate social media accounts, where a single compromised login can expose millions of followers to fraud.
How the takeover unfolded
According to The Verge, the Microsoft account began following a crypto account and shared one of its messages. The account behind the reposted message, @clippymsftcto, posed as Clippy and has since been suspended. A second account involved in the incident kept pushing a $Clippy token, claiming its liquidity pool was paired with $MSFT.
The posts were eventually taken down. The Verge reported that an apology appeared on the Microsoft account roughly 30 minutes later and was deleted soon after, with no explanation given.
The now-deleted post stated that Microsoft was aware of a token being marketed in connection with its stock that used the Clippy brand without permission. “To be clear, Microsoft does not support, endorse, sponsor, or authorize any cryptocurrency or crypto-related token,” it read.
Microsoft's response and confirmation
A Microsoft spokesperson told The Verge, “We have confirmed unauthorized access to our account on X, including posts that did not come from Microsoft.” The spokesperson added, “The account has been secured and the unauthorized posts have been removed, and we are continuing to investigate the circumstances.”
We have confirmed unauthorized access to our account on X, including posts that did not come from Microsoft. The account has been secured and the unauthorized posts have been removed, and we are continuing to investigate the circumstances.
— A Microsoft spokesperson, as told to The Verge
Common paths to account hijacking
Microsoft has not said how the attackers gained access to its account, and hackers have several options beyond tricking a social media manager into entering their credentials on a phishing page.
They can take over the phone number tied to the account through SIM swapping, as it happened with the SEC’s X account in 2024, or hijack the email address used for password resets.
Infostealer malware on an employee’s device can also steal browser session cookies from an active login, letting attackers access the account without a password or an MFA prompt. Another route is a compromised third-party marketing or social media management tool that has been authorized to post on the company’s behalf.
The Clippy-themed crypto angle
Clippy, the animated paperclip assistant that shipped with older versions of Office, was used as the branding for the fraudulent token. The account @clippymsftcto posed as Clippy, and a second account promoted the $Clippy token, claiming its liquidity pool was paired with $MSFT. The posts were removed, but not before being seen by Microsoft’s millions of followers.
The now-deleted post from Microsoft clarified that the company does not support or authorize any cryptocurrency or crypto-related token. The apology that appeared roughly 30 minutes later was also deleted without explanation.
What we don't know
Microsoft has not disclosed how the attackers gained access to its account, leaving open questions about whether the compromise involved SIM swapping, email hijacking, session cookie theft, or a third-party social media management tool.
The Verge noted that hackers have several options beyond phishing. The investigation is ongoing.
Why it matters
For businesses and consumers, the incident serves as a reminder that even the most prominent corporate accounts can be hijacked and used to promote scams. The brief takeover of Microsoft’s X account put a fraudulent crypto token in front of a massive audience, and the lack of immediate explanation about how it happened may leave followers uncertain about what else could be compromised. This suggests that companies should review their social media security, including multi-factor authentication, session management, and third-party access, to reduce the risk of similar incidents.
Sources
- SecurityWeek Original source
- SEC’s X account Also reporting
Continue Reading
Teen ran KillSec ransomware, cops say
A 16-year-old led a ransomware crew that claimed about 1,000 attacks, according to European police.
Fortinet Zero-Day Hits FortiMail Gateways
Fortinet reports active exploitation of a critical FortiMail flaw, with patches still pending and CISA ordering federal fixes by October 4th.
DIVD breach linked to agentic AI attack
Dutch bug-hunting nonprofit says AI agents exploited Zammad zero-days, stealing researcher emails in seconds.