Breaking
Cyber CrimeDeveloping Story

Microsoft X Account Hijacked for Crypto Scam

Microsoft's X account with 13 million followers was hijacked to push a Clippy-themed crypto token, and the company has yet to explain how.

··2 hours ago·3 min read
assorted-color social media signage
Photo by Merakist on Unsplash

Microsoft's official X account, with more than 13 million followers, was taken over on Thursday and used to promote a cryptocurrency impersonating Clippy, the animated paperclip assistant from older versions of Office. The incident was confirmed by the company, which said it is still investigating how the intrusion occurred.

The episode highlights the risks facing high-profile corporate social media accounts, where a single compromised login can expose millions of followers to fraud.

How the takeover unfolded

According to The Verge, the Microsoft account began following a crypto account and shared one of its messages. The account behind the reposted message, @clippymsftcto, posed as Clippy and has since been suspended. A second account involved in the incident kept pushing a $Clippy token, claiming its liquidity pool was paired with $MSFT.

The posts were eventually taken down. The Verge reported that an apology appeared on the Microsoft account roughly 30 minutes later and was deleted soon after, with no explanation given.

The now-deleted post stated that Microsoft was aware of a token being marketed in connection with its stock that used the Clippy brand without permission. “To be clear, Microsoft does not support, endorse, sponsor, or authorize any cryptocurrency or crypto-related token,” it read.

Microsoft's response and confirmation

A Microsoft spokesperson told The Verge, “We have confirmed unauthorized access to our account on X, including posts that did not come from Microsoft.” The spokesperson added, “The account has been secured and the unauthorized posts have been removed, and we are continuing to investigate the circumstances.”

We have confirmed unauthorized access to our account on X, including posts that did not come from Microsoft. The account has been secured and the unauthorized posts have been removed, and we are continuing to investigate the circumstances.

— A Microsoft spokesperson, as told to The Verge

Common paths to account hijacking

Microsoft has not said how the attackers gained access to its account, and hackers have several options beyond tricking a social media manager into entering their credentials on a phishing page.

They can take over the phone number tied to the account through SIM swapping, as it happened with the SEC’s X account in 2024, or hijack the email address used for password resets.

Infostealer malware on an employee’s device can also steal browser session cookies from an active login, letting attackers access the account without a password or an MFA prompt. Another route is a compromised third-party marketing or social media management tool that has been authorized to post on the company’s behalf.

The Clippy-themed crypto angle

Clippy, the animated paperclip assistant that shipped with older versions of Office, was used as the branding for the fraudulent token. The account @clippymsftcto posed as Clippy, and a second account promoted the $Clippy token, claiming its liquidity pool was paired with $MSFT. The posts were removed, but not before being seen by Microsoft’s millions of followers.

The now-deleted post from Microsoft clarified that the company does not support or authorize any cryptocurrency or crypto-related token. The apology that appeared roughly 30 minutes later was also deleted without explanation.

What we don't know

Microsoft has not disclosed how the attackers gained access to its account, leaving open questions about whether the compromise involved SIM swapping, email hijacking, session cookie theft, or a third-party social media management tool.

The Verge noted that hackers have several options beyond phishing. The investigation is ongoing.

Why it matters

For businesses and consumers, the incident serves as a reminder that even the most prominent corporate accounts can be hijacked and used to promote scams. The brief takeover of Microsoft’s X account put a fraudulent crypto token in front of a massive audience, and the lack of immediate explanation about how it happened may leave followers uncertain about what else could be compromised. This suggests that companies should review their social media security, including multi-factor authentication, session management, and third-party access, to reduce the risk of similar incidents.

#microsoft#x#crypto scam#account hijack#clippy

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories