Microsoft's official X account hijacked to promote fake $Clippy crypto token
Attackers gained unauthorized access to Microsoft's 13-million-follower X account and used it to promote a $Clippy crypto token in an apparent pump-and-dump; Microsoft secured the account and removed the posts.
Unknown attackers hijacked Microsoft's official X account, which has more than 13 million followers, and used it to amplify a Clippy impersonator promoting a $Clippy crypto token claimed to be paired with $MSFT, in an apparent pump-and-dump scheme. According to SecurityWeek, the compromised account followed and reposted the @clippymsftcto crypto account and replaced its profile picture with Clippy imagery. Microsoft confirmed the unauthorized access, secured the account, and removed the posts, stating it does not endorse the token or any cryptocurrency; BleepingComputer reports Microsoft also said it will take legal action and is investigating. The access method remains unknown, with suggested vectors including credential phishing, SIM swapping, infostealer session-cookie theft, or a compromised third-party social media management tool. The incident echoes prior high-profile X account compromises: in June 2024, attackers hijacked @MicrosoftIndia to push a cryptocurrency wallet drainer, and the SEC's X account was previously compromised via SIM-swap in an incident that briefly moved Bitcoin prices.
- Microsoft's official X account, with over 13 million followers, posted unauthorized crypto promotion on or around 2026-10-02.
- The scam promoted a $Clippy token claimed to be paired with $MSFT and leveraging the Clippy brand.
- The hijacked account followed and reposted the @clippymsftcto crypto account and changed its profile picture to Clippy imagery.
- Microsoft confirmed unauthorized access, secured the account, and removed the posts, stating it does not endorse the token or any cryptocurrency.
- BleepingComputer reports Microsoft said it will take legal action and is investigating.
- The access vector is unknown; suggested possibilities include credential phishing, SIM swapping, infostealer session-cookie theft, or a compromised third-party social media management tool.
- In June 2024, attackers hijacked @MicrosoftIndia to deliver cryptocurrency wallet-drainer malware.
- The SEC's X account was previously compromised via SIM-swap, briefly moving Bitcoin prices.
Coverage timelineoldest first · each row is one article
- · 6d agoMicrosoft’s X account hacked in crypto pump-and-dump scheme
BleepingComputer· 58
Attackers hijacked Microsoft’s official X account, with over 13 million followers, to promote a Clippy crypto token.
- · 6d agoCrypto Scammers Hijack Microsoft’s Official X Account
SecurityWeek· 50
Microsoft confirmed unauthorized access to its 13-million-follower X account, used to promote a fake Clippy cryptocurrency token scam.