Microsoft's official X account hijacked to push a fake Clippy crypto token
On Thursday, October 1, 2026, unknown attackers hijacked the official Microsoft account on X (formerly Twitter), which has over 13 million followers, in what appeared to be a pump-and-dump scheme promoting a crypto token. The takeover began when the @Microsoft account followed and reposted a message from @clippymsftcto, an account impersonating Clippy, the animated paperclip assistant that shipped with older versions of Microsoft Office. Microsoft's profile picture was also briefly replaced with Clippy artwork during the incident.
Incident Details
| Attribute | Value |
|---|---|
| Target | Official @Microsoft account on X (13M+ followers) |
| Date | October 1, 2026 (Thursday) |
| Compromised asset | Account credentials/session for @Microsoft on X |
| Malicious token | $Clippy |
| Attacker-controlled accounts | @clippymsftcto (suspended), @ClippyMSFT (still active at time of writing) |
| False claim | $Clippy "has a liquidity pool paired directly with $MSFT" |
| Apology window | An unauthorized "apology" post appeared roughly 30 minutes after the initial posts, then was deleted |
| Microsoft response | Confirmed unauthorized access, removed posts, secured account, pursuing legal action |
| Prior precedent | @MicrosoftIndia hijacked in June 2024 to impersonate "Roaring Kitty" and push wallet-drainer malware |
What happened
The takeover
Attackers gained unauthorized access to Microsoft's primary corporate X account and used it to follow @clippymsftcto, an account posing as Microsoft's Clippy character, then reposted its message asking how many likes it would take to "bring Clippy back." The account's profile picture was swapped for a Clippy-themed image, lending the hijack an air of legitimacy to the millions of followers who saw it appear in their feeds.
The pump-and-dump pitch
The scheme centered on $Clippy, a cryptocurrency token that attackers promoted as having a liquidity pool "paired directly with $MSFT" — falsely borrowing Microsoft's stock ticker to imply a corporate tie-in that does not exist. @clippymsftcto was suspended by X after the hijack was discovered, but a related account, @ClippyMSFT, continued promoting the token afterward, illustrating how these schemes often run on multiple coordinated accounts so that suspending one does not stop the pitch.
An unusual deleted "apology"
Roughly 30 minutes after the unauthorized posts went live, an "apology" tweet appeared on the Microsoft account stating the company had "not authorized, sponsored, endorsed, or granted permission" for any token tied to Clippy, Microsoft, or $MSFT — before that post, too, was quickly deleted. The sequence (malicious posts, then an unauthorized "clean-up" message, then another deletion) suggests the attackers retained some level of control over the account even as Microsoft worked to lock it down.
Microsoft's official statement
A Microsoft spokesperson told The Verge: "We have confirmed unauthorized access to our account on X including posts that did not come from Microsoft." The company added that the account "has been secured and the unauthorized posts have been removed," that it is "continuing to investigate the circumstances," and that it "does not endorse or have any affiliation with this token, its creators, or any related cryptocurrency project" — adding that it will "pursue appropriate legal action to have the unauthorized token and related materials removed."
How attackers likely got in
Microsoft has not disclosed the exact initial-access vector, and BleepingComputer notes the intrusion method remains unconfirmed. Security researchers point to several common ways high-follower corporate social accounts are taken over: SIM swapping the phone number tied to account recovery (as happened in the 2024 hijack of the SEC's X account), compromising the email address used for password resets, infostealer malware harvesting browser session cookies from an employee with active access (which can bypass passwords and MFA entirely), or abuse of compromised third-party social-media management tooling used to schedule and publish posts on behalf of the brand account.
Part of a recurring pattern
This is not Microsoft's first X hijacking. In June 2024, the @MicrosoftIndia account (then 211,000+ followers) was compromised and used to impersonate "Roaring Kitty" (meme-stock trader Keith Gill), luring victims into connecting cryptocurrency wallets to a drainer service. The broader tactic traces back to the July 2020 Twitter hack, in which 130 high-profile accounts — including Barack Obama, Bill Gates, and Elon Musk — were compromised via social engineering against Twitter support staff. More recently, security vendors Mandiant and CertiK both had their X accounts hijacked to push fake token claims and wallet-draining links, and researchers at SentinelOne have tracked an ongoing campaign targeting high-profile accounts — including journalists, diplomats, and platform employees — for the same purpose. Blockchain analysts at ScamSniffer previously linked a single wallet-drainer kit to roughly $59 million in stolen crypto across 63,000 victims.
Impact Assessment
| Impact Area | Description |
|---|---|
| Brand trust | A verified, 13M-follower corporate account briefly promoted an unauthorized crypto token, lending false legitimacy to the scam |
| Financial exposure | No confirmed reports of victim losses at time of writing, though pump-and-dump schemes rely on brief exposure windows to attract buyers before the token price collapses |
| Reputational | Microsoft's deleted "apology" post, which arrived mid-incident and was itself removed, added confusion rather than clarity for followers |
| Platform trust | Highlights continued gaps in X's account-security controls for high-value verified/brand accounts despite prior high-profile hijacks |
| Precedent risk | Second confirmed hijack of a Microsoft-branded X account in roughly two years, suggesting recurring exposure across the company's social media operations |
Recommendations
For social media and brand teams
- Enforce hardware-key (FIDO2/WebAuthn) MFA on all corporate social accounts rather than SMS or authenticator-app codes, which remain vulnerable to SIM swapping and phishing.
- Restrict and audit access to third-party social media management tools (scheduling platforms, API integrations) that hold persistent session tokens or API keys for brand accounts.
- Rotate API tokens and session credentials for social accounts on a regular cadence, and immediately upon any suspected compromise of an employee device with access.
- Maintain a documented, rehearsed incident response runbook for account takeovers, including pre-approved holding statements, so a scramble doesn't produce confusing follow-up posts like the deleted "apology" seen here.
For security teams
- Treat infostealer malware detections on any device with social media management access as a high-priority incident requiring immediate credential rotation, not just malware remediation.
- Monitor for impersonator accounts (e.g., accounts using brand names or mascots in usernames) that could be used to legitimize a future hijack via follows or reposts.
- Subscribe to domain and brand-abuse monitoring services to catch fraudulent token launches or liquidity pool claims that falsely reference your company's stock ticker or products.
For individual users and investors
- Treat any cryptocurrency promotion from a corporate account — even a verified one — with suspicion, especially tokens claiming a "liquidity pool" tied to a public company's stock ticker; legitimate companies do not launch tokens this way.
- Never connect a crypto wallet to a site linked from a social media post promoting a new or unfamiliar token, as these links are frequently wallet-drainer traps.
- If a familiar brand account appears to be behaving unusually (new follows, profile picture changes, off-brand posts), assume compromise and avoid interacting with any links it shares until the company confirms the account is secure.
Key Takeaways
- Microsoft's official X account (13M+ followers) was hijacked on October 1, 2026, and used to promote a fraudulent $Clippy cryptocurrency token falsely tied to $MSFT.
- The attack leveraged an impersonator account, @clippymsftcto (posing as Clippy), which the Microsoft account followed and reposted before X suspended it; a second account, @ClippyMSFT, continued the pitch afterward.
- Microsoft confirmed unauthorized access, secured the account, removed the malicious posts, and says it will pursue legal action against those responsible.
- The exact initial-access method is unconfirmed; likely vectors include SIM swapping, compromised recovery email, infostealer-stolen session cookies, or compromised third-party social media tooling.
- This is the second Microsoft-branded X account hijacked for a crypto scam in roughly two years, following the June 2024 @MicrosoftIndia "Roaring Kitty" wallet-drainer incident.
- The incident fits a broader, ongoing pattern of high-profile X account takeovers — including Mandiant, CertiK, the SEC, and numerous journalists and public figures — used to push fake tokens and wallet-draining links to large, trusting audiences.