Hackers Use Microsoft’s X Account to Amplify Clippy Crypto Scheme

Hackers used Microsoft’s X account to amplify a Clippy crypto scheme, exposing how trusted brand accounts can spread scams and mislead their followers.

Oct 5, 2026
4 minute read
Microsoft icon.

Microsoft's X account was hacked again. The lesson is simple. Image: Unsplash

eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Microsoft’s 13-million-follower X account was hijacked and turned into a crypto megaphone, with attackers using the company’s own identity to promote an unauthorized Clippy-themed token.

The attackers took control of Microsoft’s official X account on Oct. 1 and, according to PCMag, changed its profile picture to Clippy, then used it to repost content from an account impersonating the retired Office assistant.

BleepingComputer says the impersonating account is now suspended. Another account that reposted Microsoft’s unauthorized activity promoted a $Clippy cryptocurrency token, claiming a liquidity pool pairing with ‘$MSFT.’ That claim did not establish any connection to Microsoft shares or company backing. The activities effectively created the appearance that Microsoft itself was behind, or at least associated with, the token.

In a more confusing turn of events, the Microsoft account later posted an apology, noting that the earlier activity was unauthorized, but according to the company’s statement to PCMag, even that “apology” tweet didn’t come from Microsoft. The company has, however, regained full control of the X account.

The incident appears designed to exploit something more valuable than the account itself: the trust users have in it. By placing a crypto promotion inside activity coming from Microsoft's legitimate account, the attackers could give a questionable token the appearance of corporate backing.

BleepingComputer characterized the activity as an apparent pump-and-dump scam. However, no public confirmation shows the attackers completed a profitable dump.

The company has not disclosed how the attackers gained access, meaning there is currently no evidence tying the incident to phishing, stolen credentials, SIM swapping, or an X vulnerability. It also has not named anyone behind the incident.

What is unmistakably clear right now is that this is an unauthorized takeover of Microsoft's X presence. But the available evidence does not show that the attackers breached Microsoft's internal systems or customer infrastructure. What they demonstrably compromised was a trusted public-facing identity and the audience attached to it.

A steady breach pattern

Microsoft’s latest X compromise is not an isolated case of attackers turning a trusted brand account into a fraud vehicle. In June 2024, attackers hijacked Microsoft India’s X account, which had more than 211,000 followers.

Advertisement

More recently, attackers compromised Brevo, the third-party email platform hardware-wallet maker Trezor uses to send a phishing campaign to roughly 347,000 newsletter subscribers.

The U.S. Securities and Exchange Commission faced a similar takeover in January 2024, when an attacker used a SIM swap to gain control of the phone number associated with its X account and publish a false announcement approving spot Bitcoin exchange-traded funds.

And the high-profile 2020 Twitter breach showed what happens when attackers go deeper into the platform itself.

Attackers used phone-based social engineering against Twitter employees to access internal tools. They targeted 130 accounts and published posts from 45, including a Bitcoin scam that stole approximately $118,000.

The methods differed, but the payoff followed the same principle: control something people already trust, and the attacker may not need to build credibility from scratch. 

Where does this leave internet users?

For ordinary internet users, the main lesson is uncomfortable but simple: a genuine account does not guarantee that every post coming from it is genuine. Microsoft’s account was real, its audience was real, and the posts were still fraudulent because an attacker had gained control of the account.

The financial impact deserves even more caution. Social-media investment scams often rely on urgency, celebrity or corporate association, and promises of easy returns. At the same time, pump-and-dump schemes depend on convincing enough people to buy before the promoters sell.

There is also a personal-security lesson: users should assume their accounts could become the next distribution point if compromised. To help combat that, users should use strong, unique passwords and two-factor authentication.

Organizations should limit publishing access to staff who need it, review permissions regularly, and remove access when responsibilities change.

Advertisement

Merely limiting what social media managers can access is not enough, because an attacker does not need administrative privileges to cause serious damage.

As this incident shows, even the basic ability to publish a post can be abused to impersonate the organization, mislead its audience, or promote something fraudulent, meaning organizations need to pair access controls with cybersecurity awareness, strong authentication, and secure, well-managed devices.

Before acting on a post involving money, credentials, or wallet access, verify the claim through the company’s website or another independently accessed channel. A familiar account can still carry an unauthorized message.

Read more: A phishing campaign sent through Trezor’s legitimate newsletter system shows how attackers can also exploit trusted email channels to target cryptocurrency users.

Joseph Chisom Ofonagoro

Joseph is a Technical Writer with about 3 years of experience in the industry, also advancing a career in cyber threat intelligence. He is passionate about the responsible use of technology, a passion that led him into cybersecurity. As an undergrad, he leads a novel community of technology enthusiasts at his school, NOUN, where he guides and shares resources for beginners in tech. His writing experience includes a diverse range of topics, from consumer tech to startups to tutorials. Additionally, he periodically shares case studies and research reports on cybersecurity on his social media pages.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.