Microsoft’s official X account was hijacked on Thursday by cryptocurrency scammers, who used the platform to amplify their Clippy-themed crypto account to over 13 million followers. The attackers not only posted a message from the compromised account but also replaced Microsoft’s profile picture with an image of Clippy, the animated paperclip assistant that shipped with older versions of Office.
The affected X account is a highly followed one, with more than 13 million users. It was used to follow and share messages from the cryptocurrency scammer’s account, @clippymsftcto, which posed as Clippy and has since been suspended by X. A second account involved in the incident kept pushing a $Clippy token, stating that its liquidity pool was paired with $MSFT, Microsoft’s stock ticker symbol.
The posts were eventually removed, but not before an apology appeared on the Microsoft account for roughly 30 minutes. The apology stated that Microsoft was aware of a token being marketed using the Clippy brand without permission and clarified that it does not support or endorse any cryptocurrency or crypto-related tokens. However, when this message was deleted soon after, it left many wondering what had really happened.
Microsoft has confirmed unauthorized access to its account on X, stating that “the account has been secured” and the posts have been removed. The company is continuing to investigate the circumstances surrounding the incident but has not revealed how the attackers gained access to its account. According to security experts, hackers have several options beyond simply tricking a social media manager into entering their credentials on a phishing page.
One of these methods involves taking over the phone number tied to the account through SIM swapping, as it happened with the SEC’s X account in 2024. Another option is hijacking the email address used for password resets. In some cases, attackers can even use infostealer malware on an employee’s device to steal browser session cookies from an active login, allowing them to access the account without a password or an MFA prompt.
The incident highlights the risks associated with third-party marketing and social media management tools that have been authorized to post on a company’s behalf. If compromised, these tools can provide attackers with easy access to high-profile accounts like Microsoft’s.
As a result of this incident, users should be cautious when interacting with popular X accounts, especially those related to cryptocurrency or finance. It is essential for companies to regularly review and update their security protocols to prevent similar incidents from occurring in the future. Furthermore, users should remain vigilant and report any suspicious activity on X to ensure that their accounts are secure.
Source: SecurityWeek — 2026-10-02