Crypto Scammers Hijack Microsoft’s Official X Account

Microsoft’s Official X Account Hijacked by Crypto Scammers

In a shocking incident that highlights the vulnerabilities of even the most secure social media accounts, Microsoft’s official X account was taken over by scammers who used it to promote a cryptocurrency scheme. The hijacking, which was confirmed by Microsoft on Thursday, involved the company’s 13 million-strong following being misled into supporting a fake cryptocurrency called $Clippy, which promised to be paired with Microsoft’s own stock.

The scam unfolded when the scammers took control of Microsoft’s X account and replaced its profile picture with an image of Clippy, the iconic paperclip assistant from older versions of Office. They then posted a message on behalf of the company, claiming that it was aware of a token being marketed in connection with its stock using the Clippy brand without permission. However, as The Verge reported, this post was quickly deleted, and an apology appeared on the account for roughly 30 minutes before being taken down.

Microsoft has since confirmed that its account was compromised, but has not revealed how the scammers gained access to it. According to experts, there are several ways in which hackers can take over a social media account, including SIM swapping, email hijacking, and even using infostealer malware on an employee’s device to steal browser session cookies.

The incident highlights the growing threat of social engineering attacks, where hackers use psychological manipulation to trick people into divulging sensitive information or performing certain actions. In this case, the scammers exploited Microsoft’s brand reputation to promote their fake cryptocurrency scheme, which has been suspended by X administrators.

The hijacking also underscores the importance of robust security measures for even the most secure social media accounts. As more and more companies use social media to engage with their customers, they need to be aware of the potential risks involved and take steps to protect themselves from such attacks.

In practical terms, this incident serves as a reminder that no account is completely secure, and that even the largest and most reputable brands can fall victim to social engineering attacks. As cybersecurity experts, we must remain vigilant and take steps to educate ourselves and others about these types of threats. By doing so, we can reduce the risk of falling prey to such scams and protect our online presence.

As a precautionary measure, it’s essential for individuals and organizations alike to be cautious when interacting with social media accounts, especially those that claim to represent well-known brands. Verify information before sharing or engaging with suspicious posts, and always be wary of messages that ask you to divulge sensitive information or perform certain actions. By being vigilant and informed, we can all play a role in preventing such incidents from happening in the future.


Source: SecurityWeek — 2026-10-02