Microsoft’s official account on X (@Microsoft), which has more than 13 million followers, was briefly compromised on Thursday by attackers running what appears to be a cryptocurrency pump-and-dump scheme. The company has confirmed the incident and says it is investigating.
According to reporting first published by The Verge, the compromised account followed and reposted content from a now-suspended account impersonating Microsoft’s Clippy virtual assistant (@clippymsftcto). A separate account, @ClippyMSFT, reposted the hijacked tweet and continues to promote a token called $Clippy, falsely claiming it has a liquidity pool tied directly to Microsoft’s stock ticker, $MSFT.
Microsoft removed the unauthorized posts and issued a statement confirming the breach. “We have confirmed unauthorized access to our account on X including posts that did not come from Microsoft,” a company spokesperson said, adding that the account has since been secured.
In a since-deleted post, Microsoft apologized and explicitly disavowed any connection to the token, stating it has not authorized, sponsored, or endorsed any cryptocurrency associated with Clippy, Microsoft, or $MSFT. The company said it intends to pursue legal action to have the unauthorized token and related materials removed.
Not Microsoft’s first brush with crypto hijackers
This is not the first time a Microsoft-branded X account has been compromised for crypto fraud. In June 2024, the @MicrosoftIndia account, with over 211,000 followers, was hijacked to impersonate meme-stock trader Keith Gill (“Roaring Kitty”). Attackers used that account to direct followers to a fraudulent GameStop crypto presale site that deployed wallet-draining malware, stealing funds from anyone who connected a wallet and approved transactions.
The incident fits a broader pattern of high-profile account takeovers fueling crypto scams. Blockchain analysts at ScamSniffer previously estimated that the “MS Drainer” tool alone stole roughly $59 million from 63,000 victims via a single wave of malicious ads between March and November 2023. Separately, the SEC’s official X account was compromised via SIM-swapping in 2024, resulting in a fake Bitcoin ETF approval post that briefly spiked Bitcoin’s price; the attacker behind that incident was sentenced to 14 months in prison.
Security professionals monitoring brand-impersonation risk should note that verified, high-follower accounts remain prime targets for crypto-related social engineering, and that rapid incident response and clear public disavowal, as Microsoft issued here, are critical to limiting victim exposure.
