Microsoft’s Official X Account Hacked to Promote Fake Clippy Cryptocurrency Token
Unknown attackers took over Microsoft’s official X account, which has more than 13 million followers, in an apparent cryptocurrency pump-and-dump scheme.
The account compromise began when @Microsoft followed and reposted a message from an X account impersonating Microsoft’s virtual assistant Clippy. The impersonating account, @clippymsftcto, has since been suspended.
The post promoted a cryptocurrency token called $Clippy and falsely claimed that its liquidity pool was directly linked to $MSFT. Another account, @ClippyMSFT, also reposted messages promoting the token.
Microsoft has deleted the attacker’s post, acknowledged the incident, and said it is investigating the unauthorized access.
A Microsoft spokesperson told The Verge, “We have confirmed unauthorized access to our accounts on X, including posts not from Microsoft. The account has been secured, the fraudulent post has been removed, and we are continuing to investigate the situation.”
In a now-deleted post, Microsoft apologized for the unauthorized message and said it does not support cryptocurrencies or crypto-related tokens. The company also said it would take legal action against those responsible.
“We are aware of the promotion of cryptocurrency tokens in connection with $MSFT stock, including misappropriation of the Clippy brand and Microsoft-related intellectual property,” Microsoft said. “Microsoft does not endorse, sponsor, approve, or authorize the creation, promotion, or use of cryptocurrency tokens related to Clippy, Microsoft, or $MSFT.”
“We take this matter seriously and will take appropriate legal action to remove the unauthorized token and related materials. For the avoidance of doubt, Microsoft does not endorse or have any relationship with this token, its creators, or any associated crypto projects.”
A Microsoft spokesperson did not immediately respond to BleepingComputer’s request for further details about the incident.

Microsoft India X account hacked in 2024
This is not the first time Microsoft’s official X accounts have been compromised. In June 2024, cryptocurrency scammers took over Microsoft India’s X account, @MicrosoftIndia, which had more than 211,000 followers.
The attackers impersonated Roaring Kitty, the online handle used by meme stock trader Keith Gill, and used the compromised account to lure victims to a malicious cryptocurrency website.
The hijacked account directed Microsoft India followers and other X users to presale-roaringkitty[.]com, which falsely claimed to offer an authorized presale for a GameStop (GME) cryptocurrency.
The attackers connected their cryptocurrency wallets to the site and stole digital assets from victims who authorized transactions through the malicious service.
X account hijackings continue to enable crypto scams
In recent years, X users have increasingly been targeted by account hijackings and malicious advertising campaigns. Verified organizations and high-profile accounts have been compromised to promote cryptocurrency fraud, phishing sites, and wallet-draining malware.
Blockchain threat analysts at ScamSniffer reported in December 2023 that cybercriminals stole approximately $59 million in cryptocurrency from 63,000 people during a Twitter advertising campaign conducted between March and November. The campaign used the “MS Drainer” wallet-draining malware.
The U.S. Securities and Exchange Commission’s @SECGov account was also compromised in a SIM-swapping attack. The attacker used the account to post a fake announcement claiming that the SEC had approved Bitcoin exchange-traded funds (ETFs). The post caused a temporary but significant spike in Bitcoin’s price.
Eric Council Jr., who was identified as the attacker behind the SEC account hijacking, pleaded guilty in February 2025 and was sentenced to 14 months in prison for his role in a conspiracy to manipulate Bitcoin’s value using compromised accounts.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a two-hour digital summit about what will change with AI-speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



