Skip to content
Microsoft X Account Compromised by Crypto Scammers

Microsoft X Account Compromised by Crypto Scammers

First seen 2 Oct 2026, 13:08 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 2, 2026 at 13:09 UTC
  • •Microsoft's X account was hijacked to promote a cryptocurrency scam.
  • •The account has over 13 million followers, amplifying the scam's reach.
  • •Microsoft is investigating how the unauthorized access occurred.

Microsoft's official X account was compromised on October 2, 2026, leading to unauthorized posts promoting a Clippy-themed cryptocurrency. The account, which has over 13 million followers, followed a crypto account and shared its messages, including a promotion for a $Clippy token. Microsoft confirmed the unauthorized access and stated that the account has been secured. An apology post appeared shortly after the incident but was deleted quickly. The method of attack has not been disclosed, but potential vectors include phishing, SIM swapping, or compromised third-party tools. Microsoft is currently investigating the incident.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-02
Microsoft X account compromised
The official @microsoft account followed a Clippy crypto account and shared its tweets, prompting an immediate response from Microsoft.
Securityweek
2026-10-02
Unauthorized posts removed
Microsoft confirmed the unauthorized posts were removed and the account secured shortly after the incident.
The Verge

More articles in this cluster (3)

Following this threat?

Track Microsoft in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

How did the attackers gain access?
The method of access has not been disclosed, but possibilities include phishing, SIM swapping, or compromised third-party tools.
What should I do if I followed the account?
If you followed the compromised account, consider unfollowing it and monitoring for any suspicious activity in your own accounts.
Is there a risk of further exploitation?
Currently, there is no confirmed ongoing exploitation, but users should remain vigilant for any unusual activity.