Skip to content
Microsoft X Account Compromised in Crypto Scam

Microsoft X Account Compromised in Crypto Scam

First seen 2 Oct 2026, 13:08 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 2, 2026 at 15:08 UTC
  • •Microsoft's X account was hijacked to promote a Clippy-themed cryptocurrency scam.
  • •The incident involved unauthorized posts and account changes, affecting over 13 million followers.
  • •Microsoft is investigating the breach and plans legal action against the unauthorized token.

On October 2, 2026, Microsoft confirmed that its official X account was hijacked by attackers promoting a cryptocurrency token themed around Clippy, the company's virtual assistant. The account, with over 13 million followers, followed and reposted messages from a now-suspended account impersonating Clippy. A second account continued to promote a $Clippy token, falsely claiming a liquidity pool paired with $MSFT stock. Microsoft quickly removed the unauthorized posts and stated it was investigating the breach. The company emphasized that it does not endorse any cryptocurrency or related tokens, and it plans to pursue legal action against the unauthorized use of its intellectual property. The method of account compromise remains unclear, with potential vectors including phishing, SIM swapping, or compromised third-party tools. This incident follows a similar attack on Microsoft's India account in June 2024.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 17h ago How this analysis works

Timeline

2026-10-02
Microsoft X account compromised
Attackers hijacked the official Microsoft account, promoting a $Clippy cryptocurrency token and changing the profile picture to Clippy.
Securityweek
2026-10-02
Unauthorized posts removed
Microsoft confirmed the removal of unauthorized posts and secured the account, stating it was investigating the circumstances.
BleepingComputer

More articles in this cluster (7)

Following this threat?

Track Microsoft in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What specific actions did Microsoft take after the breach?
Microsoft removed unauthorized posts, secured the account, and is investigating the breach.
Is the $Clippy token legitimate?
No, Microsoft has stated it does not endorse or authorize any cryptocurrency related to its brand.
How did the attackers gain access to the account?
The exact method of compromise is unclear, but potential vectors include phishing or compromised third-party tools.