www.theverge.com Microsoft X Account Compromised in Crypto Scam
Article Content
- •Microsoft's X account was hijacked to promote a Clippy-themed cryptocurrency scam.
- •The incident involved unauthorized posts and account changes, affecting over 13 million followers.
- •Microsoft is investigating the breach and plans legal action against the unauthorized token.
On October 2, 2026, Microsoft confirmed that its official X account was hijacked by attackers promoting a cryptocurrency token themed around Clippy, the company's virtual assistant. The account, with over 13 million followers, followed and reposted messages from a now-suspended account impersonating Clippy. A second account continued to promote a $Clippy token, falsely claiming a liquidity pool paired with $MSFT stock. Microsoft quickly removed the unauthorized posts and stated it was investigating the breach. The company emphasized that it does not endorse any cryptocurrency or related tokens, and it plans to pursue legal action against the unauthorized use of its intellectual property. The method of account compromise remains unclear, with potential vectors including phishing, SIM swapping, or compromised third-party tools. This incident follows a similar attack on Microsoft's India account in June 2024.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (7)
Following this threat?
Track Microsoft in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What specific actions did Microsoft take after the breach?
Is the $Clippy token legitimate?
How did the attackers gain access to the account?
Continue Reading
Citrix NetScaler Critical Vulnerabilities Exploited: Urgent Patching Required Citrix NetScaler ADC and Gateway products are affected by critical vulnerabilities CVE-2026-88771 and CVE-2026-88772, both assigned a CVSS score of 9.5. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, and mandated…
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…