Skip to content

Security3 publishers2 min readPublished

Attackers hijack Microsoft's 13-million-follower X account to promote a Clippy crypto token

Unknown attackers hijacked @Microsoft, the company's X account with more than 13 million followers, on Thursday to promote a $Clippy crypto token. Microsoft has not said how they got in, and the takeover fits a run of crypto-scam hijacks of verified accounts on X.

The Watch · Security desk

Illustration accompanying Attackers hijack Microsoft's 13-million-follower X account to promote a Clippy crypto token

What happened

  • The takeover started with @Microsoft following and reposting @clippymsftcto, a now-suspended account impersonating the Clippy assistant, as The Verge first reported.
  • Microsoft says the account has been secured and the attackers' posts removed, and that it is still investigating the circumstances.
  • A second account, @ClippyMSFT, still links to Microsoft's retweet and claims the $Clippy token has a liquidity pool paired directly with $MSFT.
  • In a since-deleted post, Microsoft apologized for the posts and said it would take legal action over the token.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint Until Microsoft says how the attackers got in, other companies running X accounts cannot check themselves against this specific failure; the only public entry point among the cited cases is the SEC's SIM swap.
  • exposure Securing @Microsoft ended the attackers' access but left the endorsement in circulation, so anyone who reaches @ClippyMSFT can still be shown Microsoft's repost as backing for the token.
  • precedent The SEC hijack produced a guilty plea and a 14-month sentence, so using a seized verified account to move a price already has a prosecution on record.

The token pitch ran on Clippy impersonator accounts, and @Microsoft gave it reach with a follow and a repost [2][3]. BleepingComputer described the operation as what appeared to be a pump-and-dump [1]. Microsoft's since-deleted statement addressed the stock ticker the promoters used. "Microsoft has not authorized, sponsored, endorsed, or granted permission for the creation, promotion, or use of any cryptocurrency token associated with Clippy, Microsoft, or $MSFT," the company wrote [7].

The breach Microsoft has confirmed is one social account. "We have confirmed unauthorized access to our account on X including posts that did not come from Microsoft," a Microsoft spokesperson told The Verge [4]. The company has not said how the attackers got in, and a spokesperson was not immediately available when BleepingComputer asked for more details [8].

BleepingComputer cites an earlier Microsoft case. In June 2024, crypto scammers took over @MicrosoftIndia, an account with more than 211,000 followers, and used it to impersonate Roaring Kitty, the handle of meme-stock trader Keith Gill [9]. They replied to tweets and steered people to presaIe-roaringkitty[.]com, a fake presale for GameStop crypto. Anyone who connected a wallet there and authorized transactions lost their crypto to a drainer [10].

@Microsoft has roughly 60 times that audience [1]. The 2024 crew emptied wallets directly. Thursday's attackers, on the reporting so far, promoted a token [1][10].

The SEC case is the one in this set with a known entry point. Its @SECGov account was taken over through SIM swapping and used to post a fake approval of Bitcoin exchange-traded funds. Bitcoin's price spiked, temporarily but significantly [12]. Eric Council Jr., the hacker behind that takeover, pleaded guilty in February 2025 and was sentenced to 14 months in prison for his role in a conspiracy to manipulate Bitcoin's value [13].

What to watch

  • Whether Microsoft's investigation discloses how the attackers gained access to @Microsoft.
  • Whether @ClippyMSFT is suspended, and whether Microsoft's promised legal action names the token's creators.
  • Any trading data showing how much money went into $Clippy while Microsoft's repost was up.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories