Microsoft has confirmed that its official X account, which has more than 13 million followers, was hijacked last week by unknown attackers who used it to amplify a crypto pump-and-dump scheme built on a fake revival of Clippy, the office-assistant mascot.
"We have confirmed unauthorized access to our account on X including posts that did not come from Microsoft," a Microsoft spokesperson told BleepingComputer. "The account has been secured and the unauthorized posts have been removed, and we are continuing to investigate the circumstances."
How the Scheme Ran
The compromise became visible on Thursday, October 1, when the @Microsoft account followed and reposted a tweet from an account impersonating Microsoft's Clippy virtual assistant, as The Verge first reported. The impersonation account, @clippymsftcto, has since been suspended.
A separate account still promoting a $Clippy crypto token at the time of BleepingComputer's report claimed the token "has a liquidity pool paired directly with $MSFT" — an appeal to the tokenized-equity narrative that has accompanied a wave of unofficial stock-branded tokens. A since-deleted post styled as a Microsoft disclaimer, stating that the company had "not authorized, sponsored, endorsed, or granted permission" for any Clippy- or $MSFT-associated token, was also removed; Microsoft says it did not post that tweet.
No technical detail on how the account was taken over — credential compromise, session hijacking, insider threat or platform-side failure — has been disclosed. Microsoft says its investigation is continuing.
A Repeat Pattern With a Known Playbook
This is the second compromise of a official Microsoft X presence used for crypto fraud: in June 2024, attackers hijacked @MicrosoftIndia to impersonate Roaring Kitty and push victims to a wallet-drainer site dressed as a GameStop token presale. The broader pattern is larger still. In January 2024, the SEC's @SECGov account was taken over in a SIM-swapping attack and used to post a fake Bitcoin ETF approval; the hacker responsible, Eric Council Jr., was sentenced to 14 months in prison in 2025.
The economics driving the pattern are documented: ScamSniffer reported in December 2023 that a single wallet drainer promoted through Twitter ads stole roughly $59 million from about 63,000 people in eight months.
The security takeaway for crypto users is behavioral, not technical. A verified badge and a large follower count signal account history, not message authenticity — and a compromise of exactly this kind is the delivery mechanism the drainer and pump-and-dump economy depends on. Token announcements arriving via any social account, however official, warrant independent verification against the company's own domains before a wallet is connected or a swap is signed.
TrustGrade tracks the security posture of platforms and protocols in digital assets. Verified trust data: trustgrade.ai.