On Thursday, unknown attackers gained unauthorized access to Microsoft's official X account (@Microsoft), which has over 13 million followers. The compromise was used to promote a crypto pump-and-dump scheme.
The attack involved the Microsoft account following and reposting a tweet from an impersonating X account (@clippymsftcto) that mimicked Microsoft's Clippy virtual assistant. This account, now suspended, promoted a '$Clippy' crypto token, falsely claiming a liquidity pool paired with '$MSFT'. Another account, @ClippyMSFT, continues to promote the token.
Microsoft confirmed the unauthorized access, stating that posts not originating from the company were made. The account has since been secured, and the unauthorized posts removed. Microsoft is currently investigating the circumstances of the breach.
The company issued a statement clarifying that it does not support any cryptocurrency or crypto-related token and will pursue legal action against the unauthorized use of its brand and intellectual property. Microsoft explicitly denied any endorsement or affiliation with the '$Clippy' token or its creators.
This incident is not the first time a Microsoft X account has been targeted. In June 2024, the Microsoft India X account (@MicrosoftIndia) was also hijacked by crypto scammers. That previous attack involved impersonating 'Roaring Kitty' to lure victims and spread cryptocurrency wallet drainer malware.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Microsoft's official X account was compromised, leading to the promotion of a Clippy-themed cryptocurrency scam. The incident highlights ongoing social media security vulnerabilities, even for major corporations, and the potential for brand impersonation in crypto schemes.
Microsoft's official X account, with over 13 million followers, was compromised to promote a crypto pump-and-dump scheme involving a '$Clippy' token. Microsoft has secured the account, removed unauthorized posts, and is investigating the incident, stating it does not endorse any cryptocurrency.