[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fYK_NldBr5IhjDCQgTpWSJxb7SXV-yg-5WKIX26NqbMQ":3},{"article":4,"iocs":48},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":27,"category":28,"article_tags":32},"2b5589ee-27d8-4130-bb75-68719f03f893","Crypto Scammers Hijack Microsoft’s Official X Account","crypto-scammers-hijack-microsoft-s-official-x-account-989586","Hackers used the account, which has 13 million followers, to amplify a Clippy-themed cryptocurrency account. The post Crypto Scammers Hijack Microsoft’s Official X Account appeared first on SecurityWeek.","Microsoft's official X account was compromised and used to amplify a Clippy-themed cryptocurrency scam. The attackers changed the profile picture to Clippy, followed a crypto account (@clippymsftcto), and promoted a fake $Clippy token falsely claiming MSFT pairing. Microsoft secured the account within 30 minutes and posted (then deleted) a statement clarifying it does not support any cryptocurrency, while investigating the breach.","Hackers hijacked Microsoft's official X account with 13M followers to promote fake Clippy-themed cryptocurrency token.","Microsoft has confirmed that its official X account was taken over on Thursday and used to amplify a Clippy-themed cryptocurrency account. According to The Verge, the company’s account, which has more than 13 million followers, started following the crypto account and shared one of its messages. Microsoft’s profile picture was also replaced with an image of Clippy, the animated paperclip assistant that shipped with older versions of Office. The account behind the reposted message, @clippymsftcto, posed as Clippy and has since been suspended. A second account involved in the incident kept pushing a $Clippy token, saying its liquidity pool was paired with $MSFT. The posts were eventually taken down. According to The Verge, an apology appeared on the Microsoft account roughly 30 minutes later and was deleted soon after, with no explanation given. The now-deleted post said Microsoft was aware of a token being marketed in connection with its stock that used the Clippy brand without permission. “To be clear, Microsoft does not support, endorse, sponsor, or authorize any cryptocurrency or crypto-related token,” it read. A Microsoft spokesperson told The Verge, “We have confirmed unauthorized access to our account on X, including posts that did not come from Microsoft,” adding, “The account has been secured and the unauthorized posts have been removed, and we are continuing to investigate the circumstances.”Advertisement. Scroll to continue reading. Microsoft has not said how the attackers gained access to its account, and hackers have several options beyond tricking a social media manager into entering their credentials on a phishing page. They can take over the phone number tied to the account through SIM swapping, as it happened with the SEC’s X account in 2024, or hijack the email address used for password resets. Infostealer malware on an employee’s device can also steal browser session cookies from an active login, letting attackers access the account without a password or an MFA prompt. Another route is a compromised third-party marketing or social media management tool that has been authorized to post on the company’s behalf. Related: Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack Related: North Korea Suspected in $351 Million Bitget Crypto Heist Related: Party’s Over for Crypto Scammers Who Went on a Spending Spree After a $240 Million Bitcoin Theft Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Police Shut Down KillSec Ransomware, Identify Alleged Teen LeaderTreasury Blacklists Most-Wanted ATM Malware Developer and His NetworkGoogle Launches Gemini 4 Argon With Guardrail-Free Access for Vetted DefendersGoogle: AI Is Changing the Pace and Profile of Vulnerability DiscoveryGovernment, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day AttacksAnthropic Flags AI Agent Liability Risks as OpenAI Faces Hacking LawsuitHigh-Severity Vulnerabilities Patched in OpenSSL, WolfSSLNew Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks Latest News In Rare Move, Alleged Iranian State Hacker Extradited to USWarlock Expands SharePoint Exploitation in Critical Infrastructure AttacksAI Agents Aimed SQL Injection at US and Canadian Government SitesExploited Fortinet FortiMail Zero-Day Calls for Urgent ActionZero Trust Creator Says Model Holds Firm Against AI-Assisted AttacksOsavul Lands $10 Million to Spot Hostile Intent Across Cyber, Physical DomainsEnterprises Struggle to Prepare for AI and Quantum Threats, PwC SaysHacker Conversations: Rob Juncker, a Knock at the Door and a Moral Compass Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Securing AI Agents, MCPs, and AI Automations October 7, 2026 Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice. Register Virtual Event: Zero Trust & Identity Strategies Summit 2026 October 14, 2026 Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction. Register People on the MoveLumen Technologies has named Kim Keever as CSO.Quantum Secure Encryption Corp. has appointed Joseph Hall as CIO.David Cass has joined Grayscale Investments as Chief Risk Officer.More People On The MoveExpert Insights AI Has Changed Attack Speed, Not Security Fundamentals As AI accelerates vulnerability discovery and exploitation, so-called virtual patching still comes down to defense-in-depth and strong application security fundamentals. (Joshua Goldfarb) Four Cyber Threats Harboring Big Plans for the Future - AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. (Steve Durbin) Begin at the End: How to Enable Agentic Remediation Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael) “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Fcrypto-scammers-hijack-microsofts-official-x-account\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2026\u002F10\u002FX-Twitter.jpeg","2026-10-02T11:46:10+00:00","2026-10-02T12:00:04.722171+00:00",7,[18,21,24],{"name":19,"type":20},"Microsoft","vendor",{"name":22,"type":23},"X (Twitter)","technology",{"name":25,"type":26},"Clippy","product","2e06f76c-d5b9-4f54-9eef-4d3447b10730",{"id":27,"icon":29,"name":30,"slug":31},null,"Breaches","breaches",[33,38,43],{"category":34},{"id":35,"icon":29,"name":36,"slug":37},"2c8f44d4-b56e-47cf-9677-04f22c9ee78d","Identity & Access","identity-access",{"category":39},{"id":40,"icon":29,"name":41,"slug":42},"c5eccf7c-abbc-4bd3-bbed-e6da5cba8e73","Incident Response","incident-response",{"category":44},{"id":45,"icon":29,"name":46,"slug":47},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[]]