The Verge reported on Thursday that Microsoft's official X account was hijacked. The account followed a Clippy-themed crypto account, reposted one of its posts, and switched its profile picture to Clippy. BleepingComputer said the account has over 13 million followers and the attack looked like a pump-and-dump scheme. That is when promoters hype a token so they can sell it at a higher price. The reposted account, @clippymsftcto, has been suspended. BleepingComputer said another account still pushes a $Clippy token, claiming a link to $MSFT. Microsoft said the account is secured and the posts are gone.
Microsoft has not said how the attackers got in, according to SecurityWeek. The company says it is still looking into what happened. The sources differ on one point. The Verge and SecurityWeek said an apology post appeared about 30 minutes later and was soon deleted. BleepingComputer later updated its report to say Microsoft did not post that message. The sources do not name the attackers or say whether anyone lost money.
BleepingComputer noted that Microsoft India's X account was hijacked in June 2024 to spread wallet-draining malware. SecurityWeek said the SEC's account was taken over in 2024 through SIM swapping, which means taking control of a phone number. SecurityWeek also listed tools that are allowed to post for a company as one possible way in. For teams that run software, a brand's social accounts and the tools linked to them can be targets.