Skip to content
Brief Security & Trust ·

Microsoft's X account hacked to push a Clippy crypto token

The company says someone got into its official X account without permission and posted things it did not write.

In brief
  • Microsoft confirmed that someone without permission got into its official X account on Thursday. The account promoted a Clippy-themed crypto token before the posts were removed.
  • Microsoft has not said how the attackers got in. Sources disagree on whether Microsoft posted a later apology.

The Verge reported on Thursday that Microsoft's official X account was hijacked. The account followed a Clippy-themed crypto account, reposted one of its posts, and switched its profile picture to Clippy. BleepingComputer said the account has over 13 million followers and the attack looked like a pump-and-dump scheme. That is when promoters hype a token so they can sell it at a higher price. The reposted account, @clippymsftcto, has been suspended. BleepingComputer said another account still pushes a $Clippy token, claiming a link to $MSFT. Microsoft said the account is secured and the posts are gone.

Microsoft has not said how the attackers got in, according to SecurityWeek. The company says it is still looking into what happened. The sources differ on one point. The Verge and SecurityWeek said an apology post appeared about 30 minutes later and was soon deleted. BleepingComputer later updated its report to say Microsoft did not post that message. The sources do not name the attackers or say whether anyone lost money.

BleepingComputer noted that Microsoft India's X account was hijacked in June 2024 to spread wallet-draining malware. SecurityWeek said the SEC's account was taken over in 2024 through SIM swapping, which means taking control of a phone number. SecurityWeek also listed tools that are allowed to post for a company as one possible way in. For teams that run software, a brand's social accounts and the tools linked to them can be targets.

A WebPulse Brief: a short report of an important event, written by the WebPulse Newsroom with AI assistance and checked against the reporting below. When there is more to explain, we follow up with a full story. How we use AI.

Reporting: The Verge, SecurityWeek.