Microsoft's X account hijacked in $Clippy crypto pump-and-dump
Microsoft confirmed unauthorized access to its 13M-follower official X account on Oct 2 after it promoted a fake $Clippy token. Posts were removed within about half an hour.
Microsoft's official @Microsoft account on X — over 13 million followers — was hijacked on October 2 and used to shill a cryptocurrency token before the company regained control. Microsoft confirmed the compromise. Coverage: BleepingComputer and SecurityWeek.
What happened
The account's profile picture was swapped to the Clippy mascot, and it began following and reposting a crypto account, @clippymsftcto, pushing a $Clippy token that falsely claimed its liquidity pool was paired directly with $MSFT. The scheme is a textbook pump-and-dump: borrow a trusted brand's reach to inflate a token, then sell into the volume the hype creates.
Microsoft's statement, quoted by both outlets: "We have confirmed unauthorized access to our account on X including posts that did not come from Microsoft. The account has been secured and the unauthorized posts have been removed." The company said it would pursue appropriate legal action and stressed it does not endorse or have any affiliation with the token.
Scope and timeline
- Account: @Microsoft, ~13M followers.
- Dwell time: the unauthorized posts were up for roughly 30 minutes before removal.
- Fallout: the impersonating @clippymsftcto account and related posts were subsequently suspended.
Exploitation status
Microsoft has not disclosed how the attackers got in. BleepingComputer notes the usual candidates for a hijack of this kind — SIM swapping, compromise of an associated email address, or infostealer-harvested session tokens. No root cause is confirmed, and there is no indication the breach reached beyond the social account.
Action checklist
If your organization runs high-follower brand accounts, this is a reminder, not a Microsoft-specific problem:
- Enforce phishing-resistant MFA (passkeys or FIDO2 security keys) on every social account and its recovery email — SMS-based 2FA is what SIM-swaps defeat.
- Move brand accounts to X's organization/role-based access where available, so no single personal login is the whole blast radius.
- Inventory who has posting access and revoke stale third-party app authorizations and OAuth tokens quarterly.
- Have a takedown-and-statement playbook ready: the damage here is measured in the minutes a trusted account is pushing a scam.
Context
Verified brand and government accounts are a recurring target precisely because the follower count is the exploit — a 30-minute window on a 13-million-follower feed is worth more to a token scam than any novel malware. The vector almost never touches Microsoft's own infrastructure; it touches the account's login and recovery path. That the world's most security-resourced vendor still lost a half-hour on its flagship account is the point.