Crypto Scammers Hijack Microsoft's Official X Account
Microsoft's official X account was compromised and used to promote a cryptocurrency scam featuring the Clippy mascot, highlighting social media account takeover risks.

Microsoft has confirmed that its official X (formerly Twitter) account, boasting over 13 million followers, was compromised on Thursday and subsequently used by attackers to promote a cryptocurrency scam. The attackers leveraged the hijacked account to follow a specific crypto account and repost its messages, even replacing Microsoft's profile picture with the iconic Clippy mascot, a nostalgic reference to older versions of Microsoft Office.
The fraudulent cryptocurrency promotion involved a token, identified as $Clippy, which was allegedly paired with the $MSFT token, suggesting an attempt to associate the scam with Microsoft's stock. The account behind the scam, @clippymsftcto, which posed as Clippy, has since been suspended by the platform. A second account involved in the incident continued to push the $Clippy token.
Following the unauthorized activity, the malicious posts were removed from Microsoft's official account. A brief apology, which appeared on the account approximately 30 minutes after the initial compromise and was subsequently deleted, acknowledged a token being marketed in connection with Microsoft's stock without authorization. The deleted statement emphasized that Microsoft does not support, endorse, sponsor, or authorize any cryptocurrency or related tokens.
A Microsoft spokesperson confirmed the unauthorized access to The Verge, stating, "We have confirmed unauthorized access to our account on X, including posts that did not come from Microsoft." The spokesperson added that the account has since been secured, the unauthorized posts removed, and an investigation into the circumstances is ongoing.
While Microsoft has not disclosed the specific method used to gain access to its X account, several potential vectors exist for such account takeovers. These include SIM swapping attacks, which have previously affected other high-profile accounts like the SEC's X account, or the hijacking of the email address associated with password resets. Another common method involves infostealer malware on an employee's device, which can steal active session cookies, allowing attackers to bypass password and multi-factor authentication requirements.
Compromised third-party marketing or social media management tools that have been granted posting privileges on behalf of the company also represent a significant risk. These tools, if breached, can provide attackers with direct access to post content through legitimate channels, making detection more challenging. The incident underscores the persistent threat of social media account takeovers and the sophisticated tactics employed by cybercriminals to exploit them for financial gain.
The incident serves as a stark reminder of the security challenges faced by large organizations managing extensive social media presences. The use of a well-known mascot like Clippy indicates a targeted effort to leverage brand recognition and nostalgia to lure unsuspecting users into participating in the cryptocurrency scam. The rapid response from Microsoft to secure the account and remove the malicious content is crucial, but the investigation into the root cause remains paramount to prevent future occurrences.