Protect.Computer
NEWS

Microsoft's Official X Account Hijacked to Push a Crypto Token

· 1 min read · Digital scams Identity theft
Microsoft's Official X Account Hijacked to Push a Crypto Token

On Thursday, unknown attackers hijacked the official Microsoft account on X, which has more than 13 million followers, in what looked like a pump-and-dump scheme promoting a crypto token. The attack surfaced when the @Microsoft account followed and reposted a tweet from an account impersonating Microsoft’s Clippy assistant, which X has since suspended, according to The Verge. A second Clippy-themed account that reposted Microsoft’s tweet was still promoting a “$Clippy” token, claiming it had a liquidity pool paired directly with $MSFT.

Microsoft confirmed “unauthorized access to our account on X including posts that did not come from Microsoft,” said the account has been secured and the posts removed, and that it is still investigating. In a now-deleted post the company said it does not support any cryptocurrency token and will pursue legal action over the unauthorized use of the Clippy brand. How the attackers got in has not been disclosed. It is not the first time: scammers hijacked the Microsoft India X account in June 2024 to push a wallet-drainer “presale”, and in 2024 the SEC’s X account was taken over through a SIM-swap to post a fake Bitcoin ETF approval.

For ordinary users the lesson is that a verified, high-profile account is no guarantee a post is legitimate. A brand announcing a surprise token, giveaway or “presale” is a classic sign of a hijack, and connecting a crypto wallet to a link from such a post can empty it.

Sources

Related reading