The news
Hackers took control of Microsoft's official account on X, which has more than 13 million followers, and used it to promote a cryptocurrency token themed on Clippy, the animated paperclip assistant from old versions of Microsoft Office. The takeover happened on October 2, 2026, according to SecurityWeek and BleepingComputer.
The attackers changed the account's profile picture to Clippy and followed and reposted an account called @clippymsftcto, which has since been suspended, SecurityWeek and BleepingComputer reported. The scheme promoted a $Clippy token, and another account, @ClippyMSFT, claimed the token had a liquidity pool paired directly with $MSFT, the ticker of Microsoft (MSFT), according to BleepingComputer. The posts on Microsoft's account remained visible for roughly 30 minutes before they were deleted, according to SecurityWeek.
An apology message also appeared briefly on the account and was then removed. Microsoft told SecurityWeek that this apology was itself part of the unauthorized activity and did not come from the company.
A Microsoft spokesperson confirmed unauthorized access to the account, including posts that did not come from the company, and said the account had been secured and the posts removed, as reported by BleepingComputer. Microsoft also said it has not authorized, sponsored or endorsed any cryptocurrency token linked to Clippy, Microsoft or $MSFT, according to the same outlet.
Microsoft did not say how the attackers got in. SecurityWeek listed common routes for such takeovers, including SIM swapping, compromise of the email address tied to the account, infostealer malware that steals browser session cookies, and a compromised third-party social media management tool. Neither outlet reported how much money, if any, buyers of the token lost.
The incident echoes a June 2024 case in which Microsoft India's X account, with about 211,000 followers, was hijacked to spread wallet-draining malware, BleepingComputer noted.
The numbers
- Followers on Microsoft's X account
- More than 13 million
- Time unauthorized posts stayed up
- About 30 minutes
Why CEOs should care
For CISOs, this is an identity problem, not a marketing problem. If Microsoft, which sells identity security, can lose control of its main social account, any company can. Brand accounts should sit inside the identity program: owned by a corporate email address, protected with phishing-resistant multifactor authentication such as passkeys or hardware keys, and never tied to a phone number that can be SIM-swapped.
Ask three questions this quarter. Who has login access to each of our official accounts, including agencies and contractors? Which third-party scheduling or management tools are connected, and with what permissions? How fast can we lock an account and post a correction if it is taken over? Session-cookie theft by infostealer malware can bypass passwords and multifactor prompts, so devices used by social media staff need the same endpoint protection as admin workstations.
For CEOs and general counsel, a hijacked account can do harm in minutes: a fake endorsement of a token, a false market statement or a malware link sent to millions of followers. Prepare a playbook with the platform's escalation contacts and pre-approved messages, and decide in advance who can speak for the company when its own channels cannot be trusted.
The bigger picture
Crypto pump-and-dump schemes favor verified corporate and celebrity accounts because a trusted name can drive a burst of buying before the scam is spotted. The use of a stock ticker in the posts shows an attempt to borrow credibility from a listed company. As companies rely more on social platforms for announcements, those accounts become high-value targets in their own right.
What’s next
Watch whether Microsoft or X explains how the account was accessed, which would show whether the weak point was a credential, a device or a connected tool.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error
Companies in this story








