Skip to content
TECH CEO Daily
CybersecuritySecurity Alert

Hackers hijack Microsoft's 13-million-follower X account to promote a Clippy crypto token

Unauthorized posts promoting a $Clippy token stayed up for about 30 minutes; Microsoft says the account has been secured and the posts removed.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1Hackers took over Microsoft's official X account, which has more than 13 million followers, on October 2, 2026.
  • 2The account promoted a $Clippy crypto token; another account claimed it was paired with $MSFT. Posts stayed up about 30 minutes.
  • 3Microsoft confirmed unauthorized access and said the account was secured, but did not say how it was breached.

The news

Hackers took control of Microsoft's official account on X, which has more than 13 million followers, and used it to promote a cryptocurrency token themed on Clippy, the animated paperclip assistant from old versions of Microsoft Office. The takeover happened on October 2, 2026, according to SecurityWeek and BleepingComputer.

The attackers changed the account's profile picture to Clippy and followed and reposted an account called @clippymsftcto, which has since been suspended, SecurityWeek and BleepingComputer reported. The scheme promoted a $Clippy token, and another account, @ClippyMSFT, claimed the token had a liquidity pool paired directly with $MSFT, the ticker of Microsoft (MSFT), according to BleepingComputer. The posts on Microsoft's account remained visible for roughly 30 minutes before they were deleted, according to SecurityWeek.

An apology message also appeared briefly on the account and was then removed. Microsoft told SecurityWeek that this apology was itself part of the unauthorized activity and did not come from the company.

A Microsoft spokesperson confirmed unauthorized access to the account, including posts that did not come from the company, and said the account had been secured and the posts removed, as reported by BleepingComputer. Microsoft also said it has not authorized, sponsored or endorsed any cryptocurrency token linked to Clippy, Microsoft or $MSFT, according to the same outlet.

Microsoft did not say how the attackers got in. SecurityWeek listed common routes for such takeovers, including SIM swapping, compromise of the email address tied to the account, infostealer malware that steals browser session cookies, and a compromised third-party social media management tool. Neither outlet reported how much money, if any, buyers of the token lost.

The incident echoes a June 2024 case in which Microsoft India's X account, with about 211,000 followers, was hijacked to spread wallet-draining malware, BleepingComputer noted.

The numbers

Followers on Microsoft's X account
More than 13 million
Time unauthorized posts stayed up
About 30 minutes

Why CEOs should care

For CISOs, this is an identity problem, not a marketing problem. If Microsoft, which sells identity security, can lose control of its main social account, any company can. Brand accounts should sit inside the identity program: owned by a corporate email address, protected with phishing-resistant multifactor authentication such as passkeys or hardware keys, and never tied to a phone number that can be SIM-swapped.

Ask three questions this quarter. Who has login access to each of our official accounts, including agencies and contractors? Which third-party scheduling or management tools are connected, and with what permissions? How fast can we lock an account and post a correction if it is taken over? Session-cookie theft by infostealer malware can bypass passwords and multifactor prompts, so devices used by social media staff need the same endpoint protection as admin workstations.

For CEOs and general counsel, a hijacked account can do harm in minutes: a fake endorsement of a token, a false market statement or a malware link sent to millions of followers. Prepare a playbook with the platform's escalation contacts and pre-approved messages, and decide in advance who can speak for the company when its own channels cannot be trusted.

The bigger picture

Crypto pump-and-dump schemes favor verified corporate and celebrity accounts because a trusted name can drive a burst of buying before the scam is spotted. The use of a stock ticker in the posts shows an attempt to borrow credibility from a listed company. As companies rely more on social platforms for announcements, those accounts become high-value targets in their own right.

What’s next

Watch whether Microsoft or X explains how the account was accessed, which would show whether the weak point was a credential, a device or a connected tool.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

MicrosoftXCryptocurrency scamsAccount takeoverSocial media security

Earlier coverage of Microsoft

All Microsoft coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.