Microsoft’s account on X was hacked and used to promote a cryptocurrency token, turning the technology company’s 13-million-follower social media presence into part of an apparent crypto pump-and-dump operation.
The incident centered on the company’s @Microsoft account and began with activity involving another X profile impersonating Clippy, Microsoft’s former virtual assistant.
The Microsoft account followed and reposted a post from @clippymsftcto, an account that has since been suspended.
The activity subsequently drew attention to a $Clippy token. Another account, @ClippyMSFT, reposted Microsoft’s message and continued promoting the cryptocurrency. That account claimed the token had a liquidity pool directly paired with $MSFT.
Microsoft later removed the unauthorized posts and acknowledged that its account had been accessed unauthorized.
A company spokesperson said the account had been secured and that Microsoft was investigating how the breach occurred.
The company also made clear that it had no association with the cryptocurrency which was being promoted. Microsoft said it did not authorize, sponsor or endorse a cryptocurrency associated with Clippy, Microsoft or $MSFT, and had not authorized the use of its branding or intellectual property in connection with such a token.
The incident is part of a long pattern of cryptocurrency scams involving compromised accounts belonging to major organizations.
Microsoft itself experienced a similar breach in June 2024, when its Microsoft India account, which had more than 211,000 followers, was taken.
In that case, attackers used the account to impersonate meme-stock trader Keith Gill, known online as Roaring Kitty. They attempted to lure users to a website advertising a supposed GameStop cryptocurrency presale. Victims who connected their wallets and authorized transactions instead had their crypto assets stolen through a wallet-drainer malware.
Compromised social media accounts has been a particularly useful tool for cryptocurrency scams, as posts from established organizations can appear more credible to potential victims.
ScamSniffer reported in December 2023 that approximately $59 million in cryptocurrency has been stolen from 63,000 people through a Twitter advertising campaign using the “MS Drainer” wallet-draining service between March and November.
Government accounts have also been targeted. In January 2024, the U.S. Securities and Exchange Commission’s official X account was compromised through a SIM-swapping attack. Attackers used it to publish a fake announcement claiming that Bitcoin exchange-traded funds had received approval, temporarily but significantly moving Bitcoin’s price.
Eric Council Jr., identified as the hacker who compromised the SEC account, pleaded guilty in February 2025 and was sentenced to 14 months in prison over his involvement in the scheme.
Microsoft now has its account secured and the posts associated with the breach removed. Its investigation is ongoing, but the cryptocurrency promotion associated with the unauthorized activity has further raised the risks of trusting what appear to be legitimate social media posts when they involve digital-asset promotions.
Read the original article:
