Attackers swapped the tech giant’s profile picture for Clippy, reposted scam content, and briefly promoted a fraudulent $Clippy token before Microsoft scrambled to contain the breach
What happened to the @Microsoft account
On Thursday, unidentified attackers took over Microsoft’s official X (formerly Twitter) account, which has more than 13 million followers, and used it to promote a fake “Clippy” cryptocurrency token. The Verge’s Tom Warren first identified and reported the compromise. It is one of the most conspicuous social media takeovers of 2026, and it shows how exposed even the most valuable technology companies are to account takeover on platforms they don’t control.
The @Microsoft account normally carries product announcements, corporate communications and developer news. On Thursday it started following a newly created account impersonating Microsoft’s retired virtual assistant. That account, @clippymsftcto, was then reposted by Microsoft’s official handle. At the same moment, the Microsoft logo was replaced with an image of Clippy, the animated paperclip Microsoft retired from Office more than two decades ago and which is still one of the best-known mascots in computing.

Everything happened quickly, which is typical of hijackings meant to get as much exposure as possible before a security team can react. Within minutes the attackers were using Microsoft’s verified status and follower count to give a textbook pump-and-dump some legitimacy. The impersonator account promoted a token called “$Clippy,” and the promotional material claimed it had “a liquidity pool paired directly with $MSFT,” Microsoft’s NASDAQ ticker. That claim has no basis in how financial markets work.
Microsoft’s response made things worse. After the unauthorized posts were removed, an “apology” tweet appeared about thirty minutes later. It acknowledged the breach and threatened legal action against the token’s creators. Minutes later, Microsoft deleted that post too. From the outside I can’t tell whether the deletion came from confusion between response teams or from attackers who still had access to the account’s content pipeline. Microsoft hasn’t said.
How an account this size gets compromised
Microsoft has not disclosed the attack vector. Analysts and platform security researchers point to several probable methods that fit the observed indicators. Everything in this section is inference.
The most common route to a corporate account is phishing aimed at social media managers, community teams or marketing staff with admin access. Attackers typically send spear-phishing emails with urgent lures that link to fake X login pages. Microsoft’s account is probably run by a team rather than one person, which multiplies the number of possible targets. A single compromised team member could be enough, particularly if MFA was weakly enforced or session tokens were extracted.
Session theft is the second candidate. Infostealers such as RedLine, Raccoon and Lumma spread widely through 2025 and 2026 and are built to pull cookies, authentication tokens and session IDs off infected machines. If a social media manager’s workstation was infected, attackers could load the stolen cookies into their own browsers and get an authenticated session with no password and no MFA prompt. This is usually called pass-the-cookie or session hijacking, and it has been implicated in many high-profile takeovers across platforms.
SIM swapping is less likely against organizational accounts protected by hardware keys or authenticator apps, but it remains a threat. The attacker talks a mobile carrier into moving the victim’s number to a SIM they control and then intercepts SMS one-time passwords. The January 2024 takeover of the SEC’s @SECGov account worked this way, which shows that agencies with large security budgets are exposed too.
Third-party apps are another possibility. X lets outside applications hold varying levels of access to connected accounts. If a malicious or compromised tool still had elevated OAuth permissions on Microsoft’s account, an attacker who breached that tool could post without ever touching Microsoft’s credentials. Researchers have documented dormant or forgotten integrations becoming attack vectors months or years after they were authorized.
📬 Stay Ahead of Cyber Threats
Get the latest cybersecurity news, critical vulnerabilities, threat intelligence, tutorials, and exclusive giveaways delivered straight to your inbox. No spam. Unsubscribe anytime.
Subscribe to the Newsletter →Finally, enterprise social teams often use scheduling and management platforms such as Sprout Social, Hootsuite or Buffer. A breach at that level, through a supply chain attack, credential stuffing or API key theft, could reach every connected corporate account at once. Because these tools run many accounts, they deserve particular scrutiny.
Microsoft spokesperson Brent Colburn confirmed “unauthorized access” but said nothing about the attack vector, how long the compromise lasted, or whether other Microsoft accounts on X were affected. He said “the account has been secured and the unauthorized posts have been removed” and that the company is “continuing to investigate the circumstances.”
The $Clippy token and how the scam works
$Clippy has the structure of a coordinated pump-and-dump built to borrow credibility from a compromised institutional account. It fits a wider pattern of crypto fraud that has plagued X since the platform’s ownership transition and the moderation policy changes that followed.
The attackers created @clippymsftcto (now suspended), a handle that includes “msft” (Microsoft’s ticker) and “cto” (Chief Technology Officer) to look officially affiliated. Choosing Clippy was deliberate. The character is nostalgic, instantly recognizable and retired, so no active Microsoft product team would plausibly launch a Clippy initiative. That absurdity may have helped the scam. A victim might drop their skepticism because the premise seems too ridiculous to be a scam, a manipulation technique documented in the social engineering literature.
The claim of a liquidity pool paired with $MSFT is technically nonsense. Microsoft stock is a regulated equity traded on NASDAQ, and it can’t be paired with a token in a decentralized liquidity pool. Pools live inside DeFi protocols such as Uniswap, PancakeSwap or Raydium, where users deposit token pairs to enable automated trading. Either the author misunderstood financial markets or wanted to exploit casual observers who do, by faking institutional backing.
Blockchain security firms including Chainalysis, Elliptic and ScamSniffer have documented the pump-and-dump pattern at length. The attackers first mint or buy a large supply of the token at negligible cost, usually on a cheap chain such as Solana, BNB Chain or Base. The hijacked account then endorses, reposts or engages with the token, which can produce millions of impressions within minutes and looks like institutional validation. Retail buyers, trading bots that watch social sentiment and speculators chasing the move pile in and push the price up. At the peak, the attackers sell into the liquidity pool and pull out the cryptocurrency the late buyers deposited, and the price collapses. They then abandon the accounts, drain the liquidity and launder the proceeds through mixers, cross-chain bridges or privacy coins. The whole cycle can run in minutes to hours. Blockchain transactions are pseudonymous and irreversible, so victims rarely get their money back.
X suspended @clippymsftcto, but a second account, @ClippyMSFT, was still active at the time of reporting and kept promoting the token. Organized scam operations run redundant accounts for this reason: when moderation removes one, the others keep going.
Microsoft’s response and the deleted apology
The deleted apology amplified the incident, so it deserves a close look. Microsoft hasn’t said how long the malicious posts stayed up before removal. The apology, published about thirty minutes after they came down, said the token was being promoted “in connection with $MSFT stock,” confirmed the “unauthorized use of the Clippy brand and Microsoft-related intellectual property,” and stated that “Microsoft has not authorized, sponsored, endorsed, or granted permission for the creation, promotion, or use of any cryptocurrency token associated with Clippy, Microsoft, or $MSFT.” It added that Microsoft would “pursue appropriate legal action to have the unauthorized token and related materials removed” and “does not endorse or have any affiliation with this token, its creators, or any related cryptocurrency project.”

The statement was legally sound and factually accurate. Deleting it within minutes turned a controlled remediation into a spectacle. The deletion generated its own news coverage, fueled speculation that the account was still compromised, and looked like panic. Screenshots circulated across tech media and social platforms, so the apology reached more people deleted than it would have by staying up.
Microsoft hasn’t answered three obvious questions. Did it pull the apology because naming the token in an official post gave $Clippy extra visibility? Did legal, communications and security disagree about how to respond? Or did the attackers still have enough access to delete it, which would mean the account wasn’t fully secured when the apology went out? The last possibility worries me most.
BleepingComputer asked Microsoft about the attack vector, how long the unauthorized access lasted, and whether other corporate accounts were affected. A Microsoft spokesperson was not immediately available at the time of publication.
Microsoft’s earlier social media compromises
This is not the first time. In June 2024, attackers hijacked the @MicrosoftIndia account, which had over 211,000 followers. They impersonated Roaring Kitty, the online alias of Keith Gill, the retail trader behind the 2021 GameStop short squeeze, who had recently resurfaced in financial media.
The compromised handle sent followers to a fraudulent site, presaIe-roaringkitty[.]com, offering a supposed GameStop (GME) cryptocurrency presale. The domain used typosquatting: an uppercase “I” replaced the lowercase “l” in “presale,” which is easy to miss at a glance. The site ran wallet-drainer malware, malicious smart contracts that request broad transaction permissions from a connected wallet and then siphon everything in it.
That attack was more severe than the Clippy scheme. Instead of promoting a token, the attackers used the account’s credibility to push victims toward infrastructure hosting active malware. People who connected wallets lost assets directly rather than taking speculative losses.
The pattern extends beyond Microsoft. In January 2024, the SEC’s @SECGov account was compromised through a SIM swap, and a fake post announcing Bitcoin ETF approval moved Bitcoin’s price before it was retracted. Eric Council Jr., who carried out that breach, pleaded guilty in February 2025 and received a fourteen-month federal prison sentence. The case showed that a compromised institutional account can move markets, so social media security now touches financial stability as well as public relations.
Other incidents in the same category include compromised crypto exchange accounts, blockchain protocol developer handles and government agency accounts. The common thread is weak authentication at the platform level, with the victim organization’s own security infrastructure left untouched.
X’s security problems
Since the ownership change in late 2022, cybersecurity researchers and digital rights organizations have documented weaker security controls, thinner content moderation and slower incident response on X.
X replaced its legacy verification program, which required identity checks, a notability assessment and active review, with a subscription model (X Premium, formerly Twitter Blue). That removed the identity check that had partly guarded against impersonation. Organizational accounts keep a distinct badge, but paid badges are now everywhere, so users have a harder time telling a real institutional account from a good impersonator.
Independent analyses and former employees describe significant cuts to X’s trust and safety teams, and the ability to catch fraudulent accounts promoting crypto scams has shrunk with them. @clippymsftcto was able to set itself up, get a follow from the official Microsoft account and draw engagement before anyone intervened. That suggests gaps in automated detection that would once have flagged this behavior.
X’s API governs how third-party services interact with user accounts, and researchers have flagged OAuth permission scopes, token refresh mechanisms and session management as attack surfaces. If an organization gives a management platform broad API access, a breach of that platform exposes every account connected to it.
X has also become a primary channel for promoting crypto fraud, which blockchain security firms have documented extensively. ScamSniffer’s December 2023 analysis found that a single advertising campaign using the “MS Drainer” wallet drainer took about $59 million from 63,000 victims between March and November of that year. These operations employ dedicated developers for drainer contracts, social engineering scripts and account acquisition, so one account takeover is a single node in a larger criminal infrastructure.
Who might be behind it
Microsoft has not attributed the attack. The pump-and-dump structure, disposable impersonator accounts, rapid timeline and redundant promotional accounts fit financially motivated criminal groups better than state-sponsored actors or hacktivists. These groups tend to be loose networks of specialists: people who compromise or buy high-follower accounts, people who design the promotional material, blockchain developers who deploy tokens and liquidity pools, and people who manage the dump.
There is also an underground market for buying, selling and renting compromised social media accounts, run through Telegram channels, dark web marketplaces and private Discord servers. A verified organizational account with 13 million followers would command a premium price. The attackers either compromised Microsoft’s account directly or bought access from a broker who already held credentials, and Microsoft hasn’t said which.
Picking Clippy over a current property such as Copilot, Azure or Xbox suggests the attackers wanted viral memorability more than technical plausibility. Clippy is a loved-and-loathed relic of late-1990s computing that people recognize instantly, which raises the odds of organic sharing beyond the first 13 million followers. Whoever ran this understood internet culture well.
Legal exposure
The token’s promotional material explicitly referenced a pairing with $MSFT stock, which ties it to regulated securities. The SEC has jurisdiction over promotion that misleads people about the relationship between unregistered tokens and registered securities, and its 2024 and 2025 enforcement actions against crypto promoters set precedent for treating that kind of misrepresentation as securities fraud under Section 10(b) of the Securities Exchange Act and Rule 10b-5.
Microsoft’s deleted statement cited unauthorized use of the Clippy brand and Microsoft-related intellectual property. Clippy is retired from active product use but remains a registered trademark and copyrighted work owned by Microsoft. Using it commercially for a crypto token is trademark infringement under the Lanham Act and possibly copyright violation, which gives Microsoft civil litigation options separate from any criminal case.
Unauthorized access to the account, whatever the vector, violates 18 U.S.C. § 1030 (the Computer Fraud and Abuse Act) if U.S. jurisdiction applies. CFAA violations tied to financial fraud can carry substantial penalties, as Eric Council Jr.’s fourteen-month sentence for the SEC account compromise shows.
Pump-and-dump operations usually spread actors, infrastructure and money across several jurisdictions. Pseudonymous transactions, mixers and cross-chain bridges complicate attribution and asset recovery. Mutual Legal Assistance Treaties and Europol/Eurojust coordination become necessary, but they are slow, and the delay helps perpetrators who can cash out and launder within hours.
How organizations can protect their social media accounts
The recommendations below follow NIST SP 800-53, ISO/IEC 27001 and CISA guidance.
Require FIDO2/WebAuthn hardware security keys, such as YubiKey or Titan, for every account with admin or posting access to corporate social media handles. SMS codes and authenticator-app TOTP are better than passwords alone, but they fall to SIM swapping and malware interception respectively. A hardware key proves physical possession and can’t be phished, socially engineered or intercepted remotely.
Use role-based access and keep the number of people with full admin control small. Admin control covers changing profile details, managing connected apps and deleting posts. Separate scheduling and posting permissions from account configuration, log all access and audit it regularly.
Manage social accounts from dedicated, hardened workstations or virtual desktops rather than personal devices or general-purpose machines. Run EDR, enforce application allowlisting, block unauthorized software, and segment that traffic from the wider corporate network.
Have your security operations center watch for odd authentication events, logins from unexpected locations, unusual posting patterns and unauthorized app connections. Review X’s account activity logs regularly, assess the security of any third-party management platform, and audit OAuth permissions quarterly to revoke anything unneeded.
Write and rehearse an incident response plan for social media compromise. It should include escalation paths, pre-approved public statement templates, legal hold procedures and a direct line to the platform’s security team. Templates would have avoided the delay and confusion in Microsoft’s response. The aim is containment in minutes, not the thirty-plus minutes seen here.
Train everyone who manages social accounts on crypto fraud types, social engineering techniques and the signs of compromise. Include practical exercises that simulate phishing, credential-harvesting pages and phone calls aimed at authentication credentials.
Social media as critical infrastructure
Social platforms have become de facto critical infrastructure for corporate communications, financial markets and public discourse. Each large institutional account speaks to millions of customers and investors, so compromising one has consequences well beyond embarrassment.
Crypto fraud has industrialized, and an account takeover is an operating cost inside a larger criminal business model. Chainalysis estimated in its 2025 Crypto Crime Report that crypto fraud took over $12 billion from victims globally in the preceding year, with social media-driven schemes the fastest-growing category. AI is making scams easier through automated content generation, deepfake video and adaptive social engineering, which threatens to raise both the volume and sophistication of future attacks.
For platforms, this incident argues for investment in behavioral analytics, anomaly detection and fast moderation tuned to high-value institutional accounts. Compromising an account can take a single successful phishing email. Detecting and remediating it in real time takes far more, and current platform architectures haven’t closed that gap.
For the wider industry, companies spend billions securing their own infrastructure, networks and products, yet their public identity on third-party platforms depends on controls they don’t administer. Internal security spending can’t remove that risk, so companies should rethink how they spread public communications across owned and third-party channels.
What users should do about crypto scams on social media
Don’t connect a crypto wallet to a website promoted only through social media posts, whichever account posts it. Legitimate token launches and DeFi protocols are announced through several verified channels, documented in whitepapers and independently audited before they ask users to interact. A token that exists only as a promoted link, even from a verified account, is very likely fraudulent.
Check institutional announcements through independent channels. A real Microsoft announcement would appear on microsoft.com, in press releases, in established tech media and in regulatory filings where relevant. A crypto promotion that appears in none of those is fraudulent. Microsoft does not issue, endorse or promote cryptocurrency tokens, and no major NASDAQ-listed company keeps a liquidity pool pairing its stock with a meme token.
Turn on every available security feature on your own accounts, including MFA, login alerts and session management controls. Report suspicious accounts, posts and ads to the platform. Report fraudulent tokens to blockchain explorers, DeFi protocol teams and regulators such as the SEC, the CFTC or your national equivalent.
Where things stand
Microsoft says the account is secured and the investigation continues. The attack vector, the duration of unauthorized access and any law enforcement referrals are still unknown. The platform-level weakness behind the breach is also unresolved: one authentication failure can still expose a 13-million-person channel to criminal use.
This article will be updated as Microsoft discloses the attack vector, the duration of the unauthorized access and any law enforcement referrals. Readers with information about the $Clippy token or related accounts can report it to the relevant authorities and to platform trust and safety teams.









