www.securityweek.com 2 Oct 2026, 11:46 UTC

Microsoft’s 13 Million Follower X Account Hijacked in Crypto Scam

Microsoft’s 13 Million Follower X Account Hijacked in Crypto Scam
CyberSIXT Evidence Panel Source marked as original reporting

MICROSOFT confirmed that its official X account was hijacked on Thursday and used to amplify a Clippy-themed cryptocurrency account. The compromised profile—having more than 13 million followers—began following the crypto account and shared one of its messages, with the profile picture replaced by Clippy, the Office assistant. The impersonating account behind the repost, @clippymsftcto, was suspended, while a second involved account pushed a token branded as Clippy and claimed liquidity in a pool paired with MSFT.

The posts were eventually removed, and a short apology appeared on Microsoft’s account before being deleted, without explanation.

SecurityWeek notes that Microsoft has not disclosed how access was gained. The piece outlines several possible routes attackers could have used beyond social engineering: SIM swapping to seize the phone number used for account recovery; taking control of the email address used for password resets; stealing browser session cookies via infostealer malware to bypass passwords and MFA; or compromising a third‑party marketing or social media tool authorised to post on the company’s behalf.

Microsoft stated that unauthorized posts were removed and that the account had been secured, with the investigation ongoing. The incident highlights the range of potential access points for high‑profile social accounts and the need for robust controls around account recovery, third‑party tools, and post verification.

View full article

Article by CyberSIXT