Microsoft’s X account hacked in crypto pump-and-dump scheme
The official Microsoft account on X (formerly Twitter) was hijacked by unknown attackers who used it to promote a fraudulent cryptocurrency token in a pump-and-dump scheme. The attackers impersonated Microsoft's Clippy virtual assistant and posted unauthorized tweets promoting the $Clippy token, falsely claiming a liquidity pool linked to Microsoft stock. Microsoft confirmed the unauthorized access, removed the malicious posts, secured the account, and is investigating the incident. The company disavowed any association with the token and plans legal action against those responsible. This incident follows previous similar hijacks of Microsoft-related accounts used for crypto scams and wallet draining malware campaigns on X.
AI Analysis
Technical Summary
Unknown attackers gained unauthorized access to Microsoft's official X account, which has over 13 million followers, and used it to promote a fraudulent cryptocurrency token named $Clippy. The attack involved reposting tweets from impersonator accounts and falsely linking the token to Microsoft stock. Microsoft confirmed the breach, removed the unauthorized content, secured the account, and is investigating. The company clarified it does not endorse or have any affiliation with the token or related projects and intends to pursue legal remedies. This event is part of a broader trend of hijacked verified accounts on X being exploited for crypto scams and wallet draining malware distribution.
Potential Impact
The compromise of a high-profile verified account with millions of followers enabled attackers to promote a fraudulent cryptocurrency token, potentially misleading a large audience and facilitating a pump-and-dump scheme. This could result in financial losses for individuals who invested based on the unauthorized posts. The incident also damages Microsoft's brand reputation and trust on social media platforms. No direct technical vulnerability or malware infection from this specific incident is detailed, but it continues a pattern of social media account hijacks used for financial scams.
Mitigation Recommendations
Microsoft has secured the compromised account and removed the unauthorized posts. The company is investigating the breach and pursuing legal action against the perpetrators. Users should be cautious of any cryptocurrency promotions linked to Microsoft or the $Clippy token, as Microsoft does not endorse such tokens. No further immediate action is required from users regarding this incident. Organizations should continue to enforce strong account security measures such as multi-factor authentication and monitor for suspicious activity on official social media accounts.
Microsoft’s X account hacked in crypto pump-and-dump scheme
Description
The official Microsoft account on X (formerly Twitter) was hijacked by unknown attackers who used it to promote a fraudulent cryptocurrency token in a pump-and-dump scheme. The attackers impersonated Microsoft's Clippy virtual assistant and posted unauthorized tweets promoting the $Clippy token, falsely claiming a liquidity pool linked to Microsoft stock. Microsoft confirmed the unauthorized access, removed the malicious posts, secured the account, and is investigating the incident. The company disavowed any association with the token and plans legal action against those responsible. This incident follows previous similar hijacks of Microsoft-related accounts used for crypto scams and wallet draining malware campaigns on X.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Unknown attackers gained unauthorized access to Microsoft's official X account, which has over 13 million followers, and used it to promote a fraudulent cryptocurrency token named $Clippy. The attack involved reposting tweets from impersonator accounts and falsely linking the token to Microsoft stock. Microsoft confirmed the breach, removed the unauthorized content, secured the account, and is investigating. The company clarified it does not endorse or have any affiliation with the token or related projects and intends to pursue legal remedies. This event is part of a broader trend of hijacked verified accounts on X being exploited for crypto scams and wallet draining malware distribution.
Potential Impact
The compromise of a high-profile verified account with millions of followers enabled attackers to promote a fraudulent cryptocurrency token, potentially misleading a large audience and facilitating a pump-and-dump scheme. This could result in financial losses for individuals who invested based on the unauthorized posts. The incident also damages Microsoft's brand reputation and trust on social media platforms. No direct technical vulnerability or malware infection from this specific incident is detailed, but it continues a pattern of social media account hijacks used for financial scams.
Defensive Guidance
Microsoft has secured the compromised account and removed the unauthorized posts. The company is investigating the breach and pursuing legal action against the perpetrators. Users should be cautious of any cryptocurrency promotions linked to Microsoft or the $Clippy token, as Microsoft does not endorse such tokens. No further immediate action is required from users regarding this incident. Organizations should continue to enforce strong account security measures such as multi-factor authentication and monitor for suspicious activity on official social media accounts.
Technical Details
- Classification
- {"confidence":0.7,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/microsofts-x-account-hacked-in-crypto-token-pump-and-dump-scheme/","fetched":true,"fetchedAt":"2026-10-02T09:46:19.241Z","wordCount":911}
Threat ID: 6abf7d6ba43b0b3b899e5bad
Added to database: 10/02/2026, 09:46:19 UTC
Last enriched: 10/02/2026, 09:46:25 UTC
Last updated: 10/03/2026, 02:54:00 UTC
Views: 22
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.