Microsoft X Account Hijacked in Crypto Pump-and-Dump Scheme
Share
Microsoft’s official account on X (formerly Twitter), which boasts over 13 million followers, was compromised on Thursday by unknown attackers who used it to promote a cryptocurrency token in what appeared to be a pump-and-dump scheme.
The incident began when the compromised @Microsoft account followed and reposted content from another X account, @clippymsftcto, which impersonated Microsoft’s classic Clippy virtual assistant. While this initial impersonating account has since been suspended, another account, @ClippyMSFT, continued to promote a ‘$Clippy’ crypto token, making claims about its liquidity pool.
Microsoft Confirms Unauthorised Access and Investigation
Microsoft has confirmed the unauthorised access to its X account. The company swiftly removed the attackers’ posts and secured the account, initiating an investigation into the circumstances surrounding the compromise.
In a now-deleted public statement, Microsoft apologised for the posts, emphatically stating that it does not endorse any cryptocurrency or crypto-related token. The company also announced its intention to pursue legal action against those promoting the unauthorised token.
“We are aware of a cryptocurrency token being promoted in connection with $MSFT stock, including the unauthorised use of the Clippy brand and Microsoft-related intellectual property,” Microsoft stated. “Microsoft has not authorised, sponsored, endorsed, or granted permission for the creation, promotion, or use of any cryptocurrency token associated with Clippy, Microsoft, or $MSFT. We are taking this matter seriously and will pursue appropriate legal action to have the unauthorised token and related materials removed.”
Pattern of Social Media Account Hijacks
This is not the first time a Microsoft-affiliated X account has fallen victim to crypto scammers. In June 2024, the Microsoft India X account (@MicrosoftIndia), with over 211,000 followers, was hijacked. Attackers then impersonated meme stock trader Keith Gill, known as ‘Roaring Kitty,’ to spread cryptocurrency wallet drainer malware.
The broader landscape of X has seen a significant increase in account hijacks and malicious advertisements targeting users with cryptocurrency scams. Threat analysts at ScamSniffer reported that cybercriminals stole approximately $59 million in cryptocurrency from 63,000 individuals between March and November 2023 through a single Twitter ad campaign using the ‘MS Drainer’ wallet drainer.
Other high-profile X accounts have also been compromised. In January 2024, the U.S. Securities and Exchange Commission’s (@SECGov) account was compromised via a SIM-swapping attack. Attackers posted a fake announcement about the approval of Bitcoin exchange-traded funds (ETFs), causing a temporary but significant spike in Bitcoin prices. The individual responsible for that compromise, Eric Council Jr., later pleaded guilty and received a prison sentence for his role in the scheme.
Microsoft’s ongoing investigation aims to determine the full extent of the compromise and prevent future recurrences.




Leave a Reply