Security News Microsoft’s X account hacked in crypto pump-and-dump scheme

Security News
1 Reply 129 Views

Brownie2019

Level 23
Verified
Well-known
Forum Veteran
On Thursday, unknown attackers hijacked the official Microsoft account on X, which has over 13 million followers, in what appeared to be a pump-and-dump scheme promoting a crypto token.

The attack began when the Microsoft account (@Microsoft) followed and reposted a tweet from another now-suspended X account (@clippymsftcto) impersonating Microsoft's Clippy virtual assistant, The Verge first reported.

While @clippymsftcto has been suspended, another X account (@ClippyMSFT) that reposted Microsoft's tweet is still promoting a $Clippy crypto token, claiming that it has "has a liquidity pool paired directly with $MSFT."

Microsoft has since removed the attackers' posts and confirmed the incident, saying it's investigating the circumstances.

"We have confirmed unauthorized access to our account on X including posts that did not come from Microsoft," a Microsoft spokesperson told The Verge. "The account has been secured and the unauthorized posts have been removed, and we are continuing to investigate the circumstances."

In a now-deleted tweet, the company also apologized for the posts and said that it doesn't support any cryptocurrency or crypto-related token and will take legal action.

"We are aware of a cryptocurrency token being promoted in connection with $MSFT stock, including the unauthorized use of the Clippy brand and Microsoft-related intellectual property. Microsoft has not authorized, sponsored, endorsed, or granted permission for the creation, promotion, or use of any cryptocurrency token associated with Clippy, Microsoft, or $MSFT," Microsoft said.
Full Story:
 
Last edited by a moderator:
Full Story: (link omitted)


Hi Brownie, the important distinction here is that Microsoft has confirmed unauthorized access to its X account, not a compromise of Microsoft’s products, customer accounts, or corporate network. The access method remains undisclosed, so claims about a stolen password, session cookie, compromised delegated app, or an X-side failure would presently be speculation.

This attack exploited borrowed credibility: an apparent endorsement from an account with more than 13 million followers can create enough urgency and demand for scammers to sell into. The claim about a liquidity pool “paired directly with $MSFT” is particularly misleading—MSFT is a stock ticker, not a cryptocurrency, and Microsoft explicitly says it has no connection with the token. Microsoft has now secured the account and removed the posts, according to BleepingComputer.

For anyone who encountered the posts:

  • Merely viewing or reposting one does not infect a device.
  • Do not buy the token or trust its contract address because it appeared on an official account.
  • If a wallet was connected, review and revoke unwanted token approvals. Disconnecting the website alone does not revoke on-chain permissions.
  • If a seed phrase or private key was disclosed, consider that wallet compromised and transfer remaining assets to a newly created wallet.
  • If anything was downloaded or executed, seek individualized checking through MalwareTips’ Malware Removal Assistance team.

The earlier Microsoft India incident involved a wallet drainer, but that was a separate event; it does not establish that this Clippy campaign also deployed malware. At present, the confirmed facts are the social-media hijack and unauthorized token promotion—losses and the intrusion route have not yet been established publicly.

Sources
 

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top