Microsoft ’s official X account , with more than 13 million followers , has been the focus of a new cyberattack, as unknown individuals managed to gain unauthorized access and use it to promote a crypto scam. The action appears to have followed the well-known “pump-and-dump” tactic , in which perpetrators attempt to create artificial interest around a digital asset in order to increase its value and then liquidate their positions.

In the spotlight is $Clippy
The attack appears to have started with a particularly convincing form of impersonation. The @Microsoft followed and reposted a post from the @clippymsftcto, which appeared to be related to Clippy, the iconic virtual assistant that has historically been associated with Microsoft products.
The account in question has now been suspended, but the activity surrounding the token has not stopped. Another X account, @ClippyMSFT, which had reposted the post in question, continued to promote the cryptocurrency $Clippy.
In fact, the account administrators claimed that the token has a "pool of liquidity directly tied to the $MSFT stock," attempting to create the impression that there is some official or financial relationship with Microsoft.
The company, however, clarified that it has no connection with the cryptocurrency in question.
See also: Pokémon X account hacked – Promoting fake crypto
Microsoft confirmed the breach
Microsoft removed the unauthorized posts and confirmed that its account was compromised. A spokesperson said the company has re-secured the account and is investigating how the unauthorized access was gained.
At the same time, the company stated that it has not approved, supported, sponsored or licensed any cryptocurrency associated with Clippy, Microsoft or $MSFT.
This clarification is particularly important, as fraudsters can exploit the credibility of a major brand to create an appearance of legitimacy. An account with millions of followers is, in effect, a ready-made distribution channel for a misleading investment proposition.
Microsoft also said it is considering legal action to remove the unauthorized token and related hardware.

This is not the first attack on a Microsoft account
The incident is not an isolated example. In June 2024 , Microsoft India 's X account , which at the time had more than 211,000 followers, was also hacked.
In that case, the perpetrators tried to impersonate "Roaring Kitty", the online pseudonym of investor Keith Gill, who became widely known for the so-called meme stocks case.
The attackers didn't stop at posting misleading content. They used the compromised account to direct users to a malicious website that appeared to be a pre-sale platform for a cryptocurrency supposedly tied to GameStop stock.
See also: Contagious Interview: 30,000 devices breached & crypto stolen
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
In reality, those who connected their digital wallets and approved the requested transactions risked giving the perpetrators access to their digital assets. This is the classic operation of a wallet drainer, a tool designed to steal funds from crypto wallets.
Compromised accounts are a powerful weapon
The problem isn't limited to Microsoft. X has faced repeated incidents where compromised or fake accounts are being used to promote cryptocurrency, investment scams , and malicious websites.
The value of such an account to a cybercriminal is not only in the number of followers. The credibility of the brand can act as a social engineering mechanism. A user is more likely to trust a post when it appears from an account they know and consider official.
A notable example is a campaign analyzed by ScamSniffer that, according to its findings, was linked to the theft of approximately $59 million worth of cryptocurrency from 63,000 people via malicious Twitter ads. The attacks leveraged the wallet drainer tool MS Drainer.
The SEC case showed how dangerous misinformation is
Even more notable was the breach of the official SEC on X via a SIM-swapping attack. The account published a false announcement regarding the approval of Bitcoin ETFs, causing a temporary and significant change in the price of Bitcoin.
The case demonstrated that a compromised official account is not just a communication or reputation problem. It can be used to manipulate markets, lure victims, and spread misleading financial information.

Eric Council Jr., who was charged with seizing the SEC account, pleaded guilty in February 2025 and was sentenced to 14 months in prison for his involvement in the case.
See also: CISA KEV: 7 new vulnerabilities with reverse shells and crypto miners
What users should watch out for
The new incident with Microsoft is a reminder that even a post from an official and verified account is not in itself proof that an investment proposal is genuine.
Users should be particularly wary of posts that promise quick profits, present new tokens as official products of large companies, or request the connection of a crypto wallet and approval of transactions.
A particularly dangerous combination is the invocation of a well-known brand, creating a sense of urgency, and referring to an external link. In the case of Microsoft, the perpetrators attempted to exploit precisely this relationship of trust, turning an official account into a tool for promoting an unauthorized cryptocurrency.
The incident shows once again that attacks on social media accounts can go far beyond simply taking over a profile. When the target is a large company account, the breach can quickly turn into a mechanism for deception, financial exploitation , and manipulation of user trust.
source: www.bleepingcomputer.com
