Microsoft's official X account hijacked to promote fake $Clippy crypto token
Attackers took over Microsoft's @Microsoft account on X, which has more than 13 million followers, and used it to push a fake Clippy-branded cryptocurrency token.
At a glance
- Microsoft's official X account was hijacked on October 2 to promote a $Clippy token.
- The posts falsely claimed the token had a liquidity pool paired with $MSFT.
- Microsoft confirmed unauthorized access, removed the posts and said it would pursue legal action.
- How the account was compromised has not been disclosed.
Attackers hijacked Microsoft's official account on X on October 2, 2026, and used it to promote a fake cryptocurrency token in what appears to be a pump-and-dump scheme, BleepingComputer reports. The @Microsoft account has more than 13 million followers, giving the scammers a large audience for a token designed to trade on the company's name and on its retired Clippy assistant. Microsoft has confirmed the unauthorized access and says it does not endorse the token.
What happened
According to BleepingComputer, the compromised account followed and reposted content from an account named @clippymsftcto, which impersonated Microsoft's Clippy virtual assistant. The posts promoted a token called $Clippy and falsely claimed it had "a liquidity pool paired directly with $MSFT," suggesting a link to Microsoft's stock that does not exist.
Microsoft regained control of the account and removed the unauthorized posts. "We have confirmed unauthorized access to our account on X including posts that did not come from Microsoft," a company spokesperson told BleepingComputer. The company added that it "does not endorse or have any affiliation with this token, its creators, or any related cryptocurrency project" and said it would pursue legal action.
What is still unknown
Microsoft has not said how the attackers gained access to the account, and BleepingComputer's report does not include figures on how much money, if any, followers lost by buying the token. It is also unclear how long the posts remained visible before they were removed.
The incident follows a similar case in June 2024, when Microsoft India's X account was hijacked to promote a cryptocurrency wallet drainer, according to BleepingComputer.
Why it matters
Hijacked brand accounts are a common launchpad for cryptocurrency scams because a verified, high-profile account lends instant credibility. Pump-and-dump operators typically use such posts to drive a short burst of buying into a newly created token, then sell their own holdings and leave late buyers with losses.
What to do
Users should treat cryptocurrency promotions posted by corporate accounts with suspicion, especially when they reference a company's stock ticker or a nostalgic brand mascot, and should not connect wallets to sites linked from such posts. Organizations that manage social media accounts should enforce strong, phishing-resistant multi-factor authentication, limit the number of people and third-party tools with posting access, and monitor for unexpected follows, reposts or login activity so that a takeover can be contained quickly.
Sources
- Microsoft's X account hacked in crypto pump-and-dump scheme — BleepingComputer
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



