Microsoft’s X Account Hijacked to Promote Clippy-Themed Crypto Account
Microsoft confirmed unauthorized access to the @Microsoft account on X. The attackers used it to share content from an account posing as Clippy.

Microsoft’s X account was targeted in an unauthorized access incident that attackers used to promote a crypto account themed around the former Clippy assistant. Microsoft confirmed the compromise of its official @Microsoft profile, secured the account, and removed the unauthorized content.
During the incident, the account, with approximately 13 million followers, began following and shared a post from the @clippymsftcto profile. The profile posed as Clippy and linked its communications to a crypto token. The profile picture of Microsoft’s official account was also changed to a Clippy theme.
Microsoft’s X Account Restored After the Incident
Microsoft spokesperson Brent Colburn confirmed that the company had recorded unauthorized access to the account. According to his statement, the company secured the profile, removed unauthorized posts, and is continuing to investigate the circumstances of the incident.
Microsoft also denied any connection to crypto tokens using the Clippy or Microsoft names or the $MSFT ticker. The company did not authorize or endorse the promotion in question.
The @clippymsftcto account, whose content was shared from Microsoft’s profile during the compromise, was subsequently suspended on X.
Crypto Promotion Used the Brand’s Credibility
The takeover of a verified corporate profile could have temporarily given the unauthorized financial promotion visibility and an appearance of legitimacy. However, the fact that the content appeared through Microsoft’s official account does not mean that the company created, approved, or partnered with the token.
Some reports describe the operation as a “pump-and-dump” scheme. That assessment is based on the apparent promotion of the token through a compromised account, not on documented data about trading, the attackers’ profits, or investor losses.
The claim by the promoting account that the liquidity of the $Clippy token was supposedly paired directly with Microsoft stock traded under the $MSFT ticker has also not been independently confirmed.
Cause of the Compromise Still Unknown
Microsoft has not disclosed how the attackers gained access to the @Microsoft profile or who was behind the incident. No intrusion into Microsoft products, its cloud services, or customer systems has been confirmed.
Further developments will show whether Microsoft publishes a technical explanation of the compromise vector and additional measures. It also remains unclear whether X will provide details about action taken against related accounts and content, or whether Microsoft will pursue the announced legal action against the token’s creators or promoters.
Sources
- Microsoft – statement by spokesperson Brent Colburn cited in The Verge – Confirms that Microsoft recorded unauthorized access, secured the account, removed unauthorized posts, and is investigating the circumstances.
- SecurityWeek – Corroborates the profile change, sharing of content from the Clippy-themed account, suspension of one of the accounts, and denial of Microsoft’s connection to the token.
- BleepingComputer – Corroborates Microsoft’s confirmation, removal of the posts, and the reported claims by related accounts about the $Clippy token.
Verified and updated: 10/02/2026 15:22



