Microsoft’s official X account was hijacked by unknown attackers and temporarily used to promote a cryptocurrency based on Clippy, the company’s famous paperclip assistant.

 

 

The compromised @Microsoft account has more than 13 million followers. During the takeover, it began following an account posing as Clippy and reposted its content. Microsoft’s profile picture was also temporarily replaced with an image of the old Office assistant.

The activity was connected to the promotion of a cryptocurrency called $Clippy. One of the accounts behind the campaign claimed that the token had a liquidity pool paired directly with Microsoft’s $MSFT stock ticker, potentially giving users the false impression that the cryptocurrency had an official connection to the company.

Microsoft has no affiliation with the token and has not authorized or endorsed any cryptocurrency connected to Clippy or its brand.

The situation became more confusing after the initial posts disappeared. Around 30 minutes later, an apparent apology appeared on Microsoft’s account stating that the company did not support the cryptocurrency and warning about unauthorized use of its intellectual property.

That post was also deleted. Microsoft later confirmed that it had not published the apology either, meaning the attackers apparently remained able to post from the account after the original promotion was removed.

Microsoft subsequently regained control of the account and deleted the unauthorized content. The company said it had confirmed unauthorized access and was continuing to investigate how the incident occurred.

The X account that Microsoft initially followed during the compromise has since been suspended. However, another account associated with the $Clippy promotion continued advertising the token after Microsoft’s account had been secured.

There is currently no confirmed evidence showing how much cryptocurrency, if any, users lost because of the campaign. Microsoft has also not revealed whether the attackers obtained its X credentials through phishing, stolen session information, or another method.

The incident shows why posts from verified corporate social media accounts should not automatically be trusted when they suddenly promote cryptocurrency. Attackers who compromise a well-known account can immediately borrow the company’s reputation and reach millions of potential victims before the legitimate owner regains control.

Leave a Reply