Skip to main content
Emerging Threats

Microsoft X Account Hijacked in Crypto Pump-and-Dump Scam

Brightly-lit office workstation with laptop showing social media interface.

"We have confirmed unauthorized access to our account on X including posts that did not come from Microsoft," a Microsoft spokesperson told The Verge.

What happened to the @Microsoft account

On Thursday unknown attackers hijacked Microsoft's official X account (@Microsoft), which has over 13 million followers, and used it to promote a cryptocurrency token in what the company called an unauthorized campaign. Microsoft said the account was secured and that the unauthorized posts were removed; the company added it is investigating the circumstances. A Microsoft spokesperson also issued a now-deleted apology and emphasized that Microsoft "does not support any cryptocurrency or crypto-related token and will take legal action."

Clippy impersonation and the $Clippy token

The incident began when the @Microsoft account followed and reposted a tweet from a now-suspended impersonator account, @clippymsftcto, which posed as Microsoft's Clippy virtual assistant—The Verge first reported the chain of events. Another account, @ClippyMSFT, which reposted Microsoft's tweet, continued to promote a token called $Clippy and claimed the token "has a liquidity pool paired directly with $MSFT." Microsoft told reporters it had not authorized, sponsored, endorsed, or granted permission for the creation, promotion, or use of any cryptocurrency token associated with Clippy, Microsoft, or $MSFT, and said it would pursue "appropriate legal action" to have unauthorized tokens and related materials removed.

Technique: account hijack, reposts and social engineering

The attackers leveraged the high visibility of a verified corporate account by following and amplifying an impersonator, then using reposts to reach Microsoft’s large follower base. The campaign’s public-facing elements echoed previous scams: impersonation of familiar brands or personalities, promotion of a crypto presale or liquidity claim, and redirection of followers toward token purchases. Microsoft removed the posts and secured the account, but the reposting chain left at least one account (@ClippyMSFT) still promoting the $Clippy token at the time the reporting was published.

Prior incidents cited: Microsoft India breach, SEC account hijack, and MS Drainer

The report places this hijack in a broader pattern of similar abuses on X. In June 2024, attackers compromised the Microsoft India account (@MicrosoftIndia) to impersonate the Roaring Kitty persona (Keith Gill), using replies and posts to lure followers to a malicious site, presale-roaringkitty[.]com. That operation pushed a supposed GameStop (GME) crypto presale; victims who connected cryptocurrency wallets to the site had assets stolen by a wallet-draining service. The broader campaign-class used by these actors has been linked to a wallet drainer family dubbed "MS Drainer." Blockchain threat analysts at ScamSniffer reported in December 2023 that cybercriminals stole roughly $59 million in cryptocurrency from about 63,000 people in a single Twitter ad push between March and November using MS Drainer-style techniques.

What this means for technologists, regulators, and end users

  • Technologists and security teams: The incident underscores the risk that even high-follower corporate accounts can be used as vectors for financial scams through impersonation and repost chains. Teams should note the specific tactic of following and amplifying impersonator accounts and prioritize securing account credentials and session controls.
  • Policymakers and regulators: The report recalls an earlier high-profile account compromise—the @SECGov hijack—that produced a false announcement about Bitcoin ETF approvals and temporarily moved markets; the hacker, Eric Council Jr., later pleaded guilty in February 2025 and was sentenced to 14 months in prison for his role in that conspiracy. Regulators may see value in tracking platform-based financial manipulation as part of market integrity work.
  • End users and the public: The past and present incidents carry a consistent warning: do not connect cryptocurrency wallets to presale sites or follow transactional prompts from posts or replies without independent verification. The Microsoft India example showed how a seemingly legitimate corporate post can be used to redirect users to presale sites where wallets are drained after users authorize transactions.

Microsoft has said it will pursue legal remedies while it investigates how its official X account was used to amplify a crypto pump-and-dump scheme. The company secured the account and removed the unauthorized posts, but the persistence of imitator accounts promoting $Clippy and the echo of earlier wallet-drainer campaigns underline a recurring risk: verified visibility on social platforms can be weaponized to reach large audiences quickly—and the financial consequences for users can be immediate. The public record now shows a mix of technical breach, brand impersonation, and active token promotion; whether platform controls, legal action, or operational security will blunt this pattern remains to be seen.

Original report — BleepingComputer