Attackers briefly took over Microsoft’s official Twitter/X account and rebranded it with a Clippy avatar to push a Clippy-themed cryptocurrency scam. Posts suggested the token was tied to Microsoft’s stock price, potentially tricking followers into thinking it was legitimate. A fake “corporate” apology was also posted and then deleted, adding confusion.
How the attack worked
Attackers gained control of Microsoft's official Twitter/X account, a verified channel followed by 13 million people, and used it to promote a cryptocurrency scam. The account's avatar was swapped to the Clippy mascot, and the compromised account was made to follow and share posts from a Clippy-themed crypto account. A related account then promoted a token called Clippy Coin, falsely implying its liquidity was paired with Microsoft's stock price, a claim designed to make the token feel connected to a real, trusted company.
The exact method used to take over the account was not confirmed. Possibilities discussed included phishing, SIM swapping, abuse of password reset processes, or theft of session cookies. This uncertainty is itself a useful reminder: account takeovers can happen through several different paths, and defenders should not assume a single attack vector when responding.
Why it succeeded
The scam leaned heavily on borrowed trust. A verified, high-follower corporate account posting about a token gives that token instant credibility it would never earn on its own. Tying the coin's claimed liquidity to Microsoft's stock price added a veneer of legitimacy that could mislead casual observers into thinking there was a real corporate connection, even though there wasn't. A fake title reference, framing a Clippy persona as if it were Microsoft's CTO, added another layer of false authority.
The situation was made more confusing by a formal-sounding apology and disclaimer that was posted from the hacked account and then deleted. Microsoft later confirmed that apology wasn't from them either, showing that even damage-control messages from a compromised channel cannot be trusted at face value.
What to watch for
- A sudden, unexplained change to a corporate account's avatar, branding, or posting behavior.
- Crypto or financial announcements that claim a token is tied to a company's stock price or performance.
- Posts referencing executive titles or leadership in ways that don't match known company structure.
- Apology or disclaimer messages that appear and then get deleted, with no confirmation through other official channels.
Building resistance
Organizations and individuals who follow major brands should treat unexpected social media "announcements," especially those involving cryptocurrency, as potentially the product of a hijacked account until verified elsewhere. Verification should happen through a second official channel, such as a company's main website or press statement, rather than by trusting the social account itself. Social media managers, marketing and communications teams, and executives are especially relevant audiences here, since they are often the ones best positioned to confirm or deny suspicious posts quickly. Building a habit of pausing before sharing or acting on a brand's social post, particularly one involving money or investment, can reduce the spread of this kind of scam.
Key findings
- Attackers hijacked Microsoft’s official Twitter/X account (13 million followers) and changed the profile image to Clippy.
- The compromised account followed a Clippy-themed crypto account and shared one of its posts.
- A related account promoted a “Clippy Coin” and falsely implied legitimacy by claiming its liquidity was paired with Microsoft’s stock price.
- A formal-looking apology/disclaimer was posted from the hacked account and later deleted; Microsoft confirmed the apology was not theirs either.
- The podcast notes the compromise method was unknown (speculated possibilities included phishing, SIM swap, password reset abuse, or stolen session cookies).
Who’s being targeted
- Commonly targeted roles: Marketing/Communications, Social media managers, Executives/Leadership, All staff (general scam awareness).
- Affected industries: Technology, Social media / online platforms (as the channel of abuse).
- Attack channels: website.
- Impersonated: Microsoft (via its official Twitter/X account).
Red flags to watch for
- Sudden brand/avatar change on a corporate account (Microsoft avatar changed to Clippy).
- Claims implying a crypto token is tied to a company’s stock price.
- Unexplained deletion of posts/apologies and inconsistent messaging from the ‘official’ account.
Frequently asked questions
What happened to Microsoft's Twitter/X account?
Attackers hijacked Microsoft's official Twitter/X account, which had 13 million followers, and changed its profile image to Clippy to promote a crypto token.
How did the scam try to appear legitimate?
A related account promoted a 'Clippy Coin' and falsely claimed its liquidity was paired with Microsoft's stock price, which may have made followers think it was connected to Microsoft's actual stock.
Was the apology posted on the account genuine?
No. A formal-looking apology and disclaimer was posted from the hacked account and later deleted, and Microsoft confirmed that the apology was not from them either.
How was the account actually compromised?
The exact compromise method was not confirmed; speculated possibilities included phishing, SIM swap, password reset abuse, or stolen session cookies.
Read the video transcript
Someone pretending to be Clippy took over Microsoft’s official X account and started shilling a fake “Clippy Coin.” They swapped the picture for Clippy, followed a Clippy-themed crypto account, and boosted posts claiming “Clippy Coin” was paired with Microsoft’s stock price, making it look official when it wasn’t. Then a very corporate-sounding apology appeared on the same account and was deleted later. That apology was fake too. Once an account’s hijacked, every post on it is suspect. If you see a sudden crypto “announcement” from any brand, pause. Don’t click, don’t share, go to the company’s main website or another official channel and verify it there first.