Microsoft X Account Hijacked to Promote Fake Clippy Crypto Token
Microsoft's official X account was briefly hijacked by hackers on October 1, who used the platform to promote a fake cryptocurrency token called $Clippy. The token was tied to Clippy, the retired animated paperclip assistant, and promised to bring back the assistant if a post reached 500,000 likes. The attackers also claimed the token was paired with Microsoft stock, using the label 'MSTF' to suggest a corporate connection.
The takeover lasted roughly 30 minutes before the account was secured and the unauthorized content removed. Microsoft confirmed the breach in a statement, saying the account has since been secured and the unauthorized posts removed. The company also denied any connection to the token and threatened legal action against those responsible.
The incident echoes a previous breach of Microsoft's India X account in June 2024, where attackers advertised a GameStop cryptocurrency presale tied to Keith Gill, the investor known online as Roaring Kitty. Both attacks exploited Microsoft's identity to lend credibility to fraudulent crypto promotions.
The use of a fake apology to extend the confusion suggests attackers are becoming more sophisticated in their social engineering tactics. The incident highlights the ongoing challenge for investors and social media users in distinguishing legitimate corporate communications from fraudulent ones, particularly when both appear on the same compromised account within a short window.