Microsoft X account hacked to promote fake crypto token
On October 1, hackers breached Microsoft’s official X (formerly Twitter) account, which boasts over 13 million followers. The intruders replaced the account’s profile picture with an image of Clippy, the iconic Office assistant, and began promoting an unauthorized cryptocurrency token. Microsoft quickly confirmed the unauthorized access, secured the account, and removed the fraudulent content. The company is still investigating how the attackers gained control of the profile.
Microsoft emphasized that it had not authorized any token associated with Clippy, the Microsoft brand, or the stock symbol $MSFT. The incident highlights the scam’s clever mechanism, which leveraged Microsoft’s recognizable brand, verified profile, and nostalgic Clippy theme to briefly appear as an official campaign.
This attack is part of a growing trend of social media account takeovers. In June 2024, Microsoft India’s account was compromised to promote a fake cryptocurrency offer, and earlier in the year, the US SEC’s account was hacked to spread false information about Bitcoin ETF approvals, causing temporary market fluctuations. The breach of Microsoft’s profile underscores the value of social media reputations as assets that cybercriminals can exploit for quick financial gain.