threat_intelligence375 wordsRead on Huntaegis

Crypto Scammers Hijack Microsoft’s Official X Account

Microsoft has confirmed that its official X account was taken over on Thursday and used to amplify a Clippy-themed cryptocurrency account. According to The Verge, the company’s account, which has more than 13 million followers, started following the crypto account and shared one of its messages. Microsoft’s profile picture was also replaced with an image of Clippy, the animated paperclip assistant that shipped with older versions of Office. The account behind the reposted message, @clippymsftcto, posed as Clippy and has since been suspended. A second account involved in the incident kept pushing a $Clippy token, saying its liquidity pool was paired with $MSFT. The posts were eventually taken down. According to The Verge, an apology appeared on the Microsoft account roughly 30 minutes later and was deleted soon after, with no explanation given. The now-deleted post said Microsoft was aware of a token being marketed in connection with its stock that used the Clippy brand without permission. “To be clear, Microsoft does not support, endorse, sponsor, or authorize any cryptocurrency or crypto-related token,” it read. A Microsoft spokesperson told The Verge, “We have confirmed unauthorized access to our account on X, including posts that did not come from Microsoft,” adding, “The account has been secured and the unauthorized posts have been removed, and we are continuing to investigate the circumstances.” Microsoft has not said how the attackers gained access to its account, and hackers have several options beyond tricking a social media manager into entering their credentials on a phishing page. They can take over the phone number tied to the account through SIM swapping, as it happened with the SEC’s X account in 2024, or hijack the email address used for password resets. Infostealer malware on an employee’s device can also steal browser session cookies from an active login, letting attackers access the account without a password or an MFA prompt. Another route is a compromised third-party marketing or social media management tool that has been authorized to post on the company’s behalf. Related: Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack Related: North Korea Suspected in $351 Million Bitget Crypto Heist Related: Party’s Over for Crypto Scammers Who Went on a Spending Spree After a $240 Million Bitcoin Theft

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.