Microsoft X Account Hacked in $Clippy Crypto Scam
Microsoft’s official X account was hijacked by attackers who used the account to promote a cryptocurrency token tied to the company’s famous Clippy assistant.
The @Microsoft account, which has more than 13 million followers, was compromised and used to amplify posts promoting a $Clippy cryptocurrency token, according to The Verge.
Microsoft confirmed that someone gained unauthorized access to the account. The company has since secured it, removed the malicious posts, and started investigating how the attackers gained access.
Attackers used Clippy to promote a crypto token
During the compromise, Microsoft’s account followed and reposted content from another X account impersonating Clippy, the animated Office assistant that Microsoft introduced decades ago.
The account promoted a cryptocurrency called $Clippy and claimed that the token had a liquidity pool connected to $MSFT, Microsoft’s stock ticker.
The posts could have appeared particularly convincing because they received exposure through Microsoft’s verified corporate account and its millions of followers.
Microsoft quickly distanced itself from the cryptocurrency project after regaining control of the account.
Microsoft threatens legal action
Microsoft said it had not authorized, sponsored, endorsed, or granted permission for anyone to create or promote a cryptocurrency associated with Clippy, Microsoft, or the $MSFT name.
The company also stressed that it has no affiliation with the $Clippy token, its creators, or any related cryptocurrency project.
Microsoft plans to pursue legal action against those responsible for using its brands and intellectual property to promote the token.
The company has not disclosed how the attackers managed to compromise the X account, and its investigation into the incident remains ongoing.
The attack is another reminder of how compromised high-profile social media accounts can give scams immediate credibility and expose millions of followers to fraudulent promotions.
In other security news, researchers recently found that GitHub repositories leaked more than 543,000 valid credentials, while Microsoft warned about a critical Zimbra command injection vulnerability.
A separate campaign also used a fake ChatGPT “Plus 5.6” page and ClickFix instructions to install RAT malware on victims’ systems.
Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more
User forum
0 messages