The official Microsoft account on X (formerly known as Twitter) was hacked earlier this week, with the profile picture replaced by Clippy, the now-retired Office assistant. The breach raised concerns as the hackers appeared to be attempting to manipulate the value of a cryptocurrency token called $Clippy. According to reports, the hackers linked the @Microsoft account to a separate account, @clippymsftcto, which was later suspended by X.com. The hackers posted an image of Clippy on a Windows XP wallpaper and asked followers, "How many likes to bring back Clippy?" They then added, "500,000 likes and we bring back Clippy, the ball is in your court." The promoters of the $Clippy token shared this message on the @ClippyMSFT account, suggesting a "liquidity pool directly linked to $MSFT," referring to Microsoft's stock.
Microsoft has since regained control of its account, removed the posts, and confirmed the hacking. The company warned of legal action and stated that it had "neither authorized, sponsored, nor approved" the creation or promotion of any token linked to its brand. A spokesperson, Brent Colburn, told The Verge that unauthorized access was confirmed and that posts not originating from Microsoft were removed. The account was secured, and the company is continuing its investigation. An apology message was briefly posted and then removed about thirty minutes after the initial posts were deleted.
The hackers used a "pump and dump" scheme, a common tactic in cryptocurrency fraud, where a large quantity of a token is bought at a low price and then promoted to drive up its value before selling it at a higher price. The use of the official Microsoft account lent the token a false sense of legitimacy, while references to $MSFT stock added to its perceived credibility. At this time, there is no public information on the number of victims or the amounts collected by the hackers.
SecurityWeek reported several possible methods the hackers might have used to gain access, including SIM card swapping, where a scammer obtains a new SIM card linked to the phone number of the account to intercept verification codes via SMS. In January 2024, Eric Council Jr. was caught attempting a similar scheme by presenting a fake ID at an AT&T store in Alabama to obtain a SIM card linked to the phone number of the U.S. Securities and Exchange Commission (SEC). His accomplices then posted a fake approval of Bitcoin ETFs on the @SECGov account, causing the price of Bitcoin to rise over $1,000 before falling. Council was sentenced to 14 months in prison in May 2025. Other potential methods include infecting a Microsoft employee's computer with an infostealer, a type of malware that captures browser session cookies, or compromising a third-party social media management tool used by large companies.
Until Microsoft completes its investigation, the promoters of the $Clippy token continue to promote it through the @ClippyMSFT account, which remains active.
Microsoft Account Hacked to Promote Cryptocurrency Token
AI-rewritten from original reportingHow it works
microsoftx-hackclippy-tokencybersecuritypump-and-dumpsocial-media
Original sources:
- 🇫🇷Clubic



