Microsoft’s X account hacked in crypto pump-and-dump scheme

On Thursday, unknown attackers hijacked the official Microsoft account on X, which has over 13 million followers, in what appeared to be a pump-and-dump scheme promoting a crypto token.
The attack began when the Microsoft account (@Microsoft) followed and reposted a tweet from another now-suspended X account (@clippymsftcto) impersonating Microsoft's Clippy virtual assistant, The Verge first reported.
While @clippymsftcto has been suspended, another X account (@ClippyMSFT) that reposted Microsoft's tweet is still promoting a $Clippy crypto token, claiming that it has "has a liquidity pool paired directly with $MSFT."
Microsoft has since removed the attackers' posts and confirmed the incident, saying it's investigating the circumstances.
"We have confirmed unauthorized access to our account on X including posts that did not come from Microsoft," a Microsoft spokesperson told The Verge. "The account has been secured and the unauthorized posts have been removed, and we are continuing to investigate the circumstances."
In a now-deleted tweet, the company also apologized for the posts and said that it doesn't support any cryptocurrency or crypto-related token and will take legal action.
"We are aware of a cryptocurrency token being promoted in connection with $MSFT stock, including the unauthorized use of the Clippy brand and Microsoft-related intellectual property. Microsoft has not authorized, sponsored, endorsed, or granted permission for the creation, promotion, or use of any cryptocurrency token associated with Clippy, Microsoft, or $MSFT," Microsoft said.
"We are taking this matter seriously and will pursue appropriate legal action to have the unauthorized token and related materials removed. For the avoidance of doubt, Microsoft does not endorse or have any affiliation with this token, its creators, or any related cryptocurrency project."
A Microsoft spokesperson was not immediately available to comment when BleepingComputer reached out earlier today for more details on the incident.
Microsoft apology post (The Verge)This isn't the first time an official Microsoft X account has been hacked. In June 2024, crypto scammers also hijacked the Microsoft India account on X (@MicrosoftIndia), with over 211,000 followers, to impersonate Roaring Kitty, the handle of notorious meme stock trader Keith Gill.
The attackers used the compromised account to lure potential victims and infect them with cryptocurrency wallet drainer malware.
They also used the hijacked account to reply to tweets, luring Microsoft India's followers and others on X to a malicious website (presaIe-roaringkitty[.]com) that allegedly allowed them to buy GameStop (GME) crypto as part of a so-called presale.
However, the attackers stole the crypto assets of anyone who connected their cryptocurrency wallets to the site and authorized transactions to the drainer service.
In recent years, X users have been targeted by a massive wave of account hijacks and malicious ads, with verified organizations falling victim to hacks promoting cryptocurrency scams and wallet drainers.
To put things into perspective, blockchain threat analysts at ScamSniffer revealed in December 2023 that cybercriminals stole roughly $59 million worth of cryptocurrency from 63,000 people in a single Twitter ad push between March and November using the "MS Drainer" wallet drainer.
Last year, the U.S. Securities and Exchange Commission's @SECGov account was also compromised in a SIM-swapping attack. The compromised account posted a fake announcement about the long-awaited approval of Bitcoin exchange-traded funds (ETFs) on security exchanges, which caused a temporary but significant spike in Bitcoin prices.
Eric Council Jr., the hacker behind the @SECGov hijack, pleaded guilty in February 2025 and was sentenced to 14 months in prison for his role in a conspiracy that used the compromised account to manipulate Bitcoin's value.
References in this story
- Is everything ok Microsoft? www.theverge.com The official @microsoft X account has been compromised. Microsoft’s X account followed a Clippy crypto account earlier today, reposted one of its tweets, and had its profile picture changed to a Clippy one. The posts…
- Microsoft India’s X account hijacked in Roaring Kitty crypto scam www.bleepingcomputer.com The official Microsoft India account on Twitter, with over 211,000 followers, was hijacked by cryptocurrency scammers to impersonate Roaring Kitty, the handle used by notorious meme stock trader Keith Gill.
- Crypto drainer steals $59 million from 63k people in Twitter ad push www.bleepingcomputer.com Google and Twitter ads are promoting sites containing a cryptocurrency drainer named 'MS Drainer' that has already stolen $59 million from 63,210 victims over the past nine months.
- US SEC’s X account hacked to announce fake Bitcoin ETF approval www.bleepingcomputer.com The X account for the U.S. Securities and Exchange Commission was hacked today to issue a fake announcement on the approval of Bitcoin ETFs on security exchanges.
- SEC confirms X account was hacked in SIM swapping attack www.bleepingcomputer.com The U.S. Securities and Exchange Commission confirmed today that its X account was hacked through a SIM-swapping attack on the cell phone number associated with the account.
- SEC Chair Gary Gensler Archive (@GenslerArchive) on X x.com The @SECGov twitter account was compromised, and an unauthorized tweet was posted. The SEC has not approved the listing and trading of spot bitcoin exchange-traded products.
- Hacker pleads guilty to SIM swap attack on US SEC X account www.bleepingcomputer.com Today, an Alabama man pleaded guilty to hijacking the U.S. Securities and Exchange Commission (SEC) account on X in a January 2024 SIM swapping attack.
- www.justice.gov



