RUECAT DEX
All news
X / Google News 1d ago

Microsoft Official X Account Compromised to Promote Fraudulent Clippy Token Scam

A major security breach hit Microsoft's verified X account with 13 million followers to distribute an unauthorized crypto scam.

Digital security shield with glowing orange cracks illustrating Microsoft X account hack.

Cybersecurity concerns reemerged across social media following a high-profile Microsoft X account hack that targeted the tech giant's primary corporate profile. The official account, which commands an audience of over 13 million followers, was hijacked by malicious actors to promote a fraudulent cryptocurrency scheme featuring a spoofed Clippy mascot, according to breaking alerts on X.

During the unauthorized intrusion, the compromised profile followed and amplified fraudulent accounts, sharing links intended to trick users into connecting Web3 wallets to malicious draining contracts. Microsoft security personnel acted to regain control of the profile, subsequently posting a message acknowledging the incident and threatening legal recourse against the perpetrators before promptly deleting that statement as well.

The episode underscores the persistent vulnerability of major corporate profiles to social engineering and session hijacking attacks. Malicious actors frequently seek out verified, high-follower accounts to lend false credibility to fraudulent token launches and phishing portals, exploiting public trust before platform security teams can implement remedial actions.

Security specialists continue to warn users to exercise rigorous caution when encountering unexpected token promotions from corporate brands. Observers are awaiting formal debriefs regarding how the breach occurred, while social platforms face renewed scrutiny regarding the robustness of enterprise-grade two-factor authentication and access controls for multi-seat accounts.

Key takeaways

  • Microsoft's verified X account with 13 million followers was breached to promote a scam token.
  • The attackers utilized a fraudulent Clippy theme to attract retail crypto investors to phishing links.
  • Microsoft regained account access and removed the unauthorized promotional posts.