Back to Newsroom
Threat Intel

Microsoft's Official X Account Hijacked in Crypto Pump-and-Dump Scheme

Attackers seized Microsoft's 13-million-follower X account to promote a fraudulent token falsely tied to its stock ticker — the latest in a wave of hijacks turning trusted corporate accounts into crypto scam megaphones.

Microsoft's Official X Account Hijacked in Crypto Pump-and-Dump Scheme

Attackers briefly seized control of Microsoft's official X account — followed by more than 13 million people — and used it to promote a fraudulent cryptocurrency token in a textbook pump-and-dump play.

What happened

The compromised @Microsoft account followed and reposted content from an account impersonating Clippy, Microsoft's retired virtual assistant, which was pushing a token branded as "$MSFT" and falsely claiming a liquidity pool tied directly to Microsoft's stock. A second impersonator account kept amplifying the token even after the first was suspended, riding on the credibility the hijacked repost had already generated.

Microsoft confirmed the breach, saying it had identified unauthorized access to the account, removed the posts, secured the account, and launched an investigation. In a follow-up statement, the company stressed that it has no affiliation with any cryptocurrency or token using the Clippy name or the MSFT ticker, and said it intends to pursue legal action over the unauthorized use of its brand and intellectual property.

Why it matters

Verified, high-follower corporate accounts are an efficient distribution channel for crypto fraud: a single hijacked post reaches millions of people who have little reason to doubt the source. This is not an isolated case. Microsoft's India account was compromised in mid-2024 to impersonate a well-known meme-stock trader and steer followers toward a fake presale site loaded with wallet-drainer malware, and blockchain investigators have linked a single wallet-drainer campaign on X to roughly $59 million stolen from tens of thousands of victims. Even government accounts aren't immune — a SIM-swap attack against a major financial regulator's X account used a fabricated announcement to move markets before the attacker was identified and sentenced.

The pattern repeats because it works: compromise a trusted account, push a too-good-to-be-true token or link, and let the account's reputation do the work a cold-outreach scam could never pull off on its own.

What to do

  • Never treat a crypto opportunity as credible just because it was posted or reposted by a recognizable brand account — verify through the company's official channels first.
  • Treat any "exclusive" token, presale, or liquidity-pool claim tied to a major stock ticker as a red flag; publicly traded companies do not launch tokens this way.
  • If you connected a wallet or signed a transaction after clicking a link from a suspicious post, move remaining assets to a new wallet immediately and revoke token approvals using a reputable wallet-security tool.
  • Organizations managing high-follower social accounts should enforce hardware-key MFA, tightly restrict who can issue session or API tokens, and monitor for unexpected follow/repost activity as an early signal of compromise.
SHARE