On October 1, 2026, attackers took over Microsoft’s official X account and used its large audience to make an unofficial Clippy-themed cryptocurrency token appear connected to the company. Microsoft confirmed unauthorized access, secured the account and removed the posts. It said it was investigating, but the available reporting does not establish who accessed the account or how.
1
6
How the attackers used Microsoft’s account
The compromised account changed its profile picture to Clippy, followed a Clippy-themed crypto account and reposted one of its posts. The promotion centered on a token described as $Clippy; related accounts also claimed a connection between the token’s liquidity pool and Microsoft’s $MSFT ticker. Those claims did not represent Microsoft’s endorsement.
3
4
The attackers also posted a message suggesting Clippy could return if it received enough likes. After the initial unauthorized posts were removed, a purported apology appeared on the account and was deleted shortly afterward. That apology was another unauthorized post—not Microsoft’s official response.
1
9
Microsoft’s response—and what remains unknown
Microsoft spokesperson Brent Colburn confirmed that the account had been accessed without authorization and that some posts did not come from the company. Microsoft said the account was secured, the unauthorized posts were removed and the company was continuing to investigate.
1
10
Microsoft also disavowed the cryptocurrency promotion. Reporting does not identify the attackers or confirm the method they used to gain access. Without that information, claims that the incident resulted from a particular password, employee action or X vulnerability would be speculation.
1
6
10
Why the follower count mattered
Microsoft’s account had more than 13 million followers. A follow or repost from an official corporate account can lend an unfamiliar token visibility and a misleading appearance of legitimacy. But the follower count does not show how many people actually saw the posts, bought the token or acted on its promotion.
3
6
Token promotion continued elsewhere
Restoring Microsoft’s account did not immediately end the promotion. X suspended the Clippy-impersonating account that Microsoft had followed and reposted, but reporting found another account still promoting the token at the time.
6
13 That distinction matters: removing a compromised company post can stop its direct amplification without removing other accounts or claims tied to the same token.
How it compares with the 2024 Microsoft India incident
The 2024 incident targeted Microsoft India’s X account, not Microsoft’s main account. Scammers used that account to impersonate Roaring Kitty and direct people toward purported GameStop crypto presales on a malicious site.
34
46
Both incidents abused the credibility of an official Microsoft account to promote crypto-related material. The October 2026 case involved Microsoft’s main account and its larger reported audience; it also included the short-lived fake apology. The tactics differed, so the two incidents are best understood as separate account compromises rather than evidence of a shared attacker or method.
1
6
34