By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Threatwire
Search
  • Home
  • News & Alerts
  • Articles
  • Features
  • Spotlight
  • About
    • Mission
    • Services
    • Contact
  • Newsletter
  • Shop
    • All Items
    • By Category
      • Drinkware
      • T-Shirts
    • Cart
Reading: Clippy-themed crypto grift briefly took over Microsoft’s X feed
0

No products in the cart.

  • AI
  • Android
  • Authentication
  • Breaches
  • CASB
  • Compliance
  • Cryptography
  • Cyberinsurance
  • EDR
  • IAM
  • Malware
  • Phishing
  • Quantum
  • Ransomware
  • SecOps
  • SIEM
  • SOC
  • Threat Intelligence
  • Vulnerabilities
  • Zero Trust
ThreatwireThreatwire
Font ResizerAa
  • Home
  • News & Alerts
  • Articles
  • Features
  • Spotlight
  • About
  • Newsletter
  • Shop
Search
  • Home
  • News & Alerts
  • Articles
  • Features
  • Spotlight
  • About
    • Mission
    • Services
    • Contact
  • Newsletter
  • Shop
    • All Items
    • By Category
    • Cart
Follow US
  • About Threatwire
  • Services
  • Contact
  • Privacy
  • Legal
©2026 CybersecurityBeat. All Rights Reserved.
Clippy-themed crypto grift briefly took over Microsoft's X feed
News & Alerts

Clippy-themed crypto grift briefly took over Microsoft’s X feed

The company's 13-million-follower account was hijacked and used to boost a token tied to an old Office mascot.

CSBadmin
Last updated: October 4, 2026 6:41 am
CSBadmin
2 Min Read
Share
SHARE

Microsoft has acknowledged that intruders briefly controlled its official X account, then used it to promote a crypto project dressed up as a software-era mascot.

Its audience runs past 13 million people. The Verge reports that the account began following a crypto handle and boosted a post from it. The avatar was changed to Clippy, the paperclip helper that shipped years ago with Office.

The post originated from @clippymsftcto, a handle that pretended to be Clippy. That account has since been suspended. A companion account spent the episode touting a $Clippy token and claimed the coin’s liquidity pool traded alongside $MSFT.

The posts eventually came down. Roughly half an hour later a note appeared on the Microsoft account and was pulled shortly afterward without comment. In it, the company said it knew of a token being pitched against its stock and using the Clippy name without permission. The note also read: “Microsoft does not support, endorse, sponsor, or authorize any cryptocurrency or crypto-related token.”

A Microsoft spokesperson told The Verge the company had confirmed unauthorized access, that the offending posts were not Microsoft’s, and that the account was secured while investigators work.

Microsoft has not explained the intrusion. Possible routes include SIM swapping the phone number on the account, as happened with the SEC’s X profile in 2024; hijacking the password-reset inbox; lifting browser session cookies with infostealer malware; or abusing a third-party social tool trusted to post on the company’s behalf.

CSBadmin

The latest in cybersecurity news and updates.

TAGGED:Account TakeoverCrypto ScamMicrosoftSocial MediaX
SOURCES:SecurityWeek
Share This Article
Facebook Print
ByCSBadmin
Follow:
The latest in cybersecurity news and updates.
Previous Article A bogus Zoom app plants a persistent backdoor on Macs A bogus Zoom app plants a persistent backdoor on Macs
Next Article GitLab rushes a fix for a sandbox escape in its AI Gateway GitLab rushes a fix for a sandbox escape in its AI Gateway

Trending

Crooks hide a ClickFix lure inside a ChatGPT Custom GPT
Crooks hide a ClickFix lure inside a ChatGPT Custom GPT
October 5, 2026
Attackers stack two remote-access tools to keep a foothold on Windows
Attackers stack two remote-access tools to keep a foothold on Windows
October 5, 2026
MI5 tells UK universities a research funder answers to Beijing
MI5 tells UK universities a research funder answers to Beijing
October 5, 2026
A teenager and his AI bot cracked Microsoft's Titan analytics service
A teenager and his AI bot cracked Microsoft’s Titan analytics service
October 5, 2026
MetaMask pulls Ethereum validators while it probes an infrastructure breach
MetaMask pulls Ethereum validators while it probes an infrastructure breach
October 5, 2026

Related Stories

CSBadmin

Check Point rushes fix for actively exploited SmartConsole bypass

CSBadmin

OpenAI benches its next flagship after deception findings

CSBadmin

OkoBot malware injects seed phrase phishing into Ledger and Trezor wallet apps

CSBadmin

FBI Warns of In Person Cash Collections in Cryptocurrency Scams

logo-twfull
  • About Threatwire
  • Services
  • Contact
  • Privacy
  • Legal

© 2026 Threatwire / Cybersecurity Beat. All rights reserved.