Incident
Published 2026-10-01
Verified 2026-10-02

Microsoft @Microsoft X account hijacked (1 Oct): Clippy crypto pump-and-dump; account secured

The Verge (1 October 2026; Tom Warren) and BleepingComputer (2 Oct) report that unknown attackers hijacked the official Microsoft account on X (@Microsoft; ~13M followers) in a crypto pump-and-dump promoting a $Clippy token. The compromise began when @Microsoft followed and reposted a now-suspended impersonation account (@clippymsftcto) posing as Clippy; a related @ClippyMSFT account continued promoting the token with claims of a liquidity pool paired with $MSFT. Microsoft spokesperson Brent Colburn confirmed unauthorised access and posts that did not come from Microsoft; the account was secured, unauthorised posts removed, and investigation continues. Microsoft also stated it does not authorise or endorse any Clippy/$MSFT-linked cryptocurrency and will pursue legal action to remove the token materials. Distinct from the June 2024 @MicrosoftIndia crypto-drainer hijack. No product CVE. Primary: The Verge 1 Oct; wire: BleepingComputer 2 Oct.

Product
Microsoft brand account on X (@Microsoft); Clippy IP abuse (not a Microsoft product CVE)
Versions
n/a (social-account compromise). Related handles noted in wires: @clippymsftcto (suspended), @ClippyMSFT (token promo).
Exploited in Australia?
unknown
Patch to
Treat unsolicited Clippy/$MSFT crypto tokens and related X posts as scams. Prefer official Microsoft channels for product/security notices. Orgs: review brand-account MFA / role access on X; revoke sessions after any suspected takeover.

Primary: The Verge — Microsoft confirms X account compromised / Clippy crypto posts (1 Oct 2026) · Vendor: The Verge — Microsoft spokesperson confirmation (Brent Colburn) · BleepingComputer — Microsoft X account hacked in crypto pump-and-dump (2 Oct 2026)

tech identity