Microsoft confirmed an X account hack after unauthorized posts from the company’s official social media profile promoted a Clippy-themed cryptocurrency token. Microsoft says it has secured the account, removed the posts, and is investigating how the compromise occurred.
What happened to Microsoft’s X account
On October 1, 2026, Microsoft’s official X account followed and amplified a separate account promoting a cryptocurrency token tied to the company’s Clippy character and the MSFT name. The official Microsoft profile, which has more than 13 million followers, also displayed unauthorized changes during the incident.
The suspicious posts were later removed. Microsoft spokesperson Brent Colburn confirmed to The Verge that the activity resulted from unauthorized access.
What Microsoft has confirmed
Microsoft confirmed that posts appeared on its X account without the company’s authorization. The company said the account has been secured and the unauthorized content has been removed.
Microsoft also stated that it did not create, sponsor, endorse, or authorize the cryptocurrency token promoted during the incident. The company said it is continuing to investigate the circumstances and plans to pursue action against the unauthorized use of its intellectual property.
What remains unknown
Microsoft has not publicly disclosed how the attackers accessed the account. It is not yet known whether the compromise involved stolen credentials, a hijacked session, social engineering, a third-party tool, or another method.
No confirmed victim count or financial-loss total has been released. Although the activity appeared designed to increase interest in the token, Microsoft has not identified the attacker or confirmed the full scope of the scheme.
Who may be affected
The immediate risk applies to people who saw the unauthorized posts and treated them as an official Microsoft endorsement. Anyone who purchased the token, connected a cryptocurrency wallet to a linked site, or approved a wallet transaction should review that activity promptly.
Organizations should also treat the incident as a reminder that a verified social media account can distribute fraudulent content after a compromise. A familiar brand name or verified profile does not make a cryptocurrency promotion trustworthy.
Why this incident matters
High-visibility account takeovers can give scams immediate credibility and expose millions of followers to fraudulent promotions. Attackers frequently use compromised corporate accounts to promote fake token launches, investment offers, support services, or wallet-draining websites.
Microsoft’s confirmation establishes that its account was accessed without authorization. It does not establish that Microsoft’s products, customer networks, or internal corporate systems were breached.
Practical defensive actions
For individuals
- Do not buy or promote a token based only on a social media post, even when it comes from a verified account.
- Verify announcements through the organization’s official website and established press channels.
- Do not connect a cryptocurrency wallet to a site promoted through an unexpected post.
- If a wallet was connected, review token approvals, revoke suspicious permissions, and move remaining assets to a secure wallet if compromise is suspected.
- Review recent transactions and preserve screenshots, wallet addresses, URLs, and transaction hashes for any fraud report.
For businesses
- Require phishing-resistant multifactor authentication or passkeys for corporate social media accounts.
- Limit administrator access and remove former employees, unused integrations, and unnecessary third-party tools.
- Review active sessions, recovery methods, delegated access, and connected applications regularly.
- Create an out-of-band process for confirming urgent social media posts involving payments, investments, cryptocurrency, or account recovery.
- Prepare a rapid response process to revoke sessions, remove fraudulent content, preserve evidence, and notify customers after an account takeover.