The Microsoft X hack briefly placed the company’s official social media account under unauthorised control. Attackers used the account’s reach of more than 13 million followers to promote a Clippy-themed cryptocurrency.
Microsoft has since secured the account, removed the unauthorised posts and opened an investigation. As of 2 October 2026, neither the attacker nor the method used to gain access had been identified publicly.
Microsoft X hack changed the account’s identity
The incident occurred on 1 October 2026 and affected Microsoft’s official @Microsoft account on X. The first public media observation came from The Verge journalist Tom Warren at 23:04 UTC, when the account began displaying activity that did not resemble normal Microsoft communications.
During the Microsoft X hack, the account’s profile image was changed to show Clippy, the animated paperclip formerly used as an assistant in Microsoft Office. The account also followed and reposted material from @clippymsftcto, an account impersonating a Microsoft-linked Clippy project.
The compromised account published an engagement message stating, “500,000 likes and we bring Clippy back”. This combined a recognisable Microsoft character with a simple call for social engagement, helping the posts attract attention before followers could establish whether they were genuine.
The activity also amplified promotion of a Clippy-themed cryptocurrency. Reports characterised the campaign as a pump-and-dump style promotion, in which publicity and perceived legitimacy are used to encourage interest in a token and potentially increase its price before holders sell.
Using @Microsoft gave the campaign an appearance of corporate endorsement that an unknown cryptocurrency account could not create independently. The profile image change, reposts and direct message from the official account reinforced the false impression that Microsoft was involved.
Timeline of the Clippy cryptocurrency promotion
Suspicious activity appears on 1 October
At 23:04 UTC on 1 October 2026, the unusual behaviour was publicly flagged. The activity continued from late evening UTC into early 2 October, although reporting times differ slightly because coverage used different local time zones.
Within the visible incident window, the attacker changed the profile image, followed the Clippy impersonator and reposted its content. The engagement bait and cryptocurrency promotion were then placed in front of Microsoft’s substantial audience.
Crypto Briefing reported that visible unauthorised control lasted approximately 30 minutes. Even such a short period can be significant on a high-profile social account because posts can be copied, shared and converted into screenshots almost immediately.
Microsoft secures the account on 2 October
Microsoft confirmed the Microsoft X hack on 2 October 2026. In a statement provided to the press, the company said it had confirmed unauthorised access to its X account, including posts that did not come from Microsoft.
The company said the account had been secured and the unauthorised posts removed. It also said it was continuing to investigate the circumstances, but did not disclose how access had been obtained or whether any particular account control had failed.
Reports indicated that X subsequently suspended @clippymsftcto. A separate account, @ClippyMSFT, continued making claims about a “$Clippy” token, including an assertion that a liquidity pool was paired directly with “$MSFT”. Microsoft has not supported that claim, and users should not interpret the use of its branding as evidence of endorsement.
Several reports also described a brief “apology” post appearing on @Microsoft before being deleted. Microsoft has not reproduced or authenticated that message in a formal advisory, so its authorship remains uncertain.
What is known about the account takeover
The Microsoft X hack is a confirmed case of exploitation in the wild, rather than a theoretical vulnerability. An unknown party obtained sufficient control over @Microsoft to alter its visible identity, publish posts, follow another account and repost promotional content.
However, no software vulnerability, exploit code or proof of concept has been disclosed. The incident concerns access to an account hosted on X, formerly Twitter, and not a known flaw in Windows, Microsoft 365, Office or another Microsoft product.
Microsoft has not said whether the takeover involved stolen credentials, a compromised administrator, session theft, social engineering, a third-party tool or a platform-level issue. Without verified technical evidence, attributing the incident to any one of these routes would be speculative.
The main confirmed actions and indicators were:
- The @Microsoft profile image was changed to Clippy.
- The account followed and reposted @clippymsftcto.
- A post promised Clippy’s return in exchange for 500,000 likes.
- The account amplified promotion of a Clippy-themed cryptocurrency.
- The additional @ClippyMSFT account continued making unsupported token claims.
- The attacker remained unidentified as of 2 October 2026.
No related IP addresses, domains, file hashes or on-platform link artefacts have been published by Microsoft or X. This limits the indicators available to security teams investigating whether similar activity has targeted their own social accounts.
Scope and current exploitation status
The affected asset was Microsoft’s official X account. No evidence had been reported by 2 October 2026 to suggest that other Microsoft social media accounts, customer services, software products or internal corporate systems were compromised.
This distinction is important because the visible misuse of a Microsoft identity does not by itself demonstrate a broader breach. The available evidence supports an account takeover limited to X, although Microsoft’s investigation remains in progress.
The campaign’s public nature confirms that the attacker actively exploited the access obtained. What remains unknown is whether followers purchased the promoted token, whether the campaign caused financial losses, or whether direct messages and other non-public account functions were accessed.
Why the Microsoft X hack matters to organisations
The incident demonstrates how a trusted social account can become a delivery channel for fraud without compromising the organisation’s website or internal network. For UK businesses that use X for marketing, announcements or customer support, an attacker may need only minutes to expose followers to a convincing scam.
Recognisable branding can make fraudulent cryptocurrency promotions appear credible, especially when they are reposted by an established corporate account. Changes to profile imagery or tone can also create confusion while internal teams determine whether a campaign is genuine.
Actions for corporate social media teams
Organisations should review controls around high-reach accounts while the Microsoft investigation continues. Priority should be given to measures that reduce takeover opportunities and shorten the time between an unauthorised change and a response.
- Confirm which staff and agencies can access each corporate social account.
- Use phishing-resistant multi-factor authentication where the platform supports it.
- Remove former staff, unused integrations and unnecessary third-party publishing tools.
- Alert on profile, recovery detail and authentication changes.
- Monitor unexpected posts, follows and reposts outside approved campaigns.
- Maintain a process for contacting X, removing fraudulent content and warning followers.
Employees should treat cryptocurrency promotions from a corporate account as suspicious when they fall outside the organisation’s established activity. In this case, Microsoft’s removal of the posts and confirmation of unauthorised access provide the clearest current guidance while the root cause remains under investigation.
Originally reported by PCMag Australia.








