Microsoft’s X account hacked in crypto pump-and-dump scheme

A trusted social account can become a fraud delivery system in minutes. The danger is not limited to an embarrassing post. A hijacked account carries the organization’s name, audience, and accumulated credibility into whatever scheme the attacker chooses to promote.
BleepingComputer reported that unknown attackers gained access to Microsoft’s official account on X, which had more than 13 million followers. The account followed and reposted content from another account impersonating Clippy, Microsoft’s virtual assistant. That content promoted a cryptocurrency token and claimed a connection between the token and Microsoft stock.
is everything ok @Microsoft? It looks like Microsoft's X account has been taken over, as it has linked to a Clippy crypto scam 😬 https://t.co/1FBsuNLb1u
The impersonating account was later suspended, and Microsoft removed the unauthorized posts. Microsoft also said it had not authorized, sponsored, or endorsed the token. According to the report, the company was still investigating how the account access occurred.
JUST IN: 🚨 Microsoft issues strict warning denying all ties to unauthorized crypto tokens.Tech giant confirms it does not endorse or sponsor any cryptocurrency using
The account has been secured and the unauthorized posts have been removed, and we are continuing to investigate the circumstances.
BleepingComputer
Why the account mattered
The attackers did not need to reproduce Microsoft’s entire online presence. Control of one prominent account gave their promotion an appearance of legitimacy and exposed it to a large audience. Reposting content from a separate impersonation account also created a chain of apparent validation: the fake account made the claim, while the real Microsoft account seemed to amplify it.
This distinction matters for businesses of every size. Social media accounts are often treated as marketing tools, but they are also public identity assets. Customers, employees, vendors, and journalists may interpret activity from an official account as an authorized company statement. When that account is compromised, an attacker can exploit trust before the organization understands what happened.
The report also describes a previous 2024 compromise of Microsoft India’s X account. In that case, attackers impersonated a meme stock personality and directed people toward a malicious cryptocurrency site. The site allegedly drained assets from users who connected their wallets and authorized transactions. The current incident involved unauthorized token promotion, but the report does not establish that the same access method or operators were involved.
A configuration gap or compromised account is not, by itself, proof that other company systems were breached. Incident responders still need to determine the access path, affected sessions, administrative changes, and whether connected tools were exposed.
A hypothetical small business version
Hypothetical example: A regional property management company has one employee managing its social accounts through a shared password. An attacker obtains that password from an unrelated credential leak, signs in, and posts a fake payment notice directing tenants to a fraudulent portal. The company’s website and accounting system may remain untouched, but tenants could still trust the message because it came from the official account.
The lesson is not that every unexpected post proves a broad network intrusion. It is that control of a public communication channel can create immediate financial and reputational risk even when the compromise is narrowly contained.
What to actually do about it
Inventory official accounts and their owners. Record every public social profile, the employee responsible for it, the recovery address, the authentication method, and any agencies or publishing platforms with access. Remove former employees, expired vendors, and integrations that no longer have a business purpose.
Require strong, phishing-resistant authentication. Use unique credentials stored in an approved password manager and enable the strongest multifactor option the platform supports. Avoid shared passwords. Where multiple people need access, use delegated roles or a controlled social management tool so individual access can be revoked without changing credentials for the entire team.
Prepare a social account response checklist. Include platform recovery steps, internal escalation contacts, approved public channels, evidence preservation, and authority for removing fraudulent content. Staff should know who can contact the platform and who can publish a correction when the primary account cannot be trusted.
Check the public trust surface. Review impersonation accounts, lookalike domains, exposed contact details, stale login portals, and inconsistent account links. An External Security Posture Assessment can support this work through passive, external-only observation without attempting to enter systems or test credentials.
Practice the first hour. Run a short tabletop exercise in which the official account begins promoting an unauthorized investment, payment request, or download. Confirm that the team can preserve screenshots and timestamps, revoke access, warn customers through a separate verified channel, and begin reviewing connected applications.
Start by listing every account that can speak publicly in your company’s name, then verify who can access it and how that access would be revoked today.