SOCLYDE logo
Current languageEN
Cybersecurity newsData breachSecurity incident

Microsoft’s x account hijacked in clippy token scheme

Microsoft confirmed unauthorised access to its X account after posts tied to a Clippy crypto token were shared.

By Soclyde Team

A phone on a desk shows a social network with no readable post

In summary

  • The official @Microsoft account followed and reposted a post from @clippymsftcto, an account impersonating Clippy.
  • The posts were used to promote a crypto token; Microsoft confirmed unauthorised access, account recovery and removal of the posts.
  • Microsoft has not disclosed the access method and said it was continuing its investigation.

Explore next

Soclyde resources

Article contents

In early October 2026, Microsoft’s official X account followed and reposted a message from @clippymsftcto, an account presenting itself as connected to Clippy. The post asked how many likes it would take to bring back the assistant. Microsoft later confirmed unauthorised access to its account, removed the posts and said the account had been secured.

The incident was used to promote a Clippy-associated crypto token. A Microsoft spokesperson quoted by The Verge said posts had appeared that did not come from the company and that Microsoft was continuing to investigate the circumstances.

What is known and what is not

Sources establish that the brand account amplified misleading content and that Microsoft confirmed unauthorised access. They do not describe how the account was taken over. The incident should not be attributed to password theft, phishing or a compromise of internal systems without published evidence.

The deleted post and related accounts have changed or disappeared since initial coverage. Contemporary screenshots and reporting help reconstruct the sequence, but available information does not show that Microsoft wallets or customer data were affected.

Why a brand post can mislead

An official account followed by many users can make a fraudulent promotion appear credible. Here, the Clippy reference and nostalgic promise of a return made the post look familiar, while the token provided the financial hook. A message appearing temporarily on a brand account is not Microsoft’s endorsement.

The sources reviewed report token promotion and unauthorised access; they do not establish financial losses, how many people bought the token or the precise role of each crypto account.

Verify announcements and avoid the token scam

Do not treat an X post, even from an official account, as investment advice. Check announcements through another known Microsoft channel and wait for independent confirmation before acting. Do not install an extension, connect a wallet or sign a transaction through a link shared in a token-related post.

If you interacted with a site or transaction, use your wallet’s security controls to review and revoke relevant permissions. Never share a Secret Recovery Phrase with someone claiming to help.

Steps for teams managing social accounts

Organisations should limit who can publish, protect those accesses with multi-factor authentication and maintain recovery procedures independent of the account itself. Decide who can suspend posts and issue a correction through a secondary channel if an account is compromised.

After unauthorised access, revoke active sessions and available tokens, review administrators and check recent security setting changes. These are general response measures for social accounts; they do not describe the access method used against Microsoft.

The Soclyde connection

This incident concerns a social media account, and Soclyde does not protect Microsoft’s X account. Soclyde is a local-first password and access manager; its encrypted vault lets a user organise their own credentials on their devices. Session security, authentication factors and publishing roles must be managed with the relevant platform.

Takeaway

Microsoft confirmed unauthorised access to its X account after it amplified posts tied to a Clippy token. The company removed the posts and secured the account, but has not disclosed the access method. A post from a compromised official account is not financial endorsement.

To organise your own access details, see our guide to local-first password managers.

Frequently asked questions

What did the compromised X account do?

Microsoft’s official account followed and reposted a post from @clippymsftcto, an account impersonating Clippy and tied to promotion of a crypto token. Microsoft confirmed that some posts did not come from the company and removed them.

How was the account compromised?

Microsoft confirmed unauthorised access and said the account had been secured, but did not disclose the access method. Available sources do not establish password theft, phishing or a compromise of Microsoft infrastructure.

How can people avoid scams linked to the posts?

Do not treat a brand post as financial endorsement, even when it comes from an official account. Do not buy a token based on a deleted post; verify announcements through another official channel and do not sign a transaction prompted by a direct message.

References

Sources and references

Need advice?

Design your password strategy with Soclyde

Schedule a dedicated walkthrough with the team to see how local-first security adapts to your stack.

Talk with us

Keep reading