Summary
- Hackers hijacked Microsoft’s official X account to promote a fraudulent Clippy token through a fake campaign promising the assistant’s return.
- A fabricated Microsoft apology threatened legal action and appeared intended to confuse followers about who controlled the compromised corporate account.
- Microsoft’s India account suffered a June 2024 breach promoting a GameStop cryptocurrency presale through a website that could drain wallets.
Hackers hijacked Microsoft’s official X account to promote a fraudulent Clippy token through a fake promise to revive the assistant. According to BleepingComputer, the compromise turned Microsoft’s paperclip assistant into promotional bait, with posts presenting the token through the company’s profile.
The attackers reposted content from an associated account advertising the so-called $Clippy token through Microsoft’s compromised social media profile. One message promised Microsoft would bring Clippy back if followers helped the post reach 500,000 likes.
The campaign encouraged users to engage with the nostalgic promise while directing attention toward a cryptocurrency without legitimate Microsoft backing. Promotional material also claimed the token paired with Microsoft stock, using the label “MSTF” to suggest a corporate connection.
No legitimate relationship supported that claim, and X suspended the fraudulent account. Details about the compromise remain limited, including how attackers accessed Microsoft’s account and how much money the campaign generated.
Also Read: Shiba Inu Exchange Reserves Hit Four-Month High as SHIB Falls Nearly 3%
Fake Apology Complicates Microsoft Account Hijack as Earlier Crypto Attack Resurfaces
We're back on X.
— 36Crypto (@36Crypto1) August 21, 2026
Our previous account (36crypto2) is currently unavailable while we continue working through the appeal process. In the meantime, this is our new official account. While you are on this page, please support us by sharing and following.
An apparent Microsoft apology followed the promotional posts, seemingly rejecting the scam and threatening those responsible with legal action. Microsoft did not publish this message either, making the supposed corporate response another element of the fraudulent cryptocurrency promotion.
The fabricated statement appeared designed to confuse followers about whether Microsoft had recovered control of its account. By circulating an apparent corporate response alongside fraudulent promotions, the campaign blurred the distinction between attacker activity and authentic communication.
Microsoft has faced similar account compromises before, including a June 2024 attack targeting its India profile with cryptocurrency promotions. During that incident, attackers advertised a GameStop cryptocurrency presale through references to Keith Gill, better known online as Roaring Kitty.
The account directed users toward a website that could potentially drain their cryptocurrency wallets, according to the incident’s coverage. Both campaigns exploited Microsoft’s identity, although the India incident included a potentially dangerous website rather than just nostalgia-driven token promotion. The Clippy campaign’s financial impact remains undisclosed, while unanswered questions surround the access method and the company’s recovery response.
Also Read: XRP ETFs Beat Ethereum by $59.44 Million as Franklin Leads In Inflows
