Microsoft confirmed that its official X account was taken over on Thursday and used to amplify a Clippy-themed cryptocurrency account. The account has more than 13 million followers. Attackers made it follow the crypto account, reposted one of its messages, and swapped Microsoft's profile picture for an image of Clippy, the animated paperclip assistant from older versions of Office. This analysis draws on reporting from SecurityWeek.
The account doing the posting, @clippymsftcto, posed as Clippy and has since been suspended. A second account involved in the incident kept promoting a $Clippy token, claiming its liquidity pool was paired with $MSFT. That detail matters because tying a token to a real listed stock ticker is what makes the pitch look legitimate to people scrolling quickly.
According to The Verge, an apology appeared on the Microsoft account roughly 30 minutes later and was deleted soon after with no explanation. The deleted post stated Microsoft was aware of a token being marketed in connection with its stock using the Clippy brand without permission.
"We have confirmed unauthorized access to our account on X, including posts that did not come from Microsoft," a Microsoft spokesperson told The Verge, adding that "the account has been secured and the unauthorized posts have been removed, and we are continuing to investigate the circumstances."
Microsoft has not said how the attackers got in. The company's own guidance was blunt: it does not support, endorse, sponsor, or authorize any cryptocurrency or crypto-related token.
A hijacked brand account works differently from an ordinary scam post. Your staff and customers have already decided the verified vendor account is trustworthy, so the usual signals people check, the handle, the badge, the follower count, all come back clean. A link from a software vendor your team uses every day gets clicked at a rate no cold phishing email achieves. For Microsoft, the cost here was a short window of brand misuse and a public investigation. For a smaller firm, the same takeover points customers and partners at attacker-controlled content under your name.
From Fake Crypto Promotion to Infostealer Delivery
Microsoft has not said how the attackers got in, and that gap is the most operationally relevant fact in the incident. The company's statement confirmed unauthorized access and removed posts, with the investigation still open. Everything below the account takeover itself is therefore unconfirmed, and the plausible vectors each carry different containment work.
The source lays out four realistic routes into a corporate social account:
- Credential phishing against a social media manager, where the operator enters a username and password on a lookalike login page (ATT&CK T1566).
- SIM swapping of the phone number tied to the account, the same approach used against the SEC's X account in 2024, which defeats SMS-based recovery and SMS second factors.
- Email account takeover on the mailbox registered for password resets, which hands the attacker the reset loop directly.
- Abuse of an authorized third-party tool, meaning a marketing or social scheduling platform that already holds posting permission on the brand's behalf (T1199, trusted relationship).
The fourth route deserves attention because it produces no failed logins and no suspicious sign-in location on the account itself. The posts arrive through an API token the platform was told to trust. If your social presence is managed through a scheduling vendor, that vendor's authorization is effectively a second set of credentials you do not rotate.
Infostealer malware on an employee endpoint is the vector that ties this incident to the wider criminal economy. The source notes that stealers lift browser session cookies from an active login, which lets an attacker reuse the session without a password and without triggering an MFA prompt. In ATT&CK terms that is T1539 for the theft and T1550.004 for the reuse, and it is the reason "we have MFA enabled" does not settle the question of how an account was reached.
Stealer families built for this work typically sweep more than cookies in a single run. They pull saved credentials from browser password stores, extract data from browser-based cryptocurrency wallet extensions and any seed phrase material sitting in files or notes, read clipboard contents to catch copied wallet addresses and one-time codes, and grab exported password manager vaults where the user left one on disk. It produces a credential bundle that gets sold and worked through by whoever buys it.
Key Insight: For a business, a single infected laptop therefore does not produce one compromised account.
The monetization side is straightforward. A hijacked brand account with a verified handle and a large audience converts attention into token purchases faster than any attacker-owned account can, because the reach and the apparent endorsement come free. The window only has to stay open long enough for buyers to move funds into a token the operators control.
Account hijacks also serve as malware distribution, not only as financial scams. SecurityWeek's reporting on a hacked HBO Max Reddit account shows the same pattern used to push a ClickFix lure, where the victim is instructed to paste a prepared command into their own system to "fix" a fake error. A trusted brand handle is a delivery channel, and whichever payload the operator chooses is the only variable.
That is where the loop closes. Session cookies stolen from one employee enable takeover of a corporate account, the corporate account distributes a lure, the lure installs a stealer on new victims, and those victims supply the next set of cookies. Each cycle requires no new exploit and no new vulnerability disclosure.
Business Exposure from Brand Account Takeover
The money loss in this incident sits with the people who believed the posts, and that is the first exposure to measure. The second account pushed a $Clippy token and claimed its liquidity pool was paired with $MSFT, a claim designed to make the token look like an extension of a listed company's value. Anyone on your staff who acted on that from a work device bought into an asset whose price depends entirely on the people promoting it.
Crypto losses are not reversible. If an employee connected a wallet or approved a transaction, there is no chargeback process and no bank to call, so the loss is final at the moment of signing. That part is usually personal money, which is why it gets reported late or not at all.
The corporate exposure runs through the same browser. The source notes that infostealer malware on an employee device can lift browser session cookies from an active login, which means attackers reuse a valid session without ever needing a password or an MFA prompt. The browser profile holding a wallet extension is usually the same profile holding your Microsoft 365, Google Workspace, CRM, and finance portal sessions. One infection on one laptop can therefore hand over mailbox access, file storage, and whatever else that user was signed into, and the resulting account activity looks like legitimate use of your own tooling.
Email compromise is the common follow-on. An attacker reading a finance inbox with a stolen session can watch invoice threads and insert payment instructions at the right point in a real conversation. Your accounting team sees a thread they already recognize, which is why these redirects often clear before anyone questions them.
The second exposure applies to any organization that runs a verified brand account. Verification and follower count are the asset the attacker wants. They are not trying to break your product, they are borrowing the trust your audience already places in that handle, and every minute the posts stay live they are distributing to an audience you built. The precedent is not limited to crypto promotion. A hijacked HBO Max Reddit account was used to deliver malware through a ClickFix attack, so a hijacked brand channel can push payloads as easily as token links.
Recovery timing is the part your team does not control. Regaining an account, suspending impersonating profiles, and getting fraudulent posts removed all depend on the platform's support queue, not your incident response plan. You can prepare the statement, assemble the evidence, and still wait. Meanwhile your customers are screenshotting the posts.
Then come the questions you have to answer in writing. Who held access to the account, what tools were authorized to post on your behalf, when did you first know, and did any of the content amount to promoting a financial product under your brand. Microsoft's own deleted post made the point that the company does not endorse any cryptocurrency or crypto-related token, which tells you where the pressure lands when a corporate handle promotes a tradeable asset.
Budget for the communications work as a real line item. Customer notifications, support volume, legal review of every public statement, and follow-up with anyone who lost money through your channel all consume staff time during the same period your marketing team is locked out of its primary account.
Securing Corporate Social Accounts and Containing Exposure
Start by revoking active sessions and third-party app authorizations on every corporate social account, not just the one that was hit. A password reset closes the front door while leaving stolen session cookies working, which is the exact gap infostealer malware is built to exploit. On X, that means signing out all other sessions and reviewing connected apps under account settings, then re-issuing access only to tools you can name and justify.
Work through the immediate containment steps in this order:
- Identify which staff interacted with the Clippy posts from work devices or work browser profiles, including anyone who clicked through to the token's page.
- Force credential resets for the social account and the email mailbox used for its password recovery, then revoke sessions on both.
- Pull those endpoints for infostealer artifacts, specifically browser credential stores, saved cookie databases, and any recently installed browser extensions.
- Check for unauthorized wallet transactions and for wallet extensions that have been re-seeded or re-imported, which indicates the private key left the device.
In environments Capstone manages, Adlumin ITDR surfaces authentication anomalies such as a social or SaaS login resuming from an unfamiliar location without a fresh MFA challenge, which is what session cookie reuse looks like in the logs. That gives your team a trigger to revoke tokens before an attacker posts anything.
Once containment holds, audit every corporate account your organization controls, including the dormant ones nobody has posted from in two years. Those are the accounts with stale passwords, forgotten admin users, and recovery addresses pointing at an employee who left.
- Enforce phishing-resistant MFA using hardware security keys or passkeys. SMS codes do not survive a SIM swap of the number tied to the account, which is how the SEC's account was taken in 2024.
- Replace shared passwords with platform-native team access, so each contributor authenticates as themselves and you can remove one person without rotating a credential everyone knows.
- Point recovery email and phone to monitored corporate identities, never a personal Gmail or an individual's mobile number.
- Review authorized marketing and scheduling tools, remove any that no longer have an owner, and confirm the remaining ones have their own MFA enforced.
- Strip admin rights from users who only need to draft or schedule content.
Longer term, two things reduce the cost of the next incident. The first is a written runbook for social account compromise with named owners, the platform's enterprise escalation contact, and a pre-approved holding statement, because the delay between noticing a hostile post and getting it removed is where follower losses happen. The second is brand-impersonation monitoring for lookalike handles and domains, since the impersonating account in this case used a plausible corporate-sounding handle rather than an obvious fake.
Brief your staff on the practical lesson. A verified account with millions of followers can and does post links that lead to credential pages, wallet-drainer contracts, and malware, so verification is not a signal of safety. Pair that with a standing rule that financial or crypto instructions arriving through social media never get acted on without out-of-band confirmation.
Key Takeaway: Verification Is Not Authentication
Platform verification answers one question: does this account belong to the organization named on it. It does not tell your employees whether the person composing the post works for that organization. Brand accounts get read as authoritative, and that assumption survives right up to the moment someone else is holding the session.
The second point worth carrying forward is where account compromise now happens. A stolen browser session cookie represents a login that already succeeded, so it sits downstream of both the password and the multi-factor prompt. Rotating the password or confirming that MFA is enrolled does not invalidate a token an attacker already holds. If your account reviews check password age and MFA enrollment and stop there, they are measuring controls that an infostealer operator never has to defeat.
That reframes how you should read any financial offer arriving through a social feed. The identity of the posting account is one of the weakest signals available to you, because it is the exact thing an intruder inherits intact. Crypto giveaways, token launches, and wallet-connection links carry irreversible consequences for whoever acts on them, which is why they deserve the same handling whether they come from an unknown handle or a well-known corporate one.
The single most important action is to put phishing-resistant MFA, meaning hardware security keys or passkeys rather than SMS codes, on every account with publishing rights to your brand channels, and to audit third-party app authorizations on those accounts on a fixed schedule. Everything else in social account security builds on those two controls being current.