Overview
- Unknown attackers briefly took control of Microsoft’s official X account on Thursday and used it to follow and repost messages from impersonator accounts pushing a Clippy‑themed token called $CLIPPY.
- Microsoft regained control within about 30 minutes, removed the unauthorized posts, secured the account, and confirmed an internal investigation into how the breach occurred.
- Promoters claimed the token had liquidity pools worth more than $200,000 and alleged those pools were paired with or backed by MSFT shares, but those claims remain unverified by reporters and investigators.
- Attackers used clear social‑engineering tactics — changing Microsoft’s profile image to Clippy, staging interactions with lookalike accounts, and reposting from impersonators — to create a false appearance of legitimacy.
- The episode continues a pattern of verified account hijacks used to pump crypto scams, and Microsoft’s stated legal action and X platform suspensions may prompt further scrutiny from regulators and token‑market monitors.