Wireva

Microsoft X Account Hack Shows Verified Badges Can't Guarantee Safety

Attackers briefly took over Microsoft's official X account and used its 13 million followers to promote a cryptocurrency called $Clippy, exposing how compromised verified accounts can lend credibility to scams.

Attackers gained unauthorized access to Microsoft's official X account and used the company's verified profile to promote a cryptocurrency called $Clippy, in a brief takeover that security experts say illustrates a persistent weakness in how people judge what is trustworthy online.

The account, which has more than 13 million followers, followed and reposted content from another X account that appeared to be themed around Clippy, the animated paperclip character from older versions of Microsoft Office. That account was promoting the cryptocurrency $Clippy. Microsoft said two unauthorized posts appeared during the period when its account was compromised. The first was a quote repost of content from the Clippy-themed account and referenced bringing back the old Office character. The second appeared to be an apology related to the earlier activity.

Microsoft confirmed the breach and said neither post originated from the company. «We have confirmed unauthorized access to our account on X, including posts that did not originate from Microsoft,» a Microsoft spokesperson said. «The account has been secured, the unauthorized posts have been removed, and we are continuing to investigate the circumstances.»

The incident highlights why a verification badge, while still useful, cannot tell a reader whether the organization still controls an account at the moment a post appears. Hackers can steal credentials through phishing or other account takeover methods, and SIM swapping has been used to intercept password reset codes and defeat some forms of two-factor authentication. When a well-known account is compromised, attackers inherit the trust that the brand has already built.

That dynamic can make a fraudulent post far more convincing than one from an unknown account. A user who might scroll past a random claim about a Microsoft cryptocurrency could hesitate when the company's own verified account appears to amplify the same message. The reader may assume someone at the company approved the post, click a link because the account looks familiar, or move quickly out of fear of missing a financial opportunity.

The pattern is not new. In June 2024, scammers hijacked Microsoft India's X account and used it to impersonate Keith Gill, known online as Roaring Kitty, while promoting what appeared to be a GameStop cryptocurrency presale. People who followed the link and connected their cryptocurrency wallets risked having their assets stolen through wallet-draining malware.

A similar weakness appeared after hackers hijacked HBO Max's verified Reddit account. Researchers found that attackers used the compromised account to push 108 malicious ads over roughly 48 hours, giving those ads an extra layer of credibility because they appeared under a familiar verified profile.

One of the clearest examples of the damage a compromised account can cause came in January 2024, when attackers took over the U.S. Securities and Exchange Commission's official X account and falsely announced that the agency had approved spot Bitcoin exchange-traded funds. Bitcoin jumped by more than $1,000 following the false post, then fell by more than $2,000 after the SEC regained control and corrected the announcement. Investigators determined that attackers gained access through a SIM swap involving the phone number associated with the SEC account. Eric Council Jr. pleaded guilty in February 2025 to conspiracy charges related to the attack and was sentenced in May 2025 to 14 months in prison.

The Microsoft episode serves as a reminder that a post may only be the beginning of a scam. The real danger often waits behind a link, where wallet-draining malware or fraudulent payment requests can turn a moment of misplaced trust into a financial loss. When an account suddenly asks users to spend money or connect something valuable, going directly to the company's official website or app rather than acting on a social media post can help avoid a costly mistake.

Same event, other desks

Story file →