Hackers hijacked Microsoft's X account for a scam featuring everyone's least-favorite tech mascot Clippy
Microsoft's X account was used to promote a meme coin scam, and possibly even to distribute malware.
Hackers gained unauthorized access to Microsoft's X account and used it to promote a cryptocurrency token called $CLIPPY. To further deceive potential victims, the attackers created a fake Clippy account and posted a call for likes, then retweeted it from Microsoft's official X account. Subsequently, Microsoft removed the fraudulent posts and secured their account.
The cybercriminals further attempted to cover their tracks by issuing a fabricated public apology stating that Microsoft had not authorized the promotion of any cryptocurrency token related to their brand. Despite the account being disabled, researchers discovered another account, @ClippyMSFT, still promoting the $CLIPPY token. This account claimed to have a liquidity pool paired with $MSFT, raising concerns about potential malware distribution.
Microsoft confirmed the unauthorized access and removal of the fraudulent posts, and is currently investigating the incident.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.