Delligsen online News

Microsoft X account hacked and used in crypto pump-and-dump scheme

NEWYou can now listen to Fox News articles!

We have all developed little shortcuts for deciding whether something online looks legitimate. You check the account name. You recognize the company logo. Then you spot that verification badge and your guard comes down a little. That can be exactly what scammers are counting on.

Microsoft’s official X account became the latest reminder after attackers gained unauthorized access and used the account in an apparent cryptocurrency pump-and-dump scheme. The account has more than 13 million followers, giving whoever controlled it access to a huge audience and the credibility that comes with Microsoft’s name.

Here is what happened, why compromised verified accounts can be so convincing and what you should check before trusting the next surprising post that shows up in your feed.

Join us for a free CyberGuy LIVE class.

Kurt „CyberGuy“ Knutsson shares practical ways to stay safer, smarter and more confident with technology. Explore classes on stopping spam, phone security, financial protection and using AI to get better health care . Each class is free, easy to follow and comes with a free printable checklist .

See the classes and register at CyberGuyLive.com

6 CRYPTO SCAM SCRIPTS CRIMINALS USE TO STEAL YOUR MONEY

People walk in front of an office building with a Microsoft sign.

Microsoft’s name and logo carry enormous trust, which is exactly why a compromised official account can make a scam look convincing. (Michael Nagle/Bloomberg via Getty Images)

How Microsoft’s X account got pulled into a crypto scheme

BleepingComputer reported that Microsoft’s @Microsoft account followed and reposted content from another X account that appeared to be Clippy-themed. That account was promoting a cryptocurrency called $Clippy. Microsoft tells CyberGuy that two unauthorized posts appeared during the period when its account was compromised. According to the company, the first was a quote repost of content from what appeared to be a Clippy-themed account and referenced bringing back Microsoft Office’s old animated paperclip character. The second appeared to be an apology related to the earlier activity. Microsoft says neither post originated from the company.

A Microsoft spokesperson provided CyberGuy with the following statement: „We have confirmed unauthorized access to our account on X, including posts that did not originate from Microsoft. The account has been secured, the unauthorized posts have been removed, and we are continuing to investigate the circumstances.“

Why a verified account can make a scam much harder to spot

If an account you have never heard of suddenly tells you Microsoft launched a Clippy cryptocurrency, you might keep scrolling. When Microsoft’s actual account appears to amplify that same message, it becomes much easier to hesitate. You may assume someone at the company approved the post. You might click a link because you recognize the account. Someone interested in crypto could move even faster because they are worried about missing an opportunity.

That is the advantage attackers get when they compromise a well-known account. They inherit trust that has already been built for them. We recently saw the same basic weakness after hackers hijacked HBO Max’s verified Reddit account. Researchers found that attackers used the compromised account to push 108 malicious ads over roughly 48 hours. Because those ads appeared under a familiar verified account, they had an extra layer of credibility.

THOUSANDS OF HACKED SITES TRICK YOU INTO INSTALLING MALWARE

Microsoft said it did not authorize or endorse the $Clippy cryptocurrency token after unauthorized access to its X account.

Microsoft has dealt with a similar account takeover before

This is also not Microsoft’s first encounter with a crypto scam involving one of its X accounts. In June 2024, scammers hijacked Microsoft India’s X account and used it to impersonate Keith Gill, better known online as Roaring Kitty. The attackers then promoted what appeared to be a GameStop cryptocurrency presale.

People who followed the link and connected their cryptocurrency wallets risked having their assets stolen through wallet-draining malware. That example shows how quickly a social media takeover can turn into something much more expensive. A post may only be the beginning. The real danger often waits behind the link.

Even the SEC’s official X account was hijacked

One of the clearest examples happened in January 2024 when attackers took over the U.S. Securities and Exchange Commission’s official X account. The compromised account falsely announced that the SEC had approved spot Bitcoin exchange-traded funds. According to the Justice Department, Bitcoin jumped by more than $1,000 following the false post. After the SEC regained control and corrected the announcement, Bitcoin fell by more than $2,000.

Investigators later determined that attackers gained control through a SIM swap involving the phone number associated with the SEC account. Eric Council Jr. pleaded guilty in February 2025 to conspiracy charges related to the attack and was sentenced in May 2025 to 14 months in prison. That case gives us a good example of how much influence one compromised account can have. An official-looking post can spread quickly before the real organization has time to warn everyone that something has gone wrong.

A verification badge cannot guarantee who controls the account right now

A verification badge can still be useful. It may help confirm that an account belongs to the person, company or organization it claims to represent. What it cannot tell you is whether that same organization still controls the account at the exact moment you are reading a post.

Hackers can steal credentials through phishing or take advantage of other account takeover techniques. SIM swapping has also been used to intercept password reset codes and defeat some forms of two-factor authentication. CyberGuy has covered this problem before on X, where hackers have taken over verified accounts and then changed them to impersonate cryptocurrency projects. The account may look established because it is. The person controlling it may have changed.

The Microsoft account takeover shows why even posts tied to major companies should be verified before you click, invest or connect a crypto wallet. (David Paul Morris/Bloomberg via Getty Images)

7 ways to protect yourself from scams posted by trusted accounts

You do not need to assume every surprising post is the work of a hacker. Still, when an account suddenly asks you to spend money or connect something valuable, a few extra checks can save you from a painful mistake.

1) Verify surprising announcements somewhere else

If a company announces a cryptocurrency, giveaway or major investment opportunity on social media, go directly to the company’s website. Look for the same announcement in its newsroom or another official channel. If the only place you can find it is one social media post, wait before acting.

2) Pay attention when an account suddenly changes subjects

If an account that normally talks about software suddenly starts pushing an obscure crypto token, treat that change as a warning sign. Scroll through its recent posts and check whether the promotion fits anything the company has announced elsewhere.

3) Do not connect your crypto wallet from a social media link

Connecting a cryptocurrency wallet can expose you to malicious approvals that allow attackers to move assets. Navigate directly to a service you already trust instead. Never enter your recovery phrase or private key into a site because a social media post tells you to.

4) Use strong security software

Strong antivirus software can help warn you about phishing sites, malicious downloads and other threats that may be waiting behind a suspicious link. Security software adds another layer of protection, but it should never replace slowing down and checking where a link came from. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android & iOS devices at Cyberguy.com

5) Slow down when money and urgency appear together

Scammers love deadlines. You may be told a token is launching right now or that an offer disappears in a few minutes. That pressure is designed to get you moving before you verify what you are seeing. Give yourself time to check another source.

6) Check the destination before entering anything

Even when the post comes from a legitimate account, the link inside it may lead somewhere dangerous. Look carefully at the web address before entering a password, payment information or crypto credentials. Small changes in a domain name can lead you to an entirely different site.

7) Protect your own social media accounts

Use a unique password for important accounts and turn on two-factor authentication (2FA). A password manager can help you create and store strong, unique passwords so you are less likely to reuse them across accounts. An authenticator app or passkey can provide stronger protection than relying only on texted security codes. Also check your account’s active sessions periodically and sign out any devices you do not recognize.

What to do if you already clicked

What you should do next depends on how far you got before realizing something looked suspicious.

  • Clicked the link only: Close the page. If a file downloaded automatically or you were prompted to install something, run a security scan with strong antivirus software.
  • Entered a password: Go directly to the real website or app and change it immediately. Update that password anywhere else you reused it, then turn on two-factor authentication (2FA). Consider using a password manager to create and store strong, unique passwords for each account.
  • Connected a crypto wallet: Review your token approvals and revoke anything you do not recognize. Revoking suspicious approvals can help prevent additional unauthorized transfers, but it cannot recover funds that have already been stolen.
  • Exposed a recovery phrase or private key: Treat the wallet as compromised and move any remaining assets to a new secure wallet.

Kurt’s key takeaways

The Microsoft attack is a good reminder of how quickly the signals we rely on can turn against us. We tell people to check the account name, look for the real profile and be cautious with impersonators. In this case, attackers briefly had control of the account people were supposed to trust. I would still use verification as one clue, but I would never let a checkmark do the thinking for me when money, passwords or a crypto wallet are involved. If a company suddenly posts something that feels out of character, verify it somewhere else before you act. Go to the company’s website, check another official channel and give yourself a minute before clicking. That extra pause can be the difference between spotting a scam and paying for one.

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Would you still trust a financial announcement because it came directly from a verified company account, or do attacks like this make the checkmark almost meaningless to you? Let us know by writing to us at Cyberguy.com

Sign up for my FREE CyberGuy Newsletter

  • Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
  • For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com – trusted by millions who watch CyberGuy on TV daily.
  • Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.

Copyright 2026 CyberGuy.com. All rights reserved.

Exit mobile version