The hijacked account began following a crypto account and sharing its posts. The profile picture was swapped out for Clippy, the long-retired Office assistant. According to The Verge, the unauthorized activity lasted about 30 minutes before Microsoft regained control.
A Fake Clippy Token Behind the Scam
The crypto account at the center of this, @clippymsftcto, impersonated Clippy directly and has since been suspended. A second, related account kept pushing a $Clippy
token even after the first was taken down, claiming its liquidity pool was paired with $MSFT
. All related posts were eventually scrubbed from Microsoft’s feed.
Microsoft briefly posted an apology acknowledging the breach, then deleted it without explanation. The post read:
To be clear, Microsoft does not support, endorse, sponsor, or authorize any cryptocurrency or crypto-related token.
A company spokesperson later confirmed the breach directly, stating, The account has been secured and the unauthorized posts have been removed, and we are continuing to investigate the circumstances.
How Accounts Like This Get Taken Over
Microsoft hasn’t disclosed exactly how the attackers got in, but there’s no shortage of ways this kind of breach happens:
- SIM swapping, which hijacks the phone number tied to account recovery, the same method used against the SEC’s X account in 2024
- Email hijacking, which lets attackers trigger and intercept password resets
- Infostealer malware, which lifts browser session cookies and bypasses both passwords and MFA entirely
- Compromised third-party marketing or scheduling tools connected to the account
Any one of these can hand over full control without the attacker ever needing Microsoft’s actual password.
Not the Only Big Name Hit Recently
High-profile account takeovers keep happening, and size doesn’t buy immunity. A hacked HBO Max Reddit account was recently used to push malware to its audience, following a similar pattern of using earned trust against the very followers who granted it.
Hashlytics Take
The deleted apology is the detail worth paying attention to here, not the Clippy joke. A company the size of Microsoft posting a clarification and then pulling it within minutes suggests either legal caution or an internal scramble over what to say publicly, and neither reflects well on incident response at that scale. The bigger pattern across SEC, HBO Max, and now Microsoft is that account security still comes down to the weakest link in a recovery chain, a phone number, an email, a third party tool, no matter how much budget sits behind the brand.
Follow Hashlytics on Bluesky, Facebook, LinkedIn , Telegram and X to Get Instant Updates



