Unknown attackers compromised the official Microsoft account on X, promoting a cryptocurrency token in what appeared to be a pump-and-dump scheme. The incident involved unauthorized posts and the misuse of Microsoft's intellectual property, based on information published by Bleeping Computer.
The attack on Microsoft's X account, which has over 13 million followers, began with the account following and reposting tweets from an impersonating account. This led to the promotion of a cryptocurrency token, $Clippy, which claimed to have a liquidity pool paired with $MSFT. Microsoft has since confirmed the unauthorized access, secured the account, and removed the malicious posts. The company stated it does not endorse any cryptocurrency and will pursue legal action against the unauthorized token and related materials. This is not the first time a Microsoft X account has been compromised; the Microsoft India account was previously hijacked for a crypto scam involving wallet drainer malware. These incidents highlight a broader trend of X accounts being targeted for cryptocurrency scams, with significant financial losses reported by victims of similar attacks and compromised accounts, including the U.S. Securities and Exchange Commission's account which was hacked via a SIM-swapping attack to post a fake Bitcoin ETF approval.
Source: Bleeping Computer
