Why would the attacker bother creating a companion account like @clippymsftcto instead of just using the hijacked official account alone?
A single account's posts can be taken down quickly by the platform or the company itself (about 30 minutes, in this case), but if a second account that looks "affiliated" is simultaneously pushing similar messaging, the scam can keep momentum going and keep funneling in users who haven't yet seen any correction — even after the main account's posts are deleted. This is a common risk-diversification tactic that extends how long a scam survives, so the whole operation doesn't depend entirely on how long one single account stays compromised.
How can an ordinary person quickly recognize that "liquidity paired with $MSFT" doesn't make sense?
The key fact to know: Microsoft stock ($MSFT) is a regulated security traded on the Nasdaq exchange, with trading and settlement happening entirely within traditional securities market infrastructure — it is not a Token that can be placed into a decentralized exchange's Smart Contract. Any claim that a publicly traded company's "stock" can be directly paired with a crypto token in a Liquidity Pool describes two technically incompatible systems. This isn't a regulatory gray area — it's something that simply cannot happen at the infrastructure level.
Once you see a claim like this, you don't need to dig any further into other details — this statement alone is enough to identify it as a scam.
If even a company the size of Microsoft can have its official account compromised, what channel can ordinary users actually trust?
The lesson here isn't "don't trust any official account" — it's that a single channel, however official it looks, should never be the sole basis for a financial decision. A more robust approach is cross-verification: has the official website published a matching announcement, have multiple independent mainstream outlets reported on it, do the company's other official channels (an official blog, other verified accounts) corroborate the same message.
If a piece of news exists only in a single social media post and leads directly to a "buy now" call to action, that combination alone is reason enough to be suspicious — no matter how credible the account appears.
What can companies themselves do to reduce the risk of their official accounts being hijacked?
The several possible vectors security researchers pointed to — phishing, infostealer-based session hijacking, SIM swaps, compromised third-party scheduling tools, supply-chain vulnerabilities — all point toward the same defensive direction: reduce how much complete control any single person or single tool has over an official account, adopt multi-factor authentication, regularly rotate and audit third-party tool access, and treat social media managers themselves with the same security training and monitoring as high-privilege internal staff.
The fact that even one of the world's largest tech companies couldn't fully avoid this shows that this kind of risk is hard to eliminate through technology alone. A more realistic goal is shortening the exposure window after an account is hijacked, and speeding up the response time for official corrections and platform takedowns.
On Thursday, October 2, 2026, Microsoft's official X (formerly Twitter) account @Microsoft — with more than 13 million followers — was hijacked by hackers and used to promote a fraudulent cryptocurrency Token called "$Clippy." The incident is yet another reminder that even one of the world's most valuable tech companies isn't immune to having its own verified account turned, without warning, into a megaphone for scammers.
After gaining control of @Microsoft, the attackers' first move was to change the account's profile picture to Clippy — Microsoft's retired virtual assistant mascot, the classic paperclip character — while simultaneously creating a companion account, @clippymsftcto, designed to look affiliated with Microsoft. The malicious posts were taken down roughly 30 minutes later, and Microsoft followed up with an apology tweet — which was itself deleted within minutes. The chaotic sequence of events made it harder, not easier, for outside observers to quickly judge what was real.
The promotional content for $Clippy followed a textbook pump-and-dump structure — leveraging the sudden appearance of a high-profile, high-trust account to create urgency and pull in buyers. Notably, the promotion claimed the token had "a Liquidity Pool paired directly with $MSFT," Microsoft's stock ticker — a claim that is technically nonsensical, since Microsoft stock is a regulated security and cannot be directly placed into a decentralized liquidity pool paired with a token. That this claim could fool anyone at all is precisely because it was posted under Microsoft's own verified account — the account's apparent authenticity temporarily overrode how implausible the content actually was.
Public reporting hasn't confirmed exactly how Microsoft's account was breached, but security researchers have pointed to several common possibilities: phishing targeting the social media managers themselves, session hijacking via infostealer malware, SIM-swap attacks, compromise of a third-party social media scheduling or management tool, or a supply-chain-level vulnerability. This incident again illustrates that the real attack surface for high-profile accounts is rarely the account's own password strength — it's usually the weakest link somewhere in the broader chain of management and delegated access behind it.
Crypto fraud took more than $12 billion from victims globally in 2025, and social-media-based scams are among the fastest-growing categories. Tactics that hijack a verified official account are especially effective for a simple reason: the account's years of accumulated credibility and massive follower base mean the attacker doesn't need to spend any time building trust — that trust already exists, and all the attacker has to do is borrow it temporarily. That's also why a post existing for only 30 minutes can still cause real financial losses: cryptocurrency transactions move far faster than any manual review or official correction ever can.
When you see news of a well-known brand "suddenly announcing a token," the first move isn't to buy in — it's to verify the claim through the company's official website or multiple independent channels. A single social media post should never be the sole basis for authenticity, even when the account looks entirely correct, has a massive follower count, or has even changed its profile picture. Any token claiming to have "liquidity directly paired with a publicly traded company's stock" is itself a clear red flag, since that is typically technically impossible — you don't need to wait for confirmation that an account was hijacked to recognize that alone as a scam.