Microsoft’s official X account fell into the wrong hands, and whoever grabbed it told followers Clippy could come back if a post hit 500,000 likes. Nostalgia was the lure. What the scammers actually wanted to push was a fake cryptocurrency.
They named the token $Clippy, after the paperclip-shaped virtual assistant that plenty of longtime Office users still have mixed feelings about. The person running the hijacked account promoted it by reposting a related account, which X’s team has since suspended for fraud.
A fake apology was the cleverest move
The oddest part of the hijacking came after the scam posts went up. Not long after the account was compromised, a post appeared on it that seemed to put distance between Microsoft and the hack and warned bad actors that legal action was coming.
Microsoft didn’t write that post either. The apology was just as fake as the token.
It was a nasty trick. If you follow a brand and watch it disown a hack, you’d naturally assume the real owners have taken the account back. In this case, that assumption was the trap. The post was probably meant to confuse followers and make it harder to work out whether the legitimate owners had actually regained control.
A stock pairing that didn’t exist
The scammers also claimed that the $Clippy token was paired with Microsoft’s own stock, which they listed as MSTF. That claim was absurd, because the two had no legitimate connection.
The 500,000-like promise served the same purpose. Asking people to like a post to bring back a beloved mascot is exactly the kind of engagement bait that spreads quickly, and every share put the token in front of more people.
What’s still unknown
Microsoft hasn’t said how the attacker got into the account. It also hasn’t said how much money the scammers made from the campaign.
Those missing details matter. Until we know how the account was breached, there’s no way to tell whether that weakness has been fixed or is still open.
Not Microsoft’s first time
This isn’t the first time a Microsoft X account has been turned against its own followers. In June 2024, hackers took over Microsoft’s India X account to promote Keith Gill, who is better known online as “Roaring Kitty” of “GameStop” fame.
They used that account to advertise a GameStop cryptocurrency pre-sale. Users were sent to a website that could potentially drain their wallets. Based on what has been disclosed so far, that made the earlier attack more dangerous than the Clippy campaign.
The lesson for readers is simple. If a verified corporate account starts posting about a token, treat it as a red flag. A follow-up post from the same account saying everything is fine doesn’t prove anything. If Clippy ever does return, it won’t need your likes or your wallet.















STAY ALWAYS UP TO DATE