We all have our little tricks for figuring out if something we see online is legit, right? You know, checking the account name, recognizing the logo, and then that verification badge pops up, making you feel a bit safer. But that’s exactly what scammers hope for.
Recently, Microsoft’s official account on X was used without permission in what looked like a cryptocurrency pump-and-dump scheme. With over 13 million followers, whoever accessed the account had a massive audience and the trust that comes with Microsoft’s brand.
So, here’s a quick overview of what happened, why these hacked verified accounts can seem so trustworthy, and what you should consider before you take a post at face value.
How Microsoft’s X account got pulled into a crypto scheme
According to reports, Microsoft’s @Microsoft account engaged with another X account that seemingly revolved around the old character Clippy. This particular account was touting a cryptocurrency called $Clippy. Microsoft informed that two unauthorized posts were made during the account’s compromise. One post was a retweet referencing a supposed revival of Clippy, while another was an apology related to that action. Microsoft confirmed neither post was created by them.
A Microsoft representative stated: “We have confirmed unauthorized access to our account on X, including posts that did not originate from Microsoft. The account has been secured, the unauthorized posts have been removed, and we are continuing to investigate the circumstances.”
Why a verified account can make a scam much harder to spot
If a random account suddenly spouts off about a new Microsoft Clippy cryptocurrency, you might just ignore it. But when the actual Microsoft account shares that same information, it’s pretty easy to second-guess your instincts. You might think there’s an organizational stamp of approval there. Clicking on that link can seem so tempting—especially for those interested in crypto who fear missing out.
This is the danger for users when hackers compromise a well-known account. They get to leverage existing trust. A similar situation recently unfolded when hackers hijacked HBO Max’s verified Reddit account, which was then used to post 108 malicious ads within just about two days. Since those ads were linked to a verified account, they seemed more credible.
Microsoft has dealt with a similar account takeover before
This isn’t Microsoft’s first encounter with crypto-related scams via its accounts. Back in June 2024, scammers took control of Microsoft India’s account and impersonated a well-known figure in finance, Keith Gill, aka Roaring Kitty, promoting a GameStop cryptocurrency presale. Those who clicked through not only risked their wallets but could have exposed themselves to malware.
Even the SEC’s official X account was hijacked
In January 2024, attackers took over the U.S. Securities and Exchange Commission’s official account, falsely claiming the SEC had approved Bitcoin ETF funds. This mischief caused Bitcoin’s value to spike by over a thousand dollars before plummeting when the real SEC regained control and set the record straight. The promptness with which a compromised account can act shows the potential for rapid and significant financial effects.
A verification badge cannot guarantee who controls the account right now
Verification badges can still serve a purpose. They might help confirm that an account is linked to a particular person or organization. But they don’t guarantee that the account is still under the original owner’s control. Credentials can be stolen through phishing or by exploiting other methods of account compromise.
7 ways to protect yourself from scams posted by trusted accounts
You shouldn’t automatically assume that every unexpected post is a scam. Yet, when an account suddenly suggests you spend money or connect something important, being cautious can help you avoid costly mistakes.
1) Verify surprising announcements elsewhere
When a company makes an unexpected declaration about cryptocurrency or a major investment, don’t just rely on social media. Check the company’s official website for the same announcements.
2) Watch for abrupt topic changes
If an account that usually focuses on one subject suddenly pivots to promote a strange crypto coin, that’s a red flag. Browse their recent posts to see if this aligns with their typical content.
3) Avoid connecting your crypto wallet via social media links
Linking your cryptocurrency wallet could expose you to unwelcome approvals allowing hackers to steal your assets. Always navigate directly to a trustworthy service instead.
4) Use strong security software
Good antivirus software can help detect phishing sites and other threats behind dubious links. While it’s a layer of safety, it won’t replace the need to verify where a link leads.
5) Don’t rush when money and urgency collide
Scammers thrive on deadlines. If you’re being told to act fast, take a beat. Verify the information before making any decisions.
6) Check the link’s destination
Even posts from verified accounts might lead you somewhere risky, so be careful. Look closely at the URL before entering sensitive information.
7) Secure your own social media accounts
Employ a unique password for your major accounts and activate two-factor authentication (2FA). Consider using a password manager to create and retain strong passwords.
What to do if you already clicked
What you should do next varies on your interaction with the suspicious content:
- If you just clicked the link, close it immediately. If something downloads automatically, run a security scan.
- If you entered a password, visit the genuine site to change it right away. Update that password on any accounts where it might be reused.
- If you linked your crypto wallet, check your token approvals and revoke any suspicious ones.
- If you shared a recovery phrase or private key, treat the wallet as compromised and transfer your assets to a secure wallet.
Kurt’s key takeaways
The Microsoft incident exemplifies how quickly our usual indicators can fail us. We often advise people to be vigilant with account names and profiles, but what happens when attackers take control of accounts we’re meant to trust? While a verification check is helpful, don’t let it do all the heavy lifting, especially regarding money or sensitive information. If you spot something odd, pause and verify through other official channels before taking action. That moment of caution might save you from a costly error.






