express gazette logo
The Express Gazette
Sunday, October 11, 2026

Microsoft X Account Hacked in Crypto Scam, Highlighting Verification Risks

Scammers exploited the credibility of Microsoft's verified X account to promote a cryptocurrency scheme, raising concerns about the reliability of social media verification badges.

US Politics • 2 hours ago
Microsoft X Account Hacked in Crypto Scam, Highlighting Verification Risks

Microsoft's official X account was recently compromised and used in an apparent cryptocurrency pump-and-dump scheme, demonstrating how even verified accounts with millions of followers can be leveraged for scams. The unauthorized posts, which did not originate from Microsoft, appeared on the account with over 13 million followers, granting the attackers a significant audience and the inherent trust associated with the Microsoft brand.

Account Compromise and Scheme Details

According to Microsoft, two unauthorized posts were made during the compromise. The first quote-reposted content from an account promoting a cryptocurrency called $Clippy, seemingly linked to the return of Microsoft Office's animated paperclip character. The second post appeared to be an apology for the earlier activity. Microsoft has since secured the account, removed the unauthorized posts, and is investigating the incident. A spokesperson stated, "We have confirmed unauthorized access to our account on X, including posts that did not originate from Microsoft. The account has been secured, the unauthorized posts have been removed, and we are continuing to investigate the circumstances."

This incident is not Microsoft's first encounter with such scams. In June 2024, the company's India account was hijacked to impersonate Roaring Kitty and promote a fake GameStop cryptocurrency presale, potentially leading users to connect cryptocurrency wallets that could drain their assets.

The Deceptive Power of Verified Accounts

The hijacking of a verified account like Microsoft's amplifies the potential for deception. When a message comes from an account that appears legitimate and has a verification badge, users are less likely to question its authenticity. This inherited trust is precisely what attackers exploit. Researchers noted a similar pattern when hackers hijacked HBO Max's verified Reddit account, using it to push malicious ads that carried an added layer of credibility.

Past Compromises and Security Vulnerabilities

Perhaps one of the most impactful examples occurred in January 2024 when the U.S. Securities and Exchange Commission's (SEC) official X account was taken over. The attackers falsely announced the approval of spot Bitcoin exchange-traded funds, causing Bitcoin's value to surge temporarily before falling after the SEC corrected the misinformation. The Justice Department later determined the attackers gained access through a SIM swap targeting the phone number associated with the SEC's account. The individual responsible pleaded guilty to conspiracy charges and received a prison sentence, highlighting the real-world consequences of such account takeovers.

Verification badges, while intended to confirm an account's identity, cannot guarantee continuous control by the legitimate owner. Attackers can gain access through various means, including phishing, credential theft, and SIM swapping, which can bypass two-factor authentication. These methods allow them to take control of accounts and impersonate legitimate entities, making it difficult for users to discern real information from fraudulent content.

Protecting Yourself from Verified Account Scams

To mitigate the risks associated with compromised verified accounts, cybersecurity experts recommend several precautions:

  • Verify announcements independently: If a company makes a significant announcement on social media, cross-reference it on their official website or other trusted channels.
  • Be wary of sudden topic shifts: An account abruptly promoting unrelated financial schemes, especially cryptocurrency, should be viewed with suspicion.
  • Avoid connecting crypto wallets via social media links: Navigate directly to known, trusted websites to manage cryptocurrency assets.
  • Utilize strong security software: Antivirus and anti-malware programs can help detect malicious links and downloads.
  • Resist urgency tactics: Scammers often create a sense of urgency to prevent users from verifying information.
  • Check destination URLs carefully: Before entering any sensitive information, examine the web address for any discrepancies.
  • Secure your own accounts: Use strong, unique passwords, enable two-factor authentication (2FA), and consider using a password manager and authenticator app for enhanced security.

If a user clicks a suspicious link, they should close the page, run security scans if files were downloaded, change passwords immediately if entered, and revoke any unrecognized token approvals on crypto wallets. If a recovery phrase or private key was exposed, the associated wallet should be considered compromised, and assets moved to a new secure wallet.


Sources