On Thursday, October 2, 2026, attackers briefly seized Microsoft’s (NASDAQ: MSFT) official account on X and used the company’s enormous audience to push a speculative token built around Clippy, the long-retired Office paperclip assistant.
The @Microsoft profile, which has more than 13 million followers, was under outside control for roughly half an hour before the company recovered it.
During that window the compromised account followed an impersonator styled as a Microsoft Clippy persona, @clippymsftcto, and reposted that account’s engagement bait.
The message asked how many likes it would take to revive Clippy and paired the plea with imagery of the character against the old Windows XP Bliss wallpaper.
Observers also reported that the main Microsoft profile picture was swapped for a Clippy-themed image, a small visual change that made the activity look more like an official rebrand than a random intrusion.
The impersonating account was later suspended by X.A second message then appeared on the Microsoft account, written in a formal, legalistic tone.
It said Microsoft had not authorized, sponsored, endorsed, or permitted any cryptocurrency tied to Clippy, Microsoft, or the $MSFT ticker, and it suggested the company would pursue removal of the unauthorized token and related materials.
Microsoft later said that post, like the earlier Clippy repost, was not written by the company.
Both were deleted after access was restored.
Company spokesperson Brent Colburn confirmed the breach to multiple outlets, including The Verge, which first reported the incident.
He said Microsoft had verified unauthorized access to the X account, including posts that did not originate with the company; that the account had been secured; that the unauthorized posts had been removed; and that the circumstances were still under investigation.
Microsoft has given no public indication that it plans to restore Clippy as a product feature.
The character was retired from Office in the early 2000s and has since survived mainly as an occasional in-joke.
The episode fits a familiar pattern in meme-coin promotions: hijack or mimic a trusted brand, ride nostalgia, and imply an official link that does not exist.
After the impersonator was suspended, a separate account, @ClippyMSFT
, continued promoting a $Clippy token and claimed the token had a liquidity pool paired with $MSFT.
That pairing is an assertion by promoters, not a verified corporate arrangement.
Microsoft’s stock ticker is unrelated to any such token, and the company has denied any connection.
The incident is not Microsoft’s first brush with crypto-themed account abuse on X.
In June 2024, attackers took over the company’s India account and used it in a scheme that impersonated the meme-stock personality known as Roaring Kitty.
High-follower corporate profiles remain attractive targets because a single repost can reach millions of people before security teams notice.
For users, the practical lesson is unchanged. A blue check and a famous name do not turn a token pitch into an official product. Microsoft has said it does not support the Clippy-linked token, has locked down the account, and is still examining how the takeover occurred.