{"id":99809,"date":"2026-10-09T06:20:11","date_gmt":"2026-10-09T10:20:11","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=99809"},"modified":"2026-10-09T06:20:11","modified_gmt":"2026-10-09T10:20:11","slug":"clippy-crypto-scam-99809","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/clippy-crypto-scam-99809\/","title":{"rendered":"Hackers hijack Microsoft Twitter to push Clippy crypto scam"},"content":{"rendered":"<p>When a company as large and security-conscious as Microsoft falls victim to a social media hijacking, the cybersecurity community pays attention. The incident that unfolded on Microsoft&#8217;s official Twitter account last Thursday was not just another account takeover&mdash;it was a bizarre, almost nostalgic prank with a sinister financial motive. Hackers seized control of the account, which boasts over 13 million followers, replaced the profile picture with Clippy&mdash;the notoriously annoying paperclip assistant from 1990s Microsoft Office&mdash;and began promoting a cryptocurrency scam. The episode, which ultimately included a fake apology from the attackers themselves, highlights the evolving tactics of cybercriminals who are increasingly targeting high-profile accounts to push crypto fraud and steal from unsuspecting users.<\/p>\n<h2>The Clippy Crypto Takeover: How the Microsoft Hack Unfolded<\/h2>\n<p>On the afternoon of October 10, 2024, followers of Microsoft&#8217;s Twitter feed noticed something odd. The account&#8217;s avatar had changed to Clippy, the goggle-eyed paperclip that once interrupted Word documents to offer unsolicited help. The account also followed a Clippy-themed crypto account and shared one of its posts. The post came from an account called <strong>Clippy MSFT<\/strong>, which posed as Clippy acting as Microsoft&#8217;s Chief Technology Officer. Meanwhile, a second account aggressively promoted a token called <strong>Clippy Coin<\/strong>, claiming its liquidity was paired with Microsoft&#8217;s stock price&mdash;a claim designed to trick investors into thinking the cryptocurrency had a legitimate corporate backing.<\/p>\n<p>Approximately 30 minutes after the first posts appeared, a polished, corporate-style apology was published on Microsoft&#8217;s Twitter feed. It stated that Microsoft was aware of the unauthorized use of the Clippy brand and that the company did not endorse any cryptocurrency. But then, without explanation, the apology vanished. Microsoft later confirmed that the apology was also posted by the hackers, not by the company itself. The attackers had maintained control of the account long enough to issue a seemingly genuine mea culpa, likely to lull followers into a false sense of security before planning further malicious activity&mdash;though no second wave of posts materialized before Microsoft regained control.<\/p>\n<p>Security researcher and podcast host Graham Cluley, who covered the incident on the <em><a href=\"https:\/\/overcentral.com\/en\/audio-fingerprinting-tracking-technique-81382\/\" title=\"Smashing Security reveals how silence tracks you online\" data-iacss-internal=\"1\">Smashing Security<\/a><\/em> podcast, noted the peculiarity: &#8220;These hackers seized control of a Twitter account with 13 million followers. The mischief they could have caused. But what they decided was that they were just going to go with a paperclip. No ransomware, no data theft, no phishing, just a paperclip and an apology.&#8221;<\/p>\n<h2>How Did the Attackers Breach Microsoft&#8217;s Account?<\/h2>\n<p>Microsoft has not publicly disclosed the root cause of the compromise. However, security experts point to several possible vectors: a successful phishing attack against a social media manager, a SIM-swap attack that intercepted password reset codes, stolen session cookies from info-stealing malware that bypassed multi-factor authentication, or a compromised third-party social media management tool. X itself (formerly Twitter) has also been the source of account takeovers in the past, such as the infamous Bitcoin scam tweet from July 2020 that compromised high-profile accounts including Joe Biden and Elon Musk.<\/p>\n<p>Regardless of the method, the incident serves as a stark reminder that even the most sophisticated organizations can be vulnerable to account hijacking. The attackers&#8217; choice to promote a cryptocurrency scam rather than launch ransomware or data theft is telling: crypto scams offer a quick, relatively low-effort path to monetization, and the Clippy brand provided an instantly recognizable hook that tapped into nostalgia and corporate parody.<\/p>\n<h2>Cybersecurity Awareness Month: A 417% Surge in Social Media Account Hijacking<\/h2>\n<p>The Microsoft hack comes during Cybersecurity Awareness Month, a time when organizations in the UK and elsewhere increase their focus on online safety. According to new figures released by <strong>Action Fraud<\/strong>, the national cybercrime reporting service run by the City of London Police, the amount of money stolen through the hacking of email and social media accounts has skyrocketed by 417% over the past year. For the financial year 2025&ndash;2026, reported losses reached \u00a36.3 million, up from \u00a31.2 million the previous year.<\/p>\n<p>These figures represent only the tip of the iceberg. Many victims do not report smaller losses&mdash;perhaps \u00a3100 here or \u00a3200 there&mdash;out of embarrassment or the belief that the sum is too small to warrant police attention. But as the total sum shows, these small losses add up. Criminals are increasingly hijacking accounts and then using them to defraud the victim&#8217;s own friends and family, exploiting trust to make the scams far more effective.<\/p>\n<h3>The Ticket Scam That Cost \u00a31,400<\/h3>\n<p>One of the most common tactics involves offering fake tickets to sold-out events. The scam works like this: a criminal gains control of a person&#8217;s Facebook or Instagram account, then posts a message claiming that the account owner can no longer attend a hot-ticket event and is selling the tickets. Friends who see the post and trust the source transfer money directly to the scammer&#8217;s bank account. In one case reported by <em>The Guardian<\/em>, a woman whose Instagram was hacked lost \u00a31,400 after her friends bought fake Oasis reunion tickets advertised through her account.<\/p>\n<p>Another variant uses fraudulent text messages or WhatsApp messages pretending to be a family member in urgent need of money. These &#8220;hi mum, I&#8217;ve lost my phone&#8221; scams have become so common that many recipients now recognise them instantly, but the scammers only need a small success rate to make the operation profitable.<\/p>\n<h2>Simple Tips to Protect Yourself from Account Hijacking<\/h2>\n<p>The City of London Police and the UK&#8217;s National Cyber Security Centre (NCSC) have issued guidance for individuals to reduce their risk of falling victim to these scams. The advice is straightforward but worth repeating, especially for friends and family who may not follow cybersecurity news closely.<\/p>\n<ul>\n<li><strong>Don&#8217;t automatically trust messages from known contacts.<\/strong> If a friend or family member contacts you via social media or email with a request for money or tickets, verify the request through a separate channel&mdash;a phone call, a text message, or an in-person conversation.<\/li>\n<li><strong>Use passkeys where available.<\/strong> Passkeys are a more secure alternative to passwords and are being promoted by the NCSC as the future of authentication. If passkeys are not an option, enable multifactor authentication and use a strong, unique password managed by a password manager.<\/li>\n<li><strong>Review your privacy settings.<\/strong> Posting publicly about upcoming concerts, holidays, or family members gives cybercriminals the information they need to craft convincing scams. Consider making your accounts private or limiting who can see your posts.<\/li>\n<\/ul>\n<p>These measures may seem basic, but social engineering remains one of the most effective attack vectors because it preys on human emotions&mdash;trust, urgency, and fear. Even cybersecurity professionals have admitted to almost falling for well-crafted scams.<\/p>\n<h2>The Rise of AI Agents in Security Teams: Opportunity and Risk<\/h2>\n<p>While the Microsoft Clippy hack and the rise in social media hijacking represent the current threat landscape, the security industry is also grappling with a transformative technology: <a href=\"https:\/\/overcentral.com\/en\/fix-scheduled-ai-agents-96618\/\" title=\"Fix Scheduled AI Agents: The One Skill They Need\" data-iacss-internal=\"1\">AI agents<\/a>. In a featured interview on the same <em><a href=\"https:\/\/smashingsecurity.com\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">Smashing Security<\/a><\/em> episode, Christine Bartlett, CMO of Hack The Box, discussed how organisations are now managing two kinds of workers&mdash;humans and AI agents&mdash;and the new risks this introduces.<\/p>\n<p>Hack The Box helps companies train their human security teams and, more recently, appraise the performance of AI agents. Bartlett explained that many organisations are in a &#8220;grey area&#8221; between basic ChatGPT usage and fully autonomous AI security operations. Most rate themselves at a 2 or 3 on a scale of 1 to 5, where 5 represents an &#8220;AI factory&#8221; with autonomous loops.<\/p>\n<h3>Four Hidden Risks of AI in Security<\/h3>\n<p>Bartlett outlined four specific dangers that can lurk beneath the surface of AI-deployment dashboards:<\/p>\n<table>\n<thead>\n<tr>\n<th>Risk<\/th>\n<th>Description<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><strong>Automation Bias<\/strong><\/td>\n<td>Over-reliance on automated tools that may not operate 100% correctly, leading to missed threats or incorrect conclusions.<\/td>\n<\/tr>\n<tr>\n<td><strong>Skill Atrophy<\/strong><\/td>\n<td>As humans depend more <a href=\"https:\/\/overcentral.com\/en\/workers-oppose-ai-payroll-95994\/\" title=\"Workers push back on AI payroll with nearly half in opposition\" data-iacss-internal=\"1\">on AI<\/a>, they lose the &#8220;scar tissue&#8221; gained from hands-on experience with past attacks, reducing their ability to handle novel situations.<\/td>\n<\/tr>\n<tr>\n<td><strong>The Missing Middle<\/strong><\/td>\n<td>Junior analysts may never acquire deep foundational knowledge if they rely on AI from day one, creating a skills gap that will be hard to fill later.<\/td>\n<\/tr>\n<tr>\n<td><strong>Silent Agentic Drift<\/strong><\/td>\n<td>AI agents can degrade over time as the environment changes, yet organisations often fail to re-evaluate them regularly, leaving them operating with outdated or incomplete knowledge.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Bartlett emphasised that agents need a &#8220;death sentence&#8221;&mdash;a routine reassessment of their capabilities, just as humans have performance reviews. She also highlighted a Hack The Box study showing that junior analysts using AI often got trapped in loops when the AI made poor decisions, whereas experienced practitioners knew when to discard an AI&#8217;s output and move on. The lesson: AI fluency requires training, and safe environments where mistakes can be made without real-world consequences are essential.<\/p>\n<h2>The Human Role in an AI-Enhanced Security Team<\/h2>\n<p>As AI agents take over more repetitive tasks, the role of human security professionals is shifting. Bartlett argues that humans will need to direct, oversee, and intervene when AI fails. &#8220;You&#8217;d be crazy not to learn it on some level,&#8221; she said, &#8220;but also understand the good and the bad that goes along with it.&#8221; Organisations that fail to invest in both human skill development and agent appraisal risk losing control of their security posture.<\/p>\n<p>Hack The Box offers hands-on labs where security teams can practice real attack scenarios, as well as capture-the-flag exercises that benchmark team performance. For AI agents, the platform now provides an &#8220;AI competence score&#8221; that measures how well an agent completes tasks and whether it follows proper parameters.<\/p>\n<h2>The Broader Picture: From Clippy to AI Agents<\/h2>\n<p>The juxtaposition of the Microsoft Clippy hack and the interview with Christine Bartlett is not coincidental. Both stories underscore a common theme: cybersecurity is becoming more complex, with threats ranging from low-tech social engineering to high-tech AI-driven attacks. The Clippy incident was a relatively simple account takeover amplified by nostalgia and crypto greed. The rise in social media hijacking shows how attackers exploit human trust for quick financial gain. And the deployment of AI agents introduces new risks of bias, drift, and skill erosion that leaders must proactively manage.<\/p>\n<p>For organisations and individuals alike, the lesson is clear: complacency is not an option. Every month should be Cybersecurity Awareness Month. Whether it&#8217;s checking privacy settings, enabling multi-factor authentication, or regularly testing the AI agents that now share the security team&#8217;s workload, vigilance must be continuous. As Graham Cluley wryly noted on the podcast, the one month of the year we care about cybersecurity should not be followed by 11 months of neglect. The attackers are not taking time off&mdash;and neither should we.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>When a company as large and security-conscious as Microsoft falls victim to a social media hijacking, the cybersecurity community pays attention. The incident that unfolded on Microsoft&#8217;s official Twitter account last Thursday was not just another account takeover&mdash;it was a bizarre, almost nostalgic prank with a sinister financial motive. Hackers seized control of the account, [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":99812,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/99809.png","fifu_image_alt":"Hackers hijack Microsoft Twitter to push Clippy crypto scam","footnotes":""},"categories":[40668],"tags":[],"class_list":["post-99809","post","type-post","status-publish","format-standard","has-post-thumbnail","category-security"],"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/99809.png","fifu_image_alt":"Hackers hijack Microsoft Twitter to push Clippy crypto scam","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/99809","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=99809"}],"version-history":[{"count":2,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/99809\/revisions"}],"predecessor-version":[{"id":99811,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/99809\/revisions\/99811"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/99812"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=99809"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=99809"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=99809"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}