On Thursday, Microsoft’s official account on X, boasting over 13 million followers, fell victim to a security breach that saw it promoting a Clippy-themed cryptocurrency token. The company has acknowledged the unauthorized access, promptly removed the misleading posts, and is currently investigating the incident.
During the hijack, the account followed a Clippy-themed profile, @clippymsftcto, which had shared a nostalgic image of Clippy against the iconic Windows XP Bliss wallpaper, asking, “HOW MANY LIKES TO BRING CLIPPY BACK??” In a bizarre twist, the compromised account responded with, “500,000 likes and we bring Clippy back. The ball is in your court.” These posts were swiftly deleted, along with a peculiar “apology” that appeared approximately 30 minutes later.
Microsoft got hacked, and Clippy became the bait
Microsoft confirmed that the posts did not originate from them. A spokesperson stated, “We have confirmed unauthorized access to our account on X, including posts that did not originate from Microsoft. The account has been secured, the unauthorized posts have been removed, and we are continuing to investigate the circumstances.” The Clippy-themed account has since been suspended, but another account continued to promote a $Clippy token, falsely claiming a connection to Microsoft’s stock.
The deleted “apology” from the hijacked account asserted that Microsoft does not support or endorse any cryptocurrency token linked to Clippy or its brand. The company indicated it would pursue legal action to eliminate the token and related materials. Interestingly, the tone of the apology raised eyebrows, leading many to suspect it was not authentically from Microsoft.
Indeed, a Microsoft spokesperson later confirmed that both the Clippy-related post and the subsequent apology were unauthorized. The incident highlights a curious reality: despite the chaos of a crypto scam, the internet’s collective nostalgia for Clippy remains strong. In a recent post by Satya Nadella discussing Copilot, a user simply remarked, “Can you just stop and bring back Clippy at this point.”
Clippy, introduced as the default Office Assistant in Office 97, became a cultural icon, often referenced in jokes and nostalgia. Despite being phased out in Office 2007, the character’s legacy endures, symbolizing a simpler time in user assistance—ironically known for interrupting users with unsolicited advice.
Microsoft says AI can find scammers, but maybe it should secure its own accounts first
In a related context, Microsoft’s Digital Crimes Unit recently disrupted EvilTokens, an AI-driven cybercrime service linked to a significant number of compromised accounts across various organizations. While the company has taken strides to combat AI-fueled cyber threats, the breach of its own social media account raises questions about its internal security measures.
While the nature of these security challenges may differ, the incident underscores a vulnerability that has previously affected Microsoft, as seen when the Microsoft India account was hijacked for a crypto scam in 2024. The question remains: should Microsoft consider reviving Clippy, a character that resonates with many, or focus on rebuilding trust with its users?
As Microsoft continues to promise enhancements for Windows, recent updates have sparked confusion and frustration among users. The goal should transcend merely bringing back a nostalgic mascot; it should involve creating products that foster lasting positive memories. Currently, neither Windows 11 nor Copilot seems to evoke that sense of nostalgia.