Threats & Adversaries · Financial Fraud

Microsoft X Account Hijack Fueled a Crypto Scam

Microsoft’s official X account was hijacked on Thursday and used to promote a crypto token in what BleepingComputer described as a pump-and-dump scheme. The account has more than 13 million followers, which made the post a far louder delivery channel than a normal scam account could manage.

The trick was trust borrowing: attackers did not need to build an audience, because they posted from Microsoft’s own account and let the brand’s authority do the work. That kind of takeover can move money quickly, because the fraud looks company-authored long enough for followers and markets to react before the post is removed.

For organizations that use high-reach social accounts as part of their customer trust, the exposure is not just reputational. A hijacked account can become a fraud amplifier in minutes, and the damage can outlast the account recovery if people already acted on the post.

2 sources · 6h ago

Timeline

Sources

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-10-02

Every edition of this story: Microsoft X Account Hijack Fueled a Crypto Scam

More from today