Microsoft's X account: two unauthorised posts, 47 minutes apart by our arithmetic, and no word on the cause
Microsoft says two posts on its X account were not its own: a Clippy quote and a disclaimer. By arithmetic on X's post IDs they sit 47 minutes 31 seconds apart; at 17:12 BST on 5 October Microsoft had not said how the account was taken, and we found nothing from X.
By Parminder Kumar Sharma · · 16 min read

Forty-seven minutes, and what they do not show
Microsoft says two posts on its X account on Thursday 1 October 2026 were not its own. Using the timestamp built into X's post identifiers, we put them at 21:41:51 and 22:29:23 UTC, which is 47 minutes 31 seconds apart (22:41 and 23:29 BST). Several outlets say the account was held for "roughly 30 minutes" without saying from when. The account has 13 million followers, as X's own profile page showed when the Internet Archive captured it that evening.
What that does not establish. It does not say how the account was taken, when each post came down, or when Microsoft regained control. It does not say whether anyone lost money, or who was behind it. It also depends on two inferences, set out in the timeline section: that the identifiers we decoded belong to the two posts, and that the clock inside an X identifier is accurate. We check the second against a time the SEC published in 2024.
The second post matters more than the minutes. It was a disclaimer. It apologised for earlier posts, said Microsoft endorses no cryptocurrency, and ended: "Please rely only on Microsoft's official channels for information regarding our brands, products, securities, and intellectual property." It was published on Microsoft's official channel. A Microsoft spokesperson has since told Windows Latest that neither unauthorised post came from Microsoft, and that includes this one. The advice was sound. The channel that carried it was the compromised one.
What is stated, and what is not
Microsoft's words reach us through reporters. We found no statement published on a Microsoft site, and none from X. The table separates what is on the record from what is not.
What the sources state and do not state about the Microsoft X account hijack. Read between 16:40 and 17:12 BST on 5 October 2026. Wording in quotation marks is the source's own; Microsoft's quotes come via The Verge, BleepingComputer, SecurityWeek and Windows Latest.
- Question
- Was the account taken?
- Stated
- Microsoft: it "confirmed unauthorized access to our account on X including posts that did not come from Microsoft"; the account "has been secured".
- Not stated
- When access ended, or how long it lasted.
- Question
- What was done with it?
- Stated
- The Verge: the account followed a Clippy-themed account, reposted it, and had its profile picture changed. A spokesperson told Windows Latest there were two unauthorised posts: a quote of that account and the disclaimer.
- Not stated
- Whether anything else was done: replies, messages, other edits.
- Question
- How was it taken?
- Stated
- Nothing. Microsoft is "continuing to investigate the circumstances".
- Not stated
- Password, session, phone number, connected app, delegate, support desk, agency: none stated, none ruled out.
- Question
- What did X say?
- Stated
- We found no statement. Coverage says X suspended the impersonating account.
- Not stated
- Whether X support was involved, and how access was returned.
- Question
- Does Microsoft disown the token?
- Stated
- Only in the disclaimer, which says Microsoft has not authorised any token. Microsoft says the disclaimer did not come from it.
- Not stated
- A denial in Microsoft's own words. The statements we read cover the access, not the token.
- Question
- Did anyone profit?
- Stated
- Promoters claimed a liquidity pool worth over $200,000. Reporters say this is unverified.
- Not stated
- Any buyer's loss or seller's gain. No analytics firm report found.
- Question
- Who was behind it?
- Stated
- No one is named.
- Not stated
- Everything.
| Question | Stated | Not stated |
|---|---|---|
| Was the account taken? | Microsoft: it "confirmed unauthorized access to our account on X including posts that did not come from Microsoft"; the account "has been secured". | When access ended, or how long it lasted. |
| What was done with it? | The Verge: the account followed a Clippy-themed account, reposted it, and had its profile picture changed. A spokesperson told Windows Latest there were two unauthorised posts: a quote of that account and the disclaimer. | Whether anything else was done: replies, messages, other edits. |
| How was it taken? | Nothing. Microsoft is "continuing to investigate the circumstances". | Password, session, phone number, connected app, delegate, support desk, agency: none stated, none ruled out. |
| What did X say? | We found no statement. Coverage says X suspended the impersonating account. | Whether X support was involved, and how access was returned. |
| Does Microsoft disown the token? | Only in the disclaimer, which says Microsoft has not authorised any token. Microsoft says the disclaimer did not come from it. | A denial in Microsoft's own words. The statements we read cover the access, not the token. |
| Did anyone profit? | Promoters claimed a liquidity pool worth over $200,000. Reporters say this is unverified. | Any buyer's loss or seller's gain. No analytics firm report found. |
| Who was behind it? | No one is named. | Everything. |
We do not name the token, its accounts, its contract or its site, and we do not link them.
What the two posts said
The Verge published screenshots of both deleted posts. We read them as images; the originals are gone and X requires a sign-in. The first, a quote of a Clippy-themed account, read: "500,000 likes and we bring Clippy back. The ball is in your court." The post it quoted asked how many likes it would take to bring Clippy back. Neither names a token, carries a contract address or links anywhere.
So the token pitch was not on Microsoft's account in anything we could read. It was on a separate account, which claimed a liquidity pool "paired directly with" Microsoft's stock ticker. What Microsoft's account lent was a follow, a quote, a new profile picture and its 13 million followers' trust. The statements from Microsoft that we read cover the access, not the token. The only denial that the token is Microsoft's is in the disclaimer, which Microsoft says it did not write.
The disclaimer is the odd one. It says the token "is not Microsoft stock" and that Microsoft will "pursue appropriate legal action", in the register of a real communications team. Who wrote it, and why, is not stated.
The minutes, and how we got them
X's developer documentation says every post identifier is a 64-bit "Snowflake" number that encodes the creation time. The page does not print the epoch. We used the one the Snowflake scheme has always used, 1,288,834,974,657 milliseconds after the Unix epoch, and tested it against the SEC. The SEC's account of the January 2024 hijack of its own X account says staff posted a warning from another official account at 4:26 pm ET on 9 January. An identifier that BleepingComputer links on that account decodes to 21:26:30.984 UTC, which is 4:26 pm ET. The method agrees with the SEC's clock.
The first post. The Crypto Times, which is secondary, links the quote post by address. That identifier decodes to 21:41:51.867 UTC. We could not open it: the post is deleted.
The second post. The Internet Archive's index lists four status addresses under the account's name, each recorded as a 404. They decode to 21:23:31, 21:38:46, 21:41:51 and 22:29:23 UTC. We take the last to be the disclaimer, for one reason. The Verge's screenshot of the disclaimer reads "20m", and the screenshot's own filename carries a time of 3.49.34 PM. If that machine was on Pacific Daylight Time, it is 22:49:34 UTC, which is 20 minutes 11 seconds after 22:29:23. Pacific Daylight Time is the zone in force on the US west coast that day, and any zone further east would put the screenshot before the post existed. That is an inference. We cannot say what the two earlier identifiers were; Microsoft counts two unauthorised posts.
The profile. The Archive captured the account's profile page at 22:13:42 UTC, about 32 minutes after the quote post. It shows 1,097 accounts followed. A capture on 18 August shows 1,096, and one at 22:55:25 UTC on 2 October shows 1,096. That is consistent with the reported follow still being in place at 22:13 and undone later. It is not proof.
The 404. At 22:57:25 UTC the Archive recorded the disclaimer's address as not found. A crawler can be refused a post for reasons other than deletion, so we read it as "not served by then", not "deleted at".
So how long? The Verge wrote that the posts were removed and that the disclaimer appeared "around 30 minutes later". Outlets that repeat "roughly 30 minutes" as the length of the hijack drop that starting point; one says the account was "under outside control for roughly half an hour". On the arithmetic, the two posts are 47 minutes 31 seconds apart, and the account was in unauthorised hands for at least that long, because a follow and a quote come before the second post. When the first post came down is not on the record. The scam outlived the hijack: a second Clippy-themed account, not Microsoft's, was still posting about the token at 04:55 UTC on 2 October, 7 hours 13 minutes after the quote post, going by the identifier in a link that crypto.news publishes.
For comparison, The Verge's first report is stamped 23:04:38 UTC, 1 hour 22 minutes 46 seconds after the quote post, and its update carrying Microsoft's statement is undated. The SEC wrote down its own 2024 timeline: first unauthorised post at 4:11 pm ET, a warning on a second official account at 4:26 pm ET, 15 minutes later, and access ended between 4:40 and 5:30 pm ET, 29 to 79 minutes after the first post.
A gold tick says whose account it is, not who is typing
X's help page says "The gold checkmark indicates that the account is an official organization account through Premium Business." The blue checkmark, it says, means an active Premium subscription, for an individual or an organisation. In The Verge's screenshots, Microsoft's account carries the gold badge and the Clippy-themed account carries the blue one. Both labels were accurate. The gold one answered "whose account is this?" correctly throughout the 47 minutes. It never answered "who is typing?".
This is the friendly-name fallacy in its plainest form. The label is an identity claim about the account, and an attacker with the account inherits it. The disclaimer shows the next step: a rule that anything posted from the account is an official statement makes the account worth taking, and makes a forged statement from it worth more than a forged statement from anywhere else. X's own documentation puts the responsibility where it lands: "Account owners are responsible for the content posted to their accounts by authorized admins and contributors."
The control is therefore not the badge. It is the credential and session security behind the label, the short list of people and apps allowed to act through it, and a second channel that followers can use to check what the first one says.
Five ways in, one named in 2026, none named for Microsoft
Microsoft has not said which route was used. The table lists the routes the record documents elsewhere. Its right-hand column reads "Nothing" on purpose.
Routes to an organisation's X account, with what the record shows elsewhere. Sources: X help pages, the SEC's account of its January 2024 incident, a Reuters report of 28 July 2026, SecurityWeek's list of options. Read 5 October 2026.
- Route
- Password or phishing
- Documented elsewhere
- X says accounts are compromised through a malicious app or site, a weak password, malware or a compromised network.
- Said about Microsoft
- Nothing.
- Route
- Stolen session
- Documented elsewhere
- X says changing a password does not log out its mobile apps; sessions must be ended separately. SecurityWeek lists infostealer cookie theft as an option.
- Said about Microsoft
- Nothing.
- Route
- Phone number and SMS code
- Documented elsewhere
- SEC 2024: the phone number was taken in a SIM swap; MFA had been disabled by X Support at staff's request in July 2023. X's help page says it stopped supporting SMS codes for non-Premium accounts from 20 March 2023.
- Said about Microsoft
- Nothing.
- Route
- Connected app or delegate
- Documented elsewhere
- X: apps with write access can post, follow and edit the profile. Delegates keep access when the owner changes the password.
- Said about Microsoft
- Nothing.
- Route
- Support desk
- Documented elsewhere
- Robinhood's chief executive, 28 July 2026 (Reuters): "A fraudster socially engineered X customer support to gain access, bypassing standard security features like 2FA and login notifications".
- Said about Microsoft
- Nothing.
| Route | Documented elsewhere | Said about Microsoft |
|---|---|---|
| Password or phishing | X says accounts are compromised through a malicious app or site, a weak password, malware or a compromised network. | Nothing. |
| Stolen session | X says changing a password does not log out its mobile apps; sessions must be ended separately. SecurityWeek lists infostealer cookie theft as an option. | Nothing. |
| Phone number and SMS code | SEC 2024: the phone number was taken in a SIM swap; MFA had been disabled by X Support at staff's request in July 2023. X's help page says it stopped supporting SMS codes for non-Premium accounts from 20 March 2023. | Nothing. |
| Connected app or delegate | X: apps with write access can post, follow and edit the profile. Delegates keep access when the owner changes the password. | Nothing. |
| Support desk | Robinhood's chief executive, 28 July 2026 (Reuters): "A fraudster socially engineered X customer support to gain access, bypassing standard security features like 2FA and login notifications". | Nothing. |
The actions Microsoft's account took, a follow, a quote and an avatar change, are all things a connected app could do, and all things a stolen session could do. They do not point to a route.
The fifth row is the uncomfortable one. It is the only 2026 case in which the account holder has said how access was gained, and the route went round the login, not through it. A hardware key or passkey addresses most of the first and third rows, phishing and SMS interception. It does not stop a stolen session or a connected app, and it does not touch the support desk, which is a recovery route the organisation does not run. The GOV.UK One Login passkeys briefing describes the same shape: a strong login with a weaker route kept open beside it. On the first row, the EvilTokens takedown briefing covers a phish that MFA cannot stop.
X offers three two-factor methods, a text message, an authentication app or a security key, and says "Security keys can be used as your sole authentication method". Passkeys are "highly encouraged" but "not required for login". The NCSC's corporate guidance ranks FIDO2 credentials first and message-based methods last, calling them "only likely to be appropriate when no other strengthening method is possible".
The money, and the other accounts
On-chain. We found no report from a blockchain analytics firm on this token. The only liquidity figure is the promoters' own claim of a pool worth over $200,000, which reporters call unverified. One crypto news site says $3 million was drained in minutes and cites no firm; it also gives the follower count as 16.5 million, against the 13 million on the account page, and says Microsoft had issued no statement. We do not rely on it. For contrast, in the July SpaceXAI and Starlink hijack, Lookonchain's figures were quoted by Crypto Briefing: 10 trillion tokens minted and sold for about 73.7 ETH, roughly $125,000. Nothing comparable exists here, so whether anyone profited, and how much, is not established.
Other brands. Searching public reporting on 5 October, we found no other brand account hijack between 1 and 5 October. The nearest in 2026 are the SpaceXAI and Starlink accounts on Sunday 12 July, 81 days before, and the Robinhood chief executive's account on Thursday 23 July, 70 days before. Microsoft's own India account was hijacked in June 2024, according to BleepingComputer. That makes Microsoft the third large hijack of 2026 in this pattern that we can name. Of the three, we found a stated route only for the Robinhood executive's.
For UK brand and executive accounts: the order worth doing
This is for communications and security teams who hold brand, product, regional and executive accounts. The NCSC's guidance and X's help pages are the sources. The order is ours: an account that is not listed cannot be secured, so the inventory comes first.
Take this with you
Nine actions, in order
- Inventory every brand, product, regional and executive account on every platform. For each, record who holds the login, which email and phone number recover it, and which apps, agencies and delegates can post.
- Name an owner and a deputy for each account, and write down who may say "this is an official statement". The NCSC asks for access to be revoked promptly when people leave or change roles.
- Move every login to a hardware security key or passkey. Remove SMS codes where the platform lets a key stand alone, as X's help page says it does.
- Remove unused connected apps and agency delegations. On X, check Apps and sessions, end all other sessions, and review Delegate roles. Only the owner controls the password, phone number and login verification, and delegates keep access when the password changes.
- Put recovery email and phone numbers on an admin-held mailbox and line, not a person's. The NCSC says to know how to reach recovery information and keep it current.
- Ask each platform in writing what its support desk requires before it changes the login method, email or phone on a brand account, and record the answer. The one 2026 case that names its route was a support desk.
- Write the incident runbook: tested platform escalation contacts, a pre-approved holding statement published from a different channel, and a 15-minute decision rule. At 15 minutes after a confirmed unauthorised post, the owner escalates to the platform and publishes the holding statement, without waiting for the cause. The SEC took 15 minutes in 2024. The NCSC says the priority "should be regaining control of the account to contain any damage".
- Treat anything posted from a compromised account as untrusted, including a correction. Microsoft says its disclaimer was not its own.
- Monitor for what the Microsoft incident showed: an unexpected follow, a quote of an account you do not know, a changed profile picture, and your brand name beside words like token or airdrop. Switch on access logging where the platform offers it, as the NCSC advises, and rehearse the runbook at an awkward hour. These posts went out at 22:41 and 23:29 BST on a Thursday.
What the FCA page says about a hijacked account: nothing
The FCA's page for cryptoasset firms marketing to UK consumers was last updated on 6 February 2026 ("System update no content change"). It says the definition of a financial promotion is broad and covers social media posts, that the regime is "technology neutral", and that a promotion not made through one of its four routes breaches section 21 of the Financial Services and Markets Act 2000, a criminal offence carrying up to two years in prison, an unlimited fine, or both. It also says the FCA expects social media companies to have effective systems and controls to detect and remove illegal promotions.
It does not mention a hijacked account. It does not say whether a post written by an attacker is a communication by the account holder, or whether a follow, a quote or a changed profile picture counts as a promotion. Neither unauthorised post we could read invited anyone to buy anything. The CAP advice page for the ASA, dated 25 March 2026, adds only that since 8 October 2023 the FCA regulates advertising of qualifying cryptoassets and the ASA no longer regulates the technical claims in non-broadcast ads for them.
What we could not verify
The archived copies. BleepingComputer links two archive.ph and archive.li captures. The first would not connect from this machine and the second presented a CAPTCHA, which we did not attempt. We used the Internet Archive and The Verge's screenshots instead.
The posts and their identifiers. Both posts are deleted and X requires a sign-in, so we read their text from The Verge's screenshots. The quote post's identifier comes from a link in a secondary source; the disclaimer's is inferred from a screenshot time zone; two earlier identifiers are unidentified. The time Microsoft's statement reached The Verge is undated.
The cause, X's account of events, and the money. None is stated, found, or published by an analytics firm.
The question this leaves
If an attacker held your brand account at 22:41 on a Thursday, which channel would your followers use to check whether the last post was yours, and who in your organisation holds the login to it?
Key facts
Sources
- PrimaryCDX index query for captures under x.com/Microsoft between 29 September and 6 October 2026: the four status addresses recorded as 404, with their capture times, and the profile captures used for the timelineInternet Archive (Wayback Machine)accessed 2026-10-05
- PrimaryCapture of the @Microsoft profile page at 22:13:42 UTC on 1 October 2026: 13M followers, 1,097 following, 31.1K postsInternet Archive (Wayback Machine)accessed 2026-10-05
- PrimaryCapture of the @Microsoft profile page at 22:55:25 UTC on 2 October 2026: 13M followers, 1,096 followingInternet Archive (Wayback Machine)accessed 2026-10-05
- PrimaryCapture of the @Microsoft profile page at 13:33:52 UTC on 18 August 2026: 1,096 following, the baseline before the incidentInternet Archive (Wayback Machine)accessed 2026-10-05
- PrimaryX IDs documentation: post identifiers are 64-bit Snowflake numbers that encode the creation timestamp; used for the timeline arithmeticX Developer Platformaccessed 2026-10-05
- PrimaryThe SEC's own page on the January 2024 hijack of @SECGov: the SIM swap, MFA disabled by X Support in July 2023, the 4:11 pm, 4:26 pm and 4:40 to 5:30 pm ET times; used to test the identifier clock and as a timing benchmarkU.S. Securities and Exchange Commissionaccessed 2026-10-05
- PrimaryTwo-factor authentication: text message, authentication app or security key; security keys as sole method; SMS codes withdrawn for non-Premium accounts from 20 March 2023X Help Centeraccessed 2026-10-05
- PrimaryPasskeys: encouraged, not required for loginX Help Centeraccessed 2026-10-05
- PrimaryThird-party apps and log in sessions: what apps with read and write access can do, and how to end sessionsX Help Centeraccessed 2026-10-05
- PrimaryDelegate: owner, admin and contributor roles; delegates keep access when the password changes; owners are responsible for what delegates postX Help Centeraccessed 2026-10-05
- PrimaryHelp with my compromised account: the recovery steps and how X says accounts become compromisedX Help Centeraccessed 2026-10-05
- PrimaryProfile labels and checkmarks: gold means an official organisation account through Premium Business; blue means an active Premium subscriptionX Help Centeraccessed 2026-10-05
- PrimarySocial media: protecting what you publish: 2-step verification, access logging, leavers and movers, corporate devices, the emergency recovery plan and the priority of regaining controlNational Cyber Security Centreaccessed 2026-10-05
- PrimaryRecommended types of MFA: FIDO2 first, message-based methods lastNational Cyber Security Centreaccessed 2026-10-05
- PrimaryCryptoasset firms marketing to UK consumers, last updated 6 February 2026: the four routes, section 21 FSMA, social media promotions; the page does not mention hijacked accountsFinancial Conduct Authorityaccessed 2026-10-05
- PrimaryFinancial products and services: Cryptoassets, dated 25 March 2026: the FCA took over regulation of qualifying cryptoasset ads on 8 October 2023Advertising Standards Authority and CAPaccessed 2026-10-05
- PrimaryCryptocurrency investment fraud page, reached by redirect from the Action Fraud address, read with a browser; the number for organisations under cyber attackReport Fraud (formerly Action Fraud)accessed 2026-10-05
- Reported byFirst report, posted 23:04:38 UTC on 1 October 2026, with screenshots of the quote post and the deleted disclaimer, and Microsoft's statement; the disclaimer text was read from the screenshotThe Vergeaccessed 2026-10-05
- Reported byThe pointer article of 2 October 2026, updated 3 October with Microsoft's clarification that it did not post the apology; links the archive captures we could not openBleepingComputeraccessed 2026-10-05
- Reported byReport of 2 October 2026, updated 3 October: Microsoft's statement, the apology was unauthorised, and the list of possible routesSecurityWeekaccessed 2026-10-05
- Reported byMicrosoft spokesperson to Windows Latest: two unauthorised posts, the quote and the apology, neither from MicrosoftWindows Latestaccessed 2026-10-05
- Reported byUpdate stamped 9:27 ET on 5 October 2026 confirming that both the quote and the disclaimer were unauthorisedWindows Centralaccessed 2026-10-05
- Reported byLinks the quote post by address; the identifier decodes to 21:41:51 UTC. Secondary and not independently confirmedThe Crypto Timesaccessed 2026-10-05
- Reported byThe promoters' claimed liquidity pool of over $200,000 and the link whose identifier decodes to 04:55 UTC on 2 Octobercrypto.newsaccessed 2026-10-05
- Reported byReuters wire of 28 July 2026 quoting the Robinhood chief executive: a fraudster socially engineered X customer support, bypassing 2FA and login notificationsReuters, via WTVBaccessed 2026-10-05
- Reported byDate of the Robinhood chief executive's account compromise: Thursday 23 July 2026CoinDeskaccessed 2026-10-05
- Reported bySpaceXAI and Starlink hijack of Sunday 12 July 2026, with Lookonchain's figures as quotedCrypto Briefingaccessed 2026-10-05
- Reported byReport of 2 October 2026: the 2026 sequence of hijacks and the $200,000 liquidity claimBitcoin.com Newsaccessed 2026-10-05


