Microsoft hit by network compromise
Incident
Summary
Hide ▲
Show ▼
Microsoft's official X account was hijacked on Thursday, and attackers used it to post an unauthorized crypto token promotion that could mislead the account's 13 million+ followers. Microsoft said it secured the account and removed the unauthorized posts. The compromise created a public brand-abuse incident with scam and impersonation risk tied to a high-profile corporate account.
Related Happenings
PasteSwitch malicious ClickFix ads campaign via HBO Max Reddit account
Campaign
H score32
First: 21.09.2026 11:39
Last: 21.09.2026 11:39
Sources 1
About this happening:
The PasteSwitch campaign abused HBO Max's official Reddit account (u/hbomax) to push 108 malicious ads over 48 hours, turning a trusted brand channel into a delive...
PasteSwitch malicious ClickFix ads campaign via HBO Max Reddit account
CampaignAbout this happening: The PasteSwitch campaign abused HBO Max's official Reddit account (u/hbomax) to push 108 malicious ads over 48 hours, turning a trusted brand channel into a delive...
ShinyHunters and Helix passkey-themed Microsoft 365 account compromise campaign
Campaign
H score34
First: 11.09.2026 20:26
Last: 11.09.2026 20:26
Sources 1
About this happening:
A ShinyHunters- and Helix-linked campaign is using passkey and SSO-themed social engineering to compromise corporate Microsoft accounts, exposing Microsoft 3...
ShinyHunters and Helix passkey-themed Microsoft 365 account compromise campaign
CampaignAbout this happening: A ShinyHunters- and Helix-linked campaign is using passkey and SSO-themed social engineering to compromise corporate Microsoft accounts, exposing Microsoft 3...
Midnight Blizzard CaptiveCrunch hospitality Wi-Fi phishing campaign
Campaign
H score37
First: 04.08.2026 03:17
Last: 04.08.2026 03:17
Sources 1
About this happening:
Microsoft linked CaptiveCrunch to Midnight Blizzard / APT29, a global operation that abuses hospitality Wi‑Fi to steal Microsoft 365 accounts and deliver malware....
Midnight Blizzard CaptiveCrunch hospitality Wi-Fi phishing campaign
CampaignAbout this happening: Microsoft linked CaptiveCrunch to Midnight Blizzard / APT29, a global operation that abuses hospitality Wi‑Fi to steal Microsoft 365 accounts and deliver malware....
Microsoft Teams OAuth phishing campaign targeting 120 organizations
Campaign
H score30
First: 30.07.2026 15:00
Last: 30.07.2026 15:00
Sources 1
About this happening:
A Microsoft Teams-themed phishing campaign is abusing Microsoft’s legitimate authentication infrastructure to steal OAuth access and compromise corporate accounts...
Microsoft Teams OAuth phishing campaign targeting 120 organizations
CampaignAbout this happening: A Microsoft Teams-themed phishing campaign is abusing Microsoft’s legitimate authentication infrastructure to steal OAuth access and compromise corporate accounts...
Major U.S. services company hit by ransomware attack linked to DragonForce
Incident
H score38
First: 16.06.2026 13:18
Last: 16.06.2026 13:18
Sources 1
About this happening:
A DragonForce ransomware incident hit a major U.S. services firm in December 2025, with attackers maintaining access for one to two months and hiding command-and...
Major U.S. services company hit by ransomware attack linked to DragonForce
IncidentAbout this happening: A DragonForce ransomware incident hit a major U.S. services firm in December 2025, with attackers maintaining access for one to two months and hiding command-and...
Timeline
-
02.10.2026 12:29 2 articles · 2h ago
Microsoft hit by network compromise
Initial DisclosureMicrosoft first confirmed unauthorized access to its X account after attackers used it to post unauthorized crypto promotion content. The company then removed the posts, secured the account, and began investigating the intrusion.
Show sources
- Microsoft’s X account hacked in crypto pump-and-dump scheme — www.bleepingcomputer.com — 02.10.2026 12:29
- Microsoft’s X account hacked in crypto pump-and-dump scheme — www.bleepingcomputer.com — 02.10.2026 12:29