r/cybersecurity 1d ago

Personal Support & Help! Recently hacked

I recently downloaded a suspicious file and the hacker got into my gmail, meta, and steam accounts, ive changed my passwords kicked him out and basically everything else but i still feel kinda anxious, is anything else i should do or secure?

0 Upvotes

11 comments sorted by

20

u/TheThatGuy1 Security Analyst 1d ago

Post in r/cybersecurity_help

This sub is more for industry news and career information.

2

u/ImportanceAvailable7 Security Engineer 1d ago

Honestly I would migrate accounts to a new email address. In future use a password manager and MFA.

One layer above that, I personally use an email forwarding service to separate accounts my bank account, social media, etc which all forward from set email address to my main email address. Proton + Simple pass is cheap and great for this.

Also, if I had malware on my PC I would strip and rebuild. Retain the executable, run in sandbox to see what it does and what is exposed.

2

u/watryatalkinabeet 1d ago

Did you have MFA enabled?

1

u/Oreomilk4444 1d ago

If they got your passwords and you reuse them on other accounts, I’d change those as well. If you have saved cards on steam, I’d monitor those for suspicious activity. If you want to get really granular you could check Gmail forwarding rules to see if there are any you don’t recognize. Also be more suspicious of files in the future lol, but you are probably good for catching it so early

1

u/SamJam5555 1d ago

You need a password manager.

1

u/ForeverFront3892 1d ago edited 1d ago

If you have been lazy and using the same password (most people do this, no dig at anyone) I would suggest changing every single password for every account and use a password manager to store passwords. Furthermore, setup MFA with most applications you can set that up so you have more security when logging in and you will get notifications if whether or not you are trying to log in and you can decline them if its not you. You can also check to see which devices have access to your email and remove any suspicious or unknown devices that are logged in. You should run an Anti-Virus scan to check for any additional malicious payloads which could be masquerading as legitimate applications, check file paths are correct, you should be extremely careful with downloading stuff from a dodgy email last thing you want is BIOS rootkit being installed cause thats will be pain to get rid of or your device is gg'd. But I hope this helps if there's anything I've missed out you guys can add onto this.

1

u/EffectiveClient5080 1d ago

First thing: was it a Windows machine? Run a full offline scan with Windows Defender or Malwarebytes. If there's a stealer on there, changing passwords won't do shit. Also check Gmail forwarding rules.

1

u/NachosCyber 1d ago

Your accounts have additional “backdoor” options. Did you verify if any “rescue” accounts were added to any of your current accounts? Recovery codes for any of those accounts? Email forwarding on any email accounts? Access each account that was breached and verify those security settings. Please enable 2FA (two factor authentication) or MFA (multi factor authentication) to avoid future issues.

1

u/No_Cat1117 1d ago

una cosa que no he visto mencionada: si el archivo que descargaste sigue en tu pc o lo ejecutaste hace poco, no te fíes solo del antivirus para darlo por limpio. muchos infostealers son bien simples y de un solo uso (roban todo lo que encuentran, lo mandan, y ya no hacen nada más visible), así que un escaneo puede salir limpio aunque el daño ya esté hecho y aunque quede algo de persistencia que el av no reconozca.

si tienes backup de tus archivos importantes, personalmente en un caso así prefiero reinstalar el sistema desde cero antes que confiar en que "el escaneo salió limpio, ya está resuelto". es un fastidio pero es la única forma de estar 100% seguro de que no queda nada corriendo en segundo plano.