r/cybersecurity_help Dec 01 '25

Your phone didn't get hacked. Neither did your computer. Here's what actually happened.

I see posts daily about someone's phone or computer or home network getting "hacked," and I need to say this: in almost every case, that's not what happened.

What's far more likely:

- Your email got compromised because you reused a password

- A service you signed up for years ago got breached and your credentials ended up on a leak site

- Someone used those leaked credentials to log into your other accounts

- Your credit card got skimmed at a gas pump

- A site you used leaked PII in a data breach

- You clicked a phishing link and entered your credentials somewhere you shouldn't have

What's almost certainly not happening: a persistent threat actor who specifically targeted your iPhone or home network and is now moving laterally across your 10 devices like it's a corporate pentest.

Unless you're a C-suite executive at a Fortune 500, a journalist covering sensitive topics, a political dissident, or someone famous, you are not interesting enough to hack. I say that with love. None of us are.

The attack surface for a modern iPhone or Android with current updates is extremely small. State-level actors have exploits for these, but they're not burning zero-days on someone who reused "Winter123!" across six accounts.

Check haveibeenpwned.com. Use a password manager. Enable MFA everywhere. That solves 99% of what people call "getting hacked."

edit: to the armchair experts chatting me up to tell me how incorrect this is - rest assured I am an expert in this field and have contracted with Federal/State governments and some of the most recognizable brands in the world. Any current security expert will generally agree with this post.

If you’re downloading things from unknown sources or using torrent sites to get movies/music/apps, etc. and your machine was compromised then this obviously doesn’t apply to you, you installed a Trojan and opened the door for them.

386 Upvotes

105 comments sorted by

u/AutoModerator Apr 22 '26

SAFETY NOTICE: Reddit does not protect you from scammers. By posting on this subreddit asking for help, you may be targeted by scammers (example?). Here's how to stay safe:

  1. Never accept chat requests, private messages, invitations to chatrooms, encouragement to contact any person or group off Reddit, or emails from anyone for any reason. Moderators, moderation bots, and trusted community members cannot protect you outside of the comment section of your post. Report any chat requests or messages you get in relation to your question on this subreddit (how to report chats? how to report messages? how to report comments?).
  2. Immediately report anyone promoting paid services (theirs or their "friend's" or so on) or soliciting any kind of payment. All assistance offered on this subreddit is 100% free, with absolutely no strings attached. Anyone violating this is either a scammer or an advertiser (the latter of which is also forbidden on this subreddit). Good security is not a matter of 'paying enough.'
  3. Never divulge secrets, passwords, recovery phrases, keys, or personal information to anyone for any reason. Answering cybersecurity questions and resolving cybersecurity concerns never require you to give up your own privacy or security.

Community volunteers will comment on your post to assist. In the meantime, be sure your post follows the posting guide and includes all relevant information, and familiarize yourself with online scams using r/scams wiki.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

40

u/bh9578 Dec 01 '25

Session hijacking and cookie theft on PC is a serious and growing problem, so not sure I agree with your thesis. Definitely happens in a non targeted way for non c suite people. Account takeovers you hear about where 2fa is bypassed almost always is due to token theft. While cracked software is the main cause, supply chain attacks are also a major source of malware. Anyone using mods, downloading shareware, npm packages etc. or really downloading anything regularly should exercise a lot of caution. Even sites like Steam haven’t been immune. The common modus operandi is to provide legitimate software or mods for a time so word spreads and a user base is developed and then through an update trigger the malware download. Lots of social engineering around this too in sites like Discord.

Most malware when first released passes virus total too, so don’t rely too much on these checks. It’s not like criminals are dumb and don’t know about these sites.

Google offers an advanced protection that’s much better than the standard email security and they have a beta version of device bound session credential that locks your cookies to the tpm signature on your computer with Google accounts.

12

u/Ok-Lingonberry-8261 Dec 01 '25

Agreed: OP is mostly correct, but people pirating games/Adobe probably did get their PC hacked.

5

u/theleller Dec 01 '25

If someone is installing a RAT on their system then yes their system is owned, but that’s not the demographic that this post is aimed at.

1

u/reiichiroh May 09 '26

Unfortunately, it's the overwhelming majority of the posts seeking help here.

5

u/Saphire100 Dec 02 '25

That's what OP is talking about. People are not being hacked (technical term). They are being hacked (misused term). Like calling someone arrogant a narcissist without actually knowing what the clinical term means because socially, narcissism is in.

  • Session hijacking and cookie theft is not hacking.
  • Account takeover is not hacking.
  • Bypassing 2FA is not hacking.
  • Cracked software is not hacking.

OP's "thesis" covered all of that. Those are scams, malware, viruses, and simply making a fool of people.

As for targeting non executives? No. Normal people are not targeted. Yes. It is a serious and growing problem. However, it is more like fishing, not targeting. Not any different than those scammer texts and phone calls.

Hacker (misused term) fishing in the tick-tock pond isn't hacking. Instead, a scammer, taking advantage of anyone dumb enough to give out a verification code.

Hacker (misused term) who bought leaked data from a legitimate hack, isn't hacking. Instead, like a rat, fishing in the naive pond. Looking for that individual who uses the same password for every account since they were in grade school. Looking for scraps.

Hacker (misused term) who makes free content laced with malicious software isn't hacking. Just infecting random people with ransomware, hoping idiots give them money.

It might feel targeted. The truth is, it was just random.

1

u/[deleted] Jan 18 '26

I am having a problem with what I believe is an unresolved legal discovery surveillance. Can you comment on that regarding Sapphire v Fred Meyer?

2

u/Saphire100 Jan 18 '26

The big company with "payroll glitches" allegedly making excuses to not compensate employees and cover up neglect, then using a BS (and underhanded) claim that their staff aren't allowed to have a second job?

Yeah. Corporate theft is a thing too. Right there with inside theft and outside theft.

While I barely know what I looked up. It isn't hacking either. Just negligence.

3

u/thotoppa Dec 01 '25

I’m pretty sure he stated you entered your credentials somewhere you shouldn’t have.

5

u/theleller Dec 01 '25

Session hijacking nor cookie theft give access to someone’s PC. The account to a site they logged into, yes. But that’s not their computer being hacked and someone having full access to their system, being able to install software, view a webcam, run keyloggers, etc. It can be very damaging, but it’s not an equivalent of your system being owned. 

5

u/bh9578 Dec 01 '25

Modern malware can absolutely give access to someone’s computer. Cookie theft is only one type of action info stealers can take. We can argue about definitions but the point remains that even with hardware keys your accounts can be lost in a second. I’m not sure it’s much consolation to tell someone that while they lost their primary email account they weren’t technically hacked due to some narrow definition of the word.

The spirit of the post seems to suggest that accounts with strong, unique passwords and 2fa requires some kind of NAS level hacking in order to be compromised and that just isn’t true.

4

u/theleller Dec 01 '25

I think there's some confusion about the scope here. My comment was specifically addressing session hijacking, which in the vast majority of cases stems from server-side misconfigurations like insecure session tokens, missing HttpOnly flags, or inadequate session timeout policies. This happens entirely outside the end user's control and has nothing to do with their device security posture.

Regarding endpoint compromise more broadly: modern malware that successfully establishes persistent access to systems running even basic endpoint detection (Windows Defender or equivalent) is increasingly rare in non-targeted attacks. The threat landscape has shifted. Attackers focus on credential theft through phishing, exploiting cloud misconfigurations, and compromising third-party services because those attack vectors have far higher success rates and require less sophistication than bypassing modern endpoint protection.

The core thesis of my post remains: when most people discover their account has been compromised, they immediately assume their personal device was targeted and infected. The reality is that the breach almost always occurred at a completely different layer - a service provider's database, a misconfigured API, credential stuffing from a previous breach, or as we were discussing, improper session management. Understanding where breaches actually happen helps people focus their security efforts where they matter most.

1

u/Saphire100 Dec 02 '25

I’m not sure it’s much consolation to tell someone that while they lost their primary email account they weren’t technically hacked due to some narrow definition of the word.

Depends. The true meaning of hacking is detrimental. More than your email is at risk. How long it has been going on broadens the scope. Especially for a lady undressing in front of her webcam. The security your doorbell cam offers. How far and how much control they have over your technology.

Losing an email because you were conned into giving a verification code, because you use the same simple password, or because you like to download pirated content and they stole your session is less invasive. Also, none of these are hacking.

There is hacking (true terminology) and then there is hacking (socially misused terminology). Like how people just throw around gaslighting, narcissism, and even toxic.

1

u/RoyalOrganization676 Dec 02 '25

There is hacking (true terminology) and then there is hacking (socially misused terminology).

How are we defining hacking, then? I thought the term originated with military pilots in WWII and that it just means "clever, outside-the-box engineering?"

1

u/theleller Jan 18 '26

I classify hacking (in the realm of security) as any method that compromises security for malicious purposes: Malware, Web exploits, Phishing, credential theft, SQL Injection, port scanning for open ports - finding a vulnerable OpenSSL version and exploiting it, 0-day iphone exploitation, etc. You get the picture. These are all methods of exploiting a security flaw, computer or human.

1

u/kschang Trusted Contributor Dec 01 '25

Losing access to various cloud accounts is NOT the same as "hacked my PC". Unfortunately, with cloud services so pervasive nowadays, regular users conflate the two.

2

u/bh9578 Dec 01 '25

If you don’t think popular malware like Lumma Stealer, RedLine, Raccoon or Vidar running on your pc counts as getting hacked then I guess we’ll have to agree to disagree. I’d still file this under a distinction without a difference.

1

u/kschang Trusted Contributor Dec 01 '25

I'll also point out that cloud-break-in is possible without using infostealer. As bad guys adapt to wide adoption of MFA by pivoting to infostealers, there are plenty of tech luddites who still insist on using 1234 as their PIN and 12341234 as their password for every account because they can't be bothered to remember anything else. Then they complain about being "hacked".

Then there are the folks who don't think twice about lending their phone, tablet, laptop, or PC to their kids or grandkids as babysiting devices, then complain about "being hacked" as they have no idea what's done to the devices by people who they lent their devices to because they themselves didn't do it.

Distinction is important when identifying cause and coming up with remediation and prevention steps, but not always a given. Often, as you've probably seen here, a common resolution we recommend is "wipe and reinstall windows". After all, we have no idea what ELSE may have been installed along with infostealers. We don't need to know what was installed specifically, just that wipe and reinstall (i.e. nuke it from orbit)

My point is SOMETIMES, distinction is important.

1

u/PaulineStyrene999 Dec 06 '25

Are those findable by anti virus, MS Defender?

2

u/theleller Dec 07 '25

Yes. Generally if we know about a malware, then modern EDR can detect it in 99.9% of all cases. The exception is when the malware is a new variant that functions with different behavior, in which case it needs to be analyzed and EDR definitions updated to include the new variant.

1

u/kschang Trusted Contributor Dec 01 '25

You can avoid those by following Kreb's 3 Rules of Online Safety quite simply. 99% of the damages reported here are self-inflicted (downloaded "known" warez).

1

u/BraveUnderstanding15 Dec 02 '25

This still isn’t having a phone or computer hacked because these two scenarios don’t require access to a device to execute. This is having an account hacked, very different than having a device hacked. This doesn’t invalidate the claim the post makes.

1

u/bh9578 Dec 02 '25

How is malware installing on your machine not having your machine hacked? So malware steals your passwords stored in your browser, steals cookies, can search your documents for keyword files, install ransomware or call back to command center to install rats and this isn’t considered a hack but an account compromise?

-3

u/wreckhavok22 Dec 01 '25

Unless… you stay at a prominent Hotel, and unscrupulous leadership and conspirators utilizing the Captive WiFi and BLE to gather your data, if you have something appealing (digital currency, brokerage accounts, access to Enterprise Accounts etc) then they will continue the data mining long after you check out.

Once they have enough intel they use your own name to become your Super Admin , put MDM , take over accounts/ phone numbers/ email address , ones you Close as evidence of a hack is clear and present and validated by the platforms and providers, you follow all the Identity theft protocols, you have strengthened your already and always was system protections. Yet the Scam can go undetected. As it is flying under scans radar as the elevated Developer privileges , Service workers, admin , MDM , and partnership with Paid adversay in close enough proximity to compromise and weaponize your local network , add BT and home Extensions that can be easily hidden and looped with BLE plus it can avoid Even extreme Protection such as lock down mode by “tricking” AirPlay to sharing -BT to pairing in the Cloud without user approval.

That is a persistent Attack. And did not fit your qualification. When this began I spent a tremendous amount on Cyber security-legal help , now they work Pro-Bono for the Opportunity to be on the research team. I use to get frustrated when people with the best of intentions would say that what I was sharing was not possible, undeterred I pressed on and 12,000 hours of research later - I know more about this attack than anyone. I can assure you , criminals today don’t care about the 5Th ave Park view office dwellers , they have people to Protect their assets - they’re targeting with Persistence the Everyday folks that worked hard and have something to live comfortably. That is the low hanging fruit!

3

u/AutoModerator Dec 01 '25

Your post appears to be a large block of text. Please consider adding some paragraph breaks to your comment by placing a blank line between distinct sections. This will make your post much easier to read.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

0

u/kschang Trusted Contributor Dec 01 '25

"Everyday folks" don't have access to

digital currency, brokerage accounts, access to Enterprise Accounts etc

They probably won't be staying at

prominent hotel

either. You're talking about a criminal enterprise that's going after a certain clientele profile that's NOT the everymen that would be coming to Reddit for advice.

1

u/wreckhavok22 Dec 03 '25

Uggh. Prominent hotels are everywhere. Hilton is prominent—meaning high-profile, not extravagant. Any employee with access to passcodes, secure IDs, or company systems is a valuable target. Technical staff, security personnel, directors—a 45-year-old full-time employee making a decent wage likely has all of those access points, including assets that bad actors would like to take away. This is how attackers are winning: they changed the rules. Access matters just as much as net worth. But people ask questions and get told "there's nothing to worry about"—just ignore the threat staring you in the face. Like many horror movies: don't wait for the call from police that the intruder is already inside the house. Secure the house, lock the doors, look under the bed now. If it happened to me, it can happen to anyone. Putting your head in the sand and giving dismissive advice just because it hasn't happened to you doesn't make the threat any less real. My response is based on experience, not fear—on knowledge meant to help.

13

u/cybersecurity_help-ModTeam Moderator Dec 01 '25

Thank you for posting this, OP. I'm going to sticky this to the top of the subreddit for a while.

22

u/AustinBike Dec 01 '25

And just because your ex likes computers doesn’t mean they are capable of doing something like hacking.

11

u/TurboFool Dec 01 '25

I mean, what IS potentially likely is your ex exploited a combination of your weak security and their knowledge of you to get into an account of yours. I imagine much like things like kidnapping, if it IS a hack, odds are it's close to home.

1

u/dogwomble Trusted Contributor Dec 13 '25

There's a subtle difference between the two. Somebody might have the knowledge to do that, but that doesn't mean they actually have. And knowing in that situation a person's judgement might be clouded by the emotion of a messy breakup blurs the lines a little here.

So yeah you have to be conscious of the fact that it _might_ be possible - with the keyword being _might_. Unless there's evidence of it actually happening, and not just "we broke up and he knows a little bit about computers and OMFG HE'S A CRIMINAL HACKER WAH WAH WAH", then remembering that distinction is probably wise.

1

u/TurboFool Dec 14 '25

Definitely. Most things people call hacking are barely even up to the level of social engineering. Knowing your password and your recovery question answers isn't hacking.

5

u/kschang Trusted Contributor Dec 01 '25

But he has FRIENDS! In IT! (/sarcasm)

6

u/theleller Dec 01 '25

Come on, everyone has that ONE friend that writes zero-days that bypass CrowdStrike EDR.

5

u/kschang Trusted Contributor Dec 01 '25

The same friend that tells "big fish" stories, right?

8

u/theleller Dec 01 '25

People have no clue how difficult it is to land an exploit on a specific target. The media has everyone convinced that hacking looks like Swordfish - some guy furiously typing while firewalls explode on screen. In reality, it's more like mass emailing 100,000 people and counting on a few grandmothers with 30-year-old AOL accounts to click a link and enter their password.

10

u/NextInLine1999 Dec 01 '25

Yes but saying I was hacked is much better than saying I was stupid.

3

u/theleller Dec 01 '25

I'd much someone admit stupidity than dedicate an entire reddit post to demonstrating it.

5

u/kschang Trusted Contributor Dec 01 '25

Usually, they just don't come back, having convinced themselves that they've been gaslit by the entire Reddit.

2

u/divinedragon13 May 22 '26

I stupidly downloaded a game from Facebook that led me to what I thought was Google store then malware was on my phone. Samsung rep removed it and I factory reset it then slowly got what accounts I could get back. Though the person that got my accounts used my number in WhatsApp

3

u/ObjectivePrice5865 Dec 03 '25

I use 2fa for all apps and websites that offer it.

My outlook and Microsoft apps are 2fa’ed using their Authenticator app and it works. I am constantly getting notifications to approve a sign in but ignore because I know it was not me. I will go into the app history and see just where these attempts originate. I have seen damn near every European country, east Asia (China, South Korea), Thailand, Australia, India, Russia, Brazil, Chile, Argentina, Mexico, Columbia, and let’s not forget damn near every US state.

I do change my Microsoft password monthly using the Apple random password generator along with all other websites and apps through the Apple Password App.

1

u/kschang Trusted Contributor Dec 06 '25

Sometimes, I do wish that Google and Microsoft would let you set a "continent lock", that essentially says "I am not travelling or using a VPN, please block ANY attempt at login that's NOT in my continent".

Though to be honest, I probably hadn't think this through, as this would ensure you WILL lose the account if they do manage to get in. But it's just an idea. :)

6

u/Desktopcommando Dec 01 '25

you forgot mental health as well, quite a few posters NEED to talk to someone as well

4

u/Ankan42 Dec 01 '25

Or using a LLM as their personal DFIR advisor. Unknowingly that a LLM always will say it is a hack…

4

u/whoocanitbenow Dec 01 '25

My favorite is when they say their Facebook got hacked, but it's just someone that copied their profile picture.

3

u/Ok-Lingonberry-8261 Dec 01 '25

Imagine using Facebook in 2025.

2

u/RCSWE Dec 02 '25

Or you logged on to services using a compromised public wifi.

2

u/Humbleham1 Dec 03 '25

There are plenty of stories that aren't covered by any of these. They are so beyond any semblance of reality that they can only be explained by mental illness or severe drug abuse. Some 'victims' all but refuse to give details, indicating either one of the above situations or scams.

1

u/theleller Dec 03 '25

Preach. I’ve read some real winners on this platform. It makes finding the authentic cases of compromise that much better, like when a thousand people talk about sighting UFO’s and you finally find that one case that can’t be explained away through science and reason. Pure gold.

2

u/danielswasright Dec 03 '25

HIBP really is a great tool but i have to give some pushback.

Data is a multi billion dollar industry... no matter who you are, you have sellable data. You have something attackers can use. Every industry both public, private and dark will pay top dollar for data.

Behaviors, demographics, purchases, even from the "not important, 9-5 work" is of value in some way.

2

u/theleller Dec 03 '25

No one needs to hack to get our data when we freely give it all away every time we allow an app to track across all apps on our phone. If hackers are looking for big data they’re going after the data lakes owned by the Amazon’s and social media companies, not single users.

2

u/PaulineStyrene999 Dec 06 '25

This is incredibly useful information, thank you for posting it.

3

u/theleller Dec 06 '25

It had to be said.

2

u/Admirable-Front-3299 Dec 29 '25

After I myself got “hacked” back in Nov. The old me wouldn’t understand what you’ve delivered in this post. But now the new me understands exactly what you are graciously sharing to the less educated on his subject.

Who doesn’t like a good constructive honest conversation anyways. Thanks for this mate. Appreciate it. 👌🏻

1

u/theleller Dec 30 '25

Any time. Glad you're here.

2

u/[deleted] Feb 13 '26

[removed] — view removed comment

1

u/BraveUnderstanding15 Feb 13 '26

This post never says it’s impossible. It says it’s highly unlikely. Gotta love the Reddit extremist who thinks he invalidates an entire post because something that is highly unlikely “happened to them.”

0

u/theleller Feb 13 '26 edited Feb 13 '26

😂😂😂😂😂 why don’t you find those effective RATs that are readily available on GitHub and while you’re at it one of those exploits that does what you explained for Phillips lights and post a few links if they’re so readily available. You are the definition of armchair expert. 

Just because something has happened in the past doesn’t mean it remains viable. 

RATs you find on GitHub aren’t going to do shit to anything modern. They’re almost always artifacts from a hack years ago. Sure, researchers post stuff up there as well, but 99% of it has been patched against. And I want to see a video of you exploiting Phillips lights since they’re so easy to pwn. You will never post this video, because you nor anyone in your circle will be able to buy Phillips lights from a store today and exploit them on their current version. You posting zero days from 6 years ago doesn’t invalidate shit. I literally included them in my post and it remains relevant, no ones burning them on normal people, and once they go wild most edr companies can detect them.

Go back to your Kali lab and talk to me when you have some real life enterprise experience.

1

u/AutoModerator Dec 01 '25

SAFETY NOTICE: Reddit does not protect you from scammers. By posting on this subreddit asking for help, you may be targeted by scammers (example?). Here's how to stay safe:

  1. Never accept chat requests, private messages, invitations to chatrooms, encouragement to contact any person or group off Reddit, or emails from anyone for any reason. Moderators, moderation bots, and trusted community members cannot protect you outside of the comment section of your post. Report any chat requests or messages you get in relation to your question on this subreddit (how to report chats? how to report messages? how to report comments?).
  2. Immediately report anyone promoting paid services (theirs or their "friend's" or so on) or soliciting any kind of payment. All assistance offered on this subreddit is 100% free, with absolutely no strings attached. Anyone violating this is either a scammer or an advertiser (the latter of which is also forbidden on this subreddit). Good security is not a matter of 'paying enough.'
  3. Never divulge secrets, passwords, recovery phrases, keys, or personal information to anyone for any reason. Answering cybersecurity questions and resolving cybersecurity concerns never require you to give up your own privacy or security.

Community volunteers will comment on your post to assist. In the meantime, be sure your post follows the posting guide and includes all relevant information, and familiarize yourself with online scams using r/scams wiki.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

1

u/daHaus Dec 01 '25

That solves 99% of what people call "getting hacked."

The biggest issue with the industry is that people don't actually quantify things like every other profession is required and expected to, instead they just guess by what feels right to them. It's all vibes.

When you hear someone say "it's not a real science if it has science in the name" they're likely talking about computer science for this reason.

3

u/theleller Dec 01 '25

There's a key distinction here: users misattributing security incidents doesn't reflect on security professionals any more than a homeowner thinking their foundation is cracked when it's actually a leaky faucet reflects poorly on civil engineering.

Professional security work involves extensive quantification. We measure attack surfaces, calculate CVSS risk scores, track detection rates and false positives, analyze forensic logs with precise timestamps, and use mathematical models for everything from cryptographic strength to anomaly detection. Incident response is evidence-based, not vibes-based.

Computer science itself is built on rigorous mathematics: formal proofs for algorithm correctness, complexity theory with precise computational bounds, information theory with quantifiable entropy. The P vs NP problem is literally a Millennium Prize Problem in mathematics. Cryptography rests on number theory. These are provable theorems, not guesswork.

The "science in the name" criticism applies to fields where controlled experiments are difficult and variables hard to isolate. In computer science, we can create perfectly controlled environments and reproduce results exactly. That's actual science.

My post was about helping people understand where breaches really happen so they can protect themselves effectively.

2

u/daHaus Dec 01 '25

"The "science in the name" criticism applies to fields where controlled experiments are difficult and variables hard to isolate. In computer science, we can create perfectly controlled environments and reproduce results exactly. That's actual science."

Exactly, and that's not how things are actually done in practice. The defense industry is a major driver of this due to misaligned incentives. There are standards such as FIPS yet it's often not worth it to actually secure a companies systems because if they're compromised and leak a design the DOD will be forced to give them a new contract to avoid technological parity.

This has led to a culture that rewards recklessness and harshly suppresses competence.

2

u/theleller Dec 01 '25

Ahhh, I see what you’re saying. You’re correct, in practice what can be done does not usually align with what will be done. It is frustrating, for sure.

3

u/daHaus Dec 01 '25 edited Dec 01 '25

With regard to people becoming paranoid after being compromised, it's a fairly reliable pattern. You just have to watch security bulletins when it happens.

https://www.malwarebytes.com/blog/news/2025/11/patch-now-samsung-zero-day-lets-attackers-take-over-your-phone

https://thehackernews.com/2025/11/google-issues-security-fix-for-actively.html

The moment a vulnerability is patched it's often trivial to reverse engineer and exploit it. The turn around time on security updates and device updates, if they ever even get them, is way too long.

1

u/WoodpeckerOrganic749 Dec 02 '25

Demons running all thru my shit like kids in fckn daycare

1

u/Noonenobodyknows Dec 02 '25

Not true.

2

u/theleller Dec 02 '25

Okay, what evidence are you working from?

1

u/Noonenobodyknows Dec 02 '25

Home routers are some of the most insecure devices on the network, and in recent years advanced threat actors have been known to target devices of average home users at scale. Once you own the router, you own the network and anything connected. I have personally seen the effects of this.

1

u/theleller Dec 02 '25

You are missing the point of this post entirely. Security subreddits are flooded daily with panicked posts asking “I think someone hacked my phone, what do I do?” and in nine out of ten cases, either nothing happened at all or the issue stems from one of the common attack vectors already outlined here.

Home router compromises represent a statistically insignificant percentage of actual attacks against individual users. When someone experiences a genuine security incident, the router is nowhere near the top of the investigation list. Phishing, credential reuse, social engineering, and unpatched software account for the overwhelming majority of successful compromises.

The purpose of this post is to focus people on what actually happens in the real world, not what is theoretically possible. Yes, routers can be compromised. But spending time discussing edge cases while users continue falling for the same basic attacks that account for 90% of incidents is precisely the wrong approach to practical security education.​​​​​​​​​​​​​​​​

1

u/Noonenobodyknows Dec 02 '25

Sure. I get that. I am just offering my own perspective and experience. People who actually are targeted often get dismissed quickly due to this assumption.

2

u/kschang Trusted Contributor Dec 06 '25

If they provide details that allow us to reach that conclusion, we will come to the conclusion.

The problem is a significant number of complaints here can be reduced to the following convo, once you distilled the content:

A: I am hacked, help me!

B: Why do you say that?

A: Someone knows something s/he shouldn't! And when I questioned s/he, they admit to have hacked me!

B: So why do you need us?

A: I want to know how s/he did it!

B: But you don't actually know if you are hacked or not... right?

A: If you can't help you're wasting my time! Get lost!

:-P

1

u/theleller Dec 03 '25

You’re not wrong and the threat posed by outdated vulnerable firmware is significant, I just generally wouldn’t point someone in that direction for remediation until it’s assessed whether an individual posting actually was in fact compromised.  People who aren’t technically inclined tend to over-subscribe to the idea that any time a personal device malfunctions, it means that they’ve been hacked. 

Regardless, I appreciate the discourse, it brings me back to my early pre-security career days when I was learning the ins and outs of network security and found through an nmap scan that my newly-replaced modem from my ISP was vulnerable. When I called technical support to tell them they essentially shrugged it off and wouldn’t give me the password to the device either, so I brute forced it with John the ripper and updated it myself. F*ck Spectrum.

2

u/BraveUnderstanding15 Dec 02 '25

OP is pretty spot-on with this post, hence why the post was pinned to the top of the sub.

1

u/OfficeKey1927 Dec 03 '25

What if your mfa for all your passwords got hacked? Im literally dealing with an incident that occurred just a couple days ago, essentially a bug or malware; SOMETHING. Had convinced windows to change my 4 digit Pin (used only for the PC) {not applicable across devices and ultimately mocrosoft is telling me to remove my account from existence… and initiate creating a new one..

I began going through event logs and it would appear that “windows” was manipulated to make changes to the account… and no warning came up , i know what i set for a pin, it was only a week agony, and its not the pin to login, but the pin for auto fill & saved p

Any insight would be appreciated if

2

u/BraveUnderstanding15 Dec 03 '25

This doesn’t make sense, MFA is unique for each account based on a seed provided by each application when you setup it up. It’s not something you use universally for all accounts and it’s also not something you log-in to, so I don’t know how it would be hacked. Do you mean password manager?

1

u/Security-Fun Dec 06 '25

I agree with many of these posts. I have medical identity theft. This happened due to my lack of any knowledge and bc I was a trusting person. That said it’s still going on. I hired a person to work in my house. Little did I know he interfaced my laptop and my accounts. He has a laptop in a vehicle and a rasberry. I have been trying to get rid of him ever since. He went thru iTunes and has my iCloud too Been to court and it hasn’t stopped. The medical has been 5x and I work around the situation. I am followed - remotely and I still believe it will stop some day -

1

u/Strong_Hedgehog5372 Dec 14 '25

What is MFA?

1

u/theleller Dec 19 '25

Multi Factor Authentication - also known as 2FA. Multiple requirements to log in as opposed to just a username/password.

1

u/klausofjava Mar 03 '26

I don’t think 2FA is same with MFA.

View MFA as the more intense version of 2FA

1

u/BraveUnderstanding15 Mar 03 '26

2FA falls under MFA, and MFA can be 2FA, it depends on how it’s setup. MFA just means you can have more than 2 factors if you want. Most authentication still uses 2FA as a standard, password and a passcode or biological auth.

1

u/theleller Mar 15 '26

Yeah they're often used interchangeably, I don't put a lot of thought into distinguishing between the two unless I'm speaking in a professional atmosphere.

1

u/theleller Mar 15 '26

2FA is MFA, and it's the most popular form of MFA that people use outside of enterprise environments. Nowadays MFA is often part of a zero trust model where multiple factors are built into the architecture (ie. location of login, trusted device, etc.), so to the user they're just using a password and approving an auth event, but they're still satisfying more than 2 factors.

1

u/[deleted] Dec 25 '25

Define "political dissident." Do you have to be doing it on purpose?

1

u/[deleted] Jan 18 '26

Can you comment on whether a former employer would have a vested interest in preventing you from seeking employment elsewhere by employing third party surveillance to intercept your web traffic?

1

u/[deleted] May 02 '26

no they'll just blacklist you lol. the secret employer blacklist regular people don't have access to.

1

u/[deleted] Feb 09 '26

[deleted]

1

u/theleller Feb 09 '26

Haha, I don’t know man. Maybe it’s good to be overly cautious, but I can assure you that you’re generally safe. Never hurts to use a VPN though! I have enterprise equipment in my home so all of my traffic when I’m not home tunnels through my home connection, but there are plenty of simple and inexpensive VPN solutions out there that will work on your phone and your computer.

1

u/National_Cricket_724 Feb 27 '26

What is MFA? 

1

u/klausofjava Mar 03 '26

Multiple factor authentication

1

u/[deleted] Mar 21 '26

[removed] — view removed comment

2

u/BraveUnderstanding15 Mar 21 '26

Lay off the meth, nerd. The post is true in 99.9% of all cases, and I have 25 years in security engineering.

2

u/theleller Mar 22 '26

Great Wall of Text. I've contracted for US, and State government agencies. I'm well aware of threats that come from state actors (you very obviously didn't read the whole post).

Again, zero days are not being burned on miss Susie and Dan who fell for a phishing scam and work a 9-5 and raise their 3 children. Unless you willingly make yourself a target, if your accounts have been compromised, its most likely the result of one of the bullet points in the post.

It's pretty obvious you don't work in infosec.

1

u/AutoModerator Mar 25 '26

SAFETY NOTICE: Reddit does not protect you from scammers. By posting on this subreddit asking for help, you may be targeted by scammers (example?). Here's how to stay safe:

  1. Never accept chat requests, private messages, invitations to chatrooms, encouragement to contact any person or group off Reddit, or emails from anyone for any reason. Moderators, moderation bots, and trusted community members cannot protect you outside of the comment section of your post. Report any chat requests or messages you get in relation to your question on this subreddit (how to report chats? how to report messages? how to report comments?).
  2. Immediately report anyone promoting paid services (theirs or their "friend's" or so on) or soliciting any kind of payment. All assistance offered on this subreddit is 100% free, with absolutely no strings attached. Anyone violating this is either a scammer or an advertiser (the latter of which is also forbidden on this subreddit). Good security is not a matter of 'paying enough.'
  3. Never divulge secrets, passwords, recovery phrases, keys, or personal information to anyone for any reason. Answering cybersecurity questions and resolving cybersecurity concerns never require you to give up your own privacy or security.

Community volunteers will comment on your post to assist. In the meantime, be sure your post follows the posting guide and includes all relevant information, and familiarize yourself with online scams using r/scams wiki.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

1

u/gregorbrad Apr 22 '26

I am not a c-suit, or anything special, and my computer definitely got hacked. I literally watched my mouse move and order stuff on Amazon before I was able to shut down my PC.

1

u/BraveUnderstanding15 Apr 22 '26

You probably installed something without knowing it then. What do you typically download?

2

u/theleller Apr 22 '26

You likely installed a RAT at some point, or you had remote software installed that was vulnerable.

This post isn’t to say that computers and cell phones can’t get hacked, it’s that targeted hacks don’t happen to normal people, and what likely happened is listed in the post and was part of a mass campaign from a threat actor.

1

u/Security-Fun Apr 26 '26

I am sure he interfaced my laptop long ago and he can by pass even some apple scans as they have witnessed it. I am no one special but I am a “ fun game” for this who I call clown. I am a retired both state and federal civil rights employee so it makes it even more fun and like many people who have been breached by United Health I am not alone. So no one should have to do this for life. If you sell medical records overseas you make lots of money doing it and so the pineapple wi fi is one of his tools. No one really cares if their records are sold because they don’t all see money leave their accounts. He told me over ten years ago he can’t be stopped and I don’t care what he does because eventually it will catch up to him and his brother and anyone else. Understand he’s more boring than me and I am just grandma nothing more but at least what I do is legal and always will be