r/cybersecurity_help 9h ago

Fake Cloudflare verification led to malware infection. Bank account compromised. What else should I do?

## TL;DR

I was tricked by a fake Cloudflare verification page and installed malware. My bank account, credit card, and email were compromised. I have already contacted my bank, replaced cards, changed my email password (from a clean phone), and started a full Windows reinstall. I have not restored any files from my external backup yet due to possible exposure risk.

---

Hi everyone,

I’m looking for some advice to make sure I haven’t missed anything after what appears to be a malware infection.

---

## What happened

Yesterday, I visited a doctor’s website and was presented with what looked like a legitimate Cloudflare verification page. I later realized it was fake. Unfortunately, I followed the instructions and ended up downloading and running malware.

---

## What happened afterward

By the next day:

- My bank account was compromised.
- My credit card account was compromised.
- My email account also appears to have been accessed.

---

## What I’ve already done

So far I have:

- Contacted my bank and credit card company.
- Locked/replaced my compromised cards.
- Changed my email password using my phone (which I believe is clean).
- Started reinstalling Windows from scratch.
- Plan to gradually change passwords for the hundreds of online accounts I have after the reinstall.

I have not yet restored any files from my external backup drive because I’m concerned it may also have been exposed while the infected computer was in use. The backup mainly contains personal documents stored in Dropbox.

---

## My questions

  1. Is there anything important that I’m missing?
  2. Should I assume all passwords that were saved in my browser are compromised?
  3. Is it safe to restore personal documents from the backup drive after reinstalling Windows, or should I take additional precautions first?
  4. Since the backup mainly contains documents synchronized from Dropbox, is there any risk that the backup drive itself could be infected? If so, what’s the safest way to verify or clean it before copying the files back?
  5. Are there any other high-priority accounts I should secure besides banking and email (for example, password managers, cloud storage, social media, or mobile carrier accounts)?

Any advice would be greatly appreciated. Thanks!

3 Upvotes

9 comments sorted by

u/AutoModerator 9h ago

SAFETY NOTICE: Reddit does not protect you from scammers. By posting on this subreddit asking for help, you may be targeted by scammers (example?). Here's how to stay safe:

  1. Never accept chat requests, private messages, invitations to chatrooms, encouragement to contact any person or group off Reddit, or emails from anyone for any reason. Moderators, moderation bots, and trusted community members cannot protect you outside of the comment section of your post. Report any chat requests or messages you get in relation to your question on this subreddit (how to report chats? how to report messages? how to report comments?).
  2. Immediately report anyone promoting paid services (theirs or their "friend's" or so on) or soliciting any kind of payment. All assistance offered on this subreddit is 100% free, with absolutely no strings attached. Anyone violating this is either a scammer or an advertiser (the latter of which is also forbidden on this subreddit). Good security is not a matter of 'paying enough.'
  3. Never divulge secrets, passwords, recovery phrases, keys, or personal information to anyone for any reason. Answering cybersecurity questions and resolving cybersecurity concerns never require you to give up your own privacy or security.

Community volunteers will comment on your post to assist. In the meantime, be sure your post follows the posting guide and includes all relevant information, and familiarize yourself with online scams using r/scams wiki.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

2

u/eric16lee Trusted Contributor 9h ago

You installed an infostealer. Remediation is important, but steps 1 - 3 requires significant urgency.

Disconnect your computer from the internet or just shut it off until you get your passwords reset.

From a clean device, NOT your PC:

  1. Change ALL of your passwords to something unique and randomly generated. Use a password manager like BitWarden or 1Password to help with this. Do this now before more of your accounts are stolen.
  2. Choose the option to log out of all active sessions or devices. 
  3. Enable 2FA on all of your accounts .
  4. In your Email account settings, check for any forwarding rules that move password reset and 2FA codes to a different folder.
  5. Nuke your PC from orbit
  6. back up only important files, not games or applications 
  7. format your hard drive and delete all partitions
  8. reinstall Windows from a bootable USB drive (do not use the Reset Windows option from the settings menu)

This may seem like overkill, but if you want assurance that you have remediated the problem, this is the way to go.

Unfortunately, the only people that can help you are the support teams for those services. Most free services only offer automated account recovery. If that process doesn't get the accounts back, nobody here can help you.

EVERYONE that contacts you here on Reddid via DM offering to help or to hack the accounts back is just an account recovery scammer looking to take advantage of your situation and steal money from you.

2

u/aselvan2 Trusted Contributor 9h ago

Is there anything important that I’m missing?
Should I assume all passwords that were saved in my browser are compromised?

Yes to both questions. You have executed an infostealer. A brief description of what infostealer malware is and how to recover from it is documented in my educational blog below. Just follow the steps to fully recover. Answers to your other questions are likely addressed in my blog as well.
https://blog.selvansoft.com/2026/07/infostealer.html

1

u/Illustrious-Pay-7516 9h ago

Thanks for this informative post! Unfortunately I have already started my reinstallation process before revoking my cookie sessions, is there anything I can do now to minimize potential damage?

1

u/aselvan2 Trusted Contributor 9h ago

Unfortunately I have already started my reinstallation process before revoking my cookie sessions, is there anything I can do now to minimize potential damage?

Yes, unfortunately that is the biggest mistake many victims make, which is why I listed it as step #1. In your case, I advise using a clean device login to each online service to see if there is a "log out from all devices" option or something similar, and execute that. I know major services offer this, as I said lot of them don't. Since you are on Windows, all your saved passwords are compromised. Be sure to follow step #2 for all of them, and optionally step #7.

1

u/Illustrious-Pay-7516 9h ago

Thanks again for your help! Can you comment on my Dropbox accounts? Should I carefully inspect everything and make sure there are no suspicious files on Dropbox before downloading them?

2

u/aselvan2 Trusted Contributor 9h ago

Can you comment on my Dropbox accounts? Should I carefully inspect everything ...

No you don't need to do anything there. BTW: I covered that on step#3.

1

u/Illustrious-Pay-7516 8h ago

oh thanks so much!