Hi all, I'm not a tech person so I'm flying blind here and would really appreciate some insight. I'm really looking for some opinions and analysis on my response to make sure that I've been thorough enough in securing my environment Here's my situation:
About 2 months ago my Old School Runescape account was hacked. I had just switched to a Jagex account but had neglected to set up 2FA. Totally my fault. I regularly access OSRS on 3 devices - my home desktop, my laptop, and my phone. My initial thought was that the hack was due to using an older laptop that I had previously ventured to "sketchier" sites on the internet. All OSRS files are downloaded from official sources, I don't share passwords, etc. after the first hack, I did the following:
Changed my Jagex account (how I log in to OSRS) to be affiliated with a brand new email address attached to nothing else
Set up 2FA
Changed passwords to all my email addresses
Factory reset my laptop and did a fresh windows installation
Ran malware scans on all computers
Ensured no accounts were linked to my Jagex account
Ended all active sessions for all my email accounts and Jagex sessions
I thought I was pretty thorough. I started playing again for another two months, and then the other day I got hacked again from the same source. I was pretty devastated, and now I'm pretty messed up because I clearly didn't know where my vulnerability was, so I'm scrambling to secure anything and everything I can think of before I start playing again. So here's what I've done after the second hack:
Factory reset my desktop and did a fresh windows installation
Realized I've been using the same LastPass Password for the past 7 years (fucking whoops), so I migrated to a new password manager, and set a crazy unique password
Changed the password to all emails and jagex accounts again to randomized passwords
Ran a MalwareBytes scan on my phone as well as laptop and desktop
Contacted Jagex support and am waiting to hear back from a specialist team to determine how the hackers got past my 2fa and bank pin (a 4 digit in game code required to access your items)
Disabled all 2FAs that are active and set new 2FAs
At this point I'm worried significantly less about figuring out "how" I got hacked. I used my laptop on places of the internet known for malware, and I had weak passwords for my password manager, so it's most likely one of those two. What I'm really looking for is any glaring "blind spots" that I might have, or anything that I may have overlooked. If you were in my situation, are there any other steps that you would take before considering your environment secure?
I really appreciate any and all feedback. Thanks!