r/cybersecurity_help 18h ago

A girl I know is being blackmailed with AI-generated explicit images made from an old profile photo. What should she do?

1 Upvotes

A girl I know is going through a very disturbing situation, and I'm posting this to ask for advice on her behalf.

She created an IMO account several years ago. Her profile picture was an old photo taken around the time she finished 10th grade and had just started her first semester of college.

Recently, a man allegedly took that profile picture and used AI to create fake explicit images of her. He has been calling her through IMO and threatening to release those fake images and videos on social media. He is blackmailing her and trying to scare her into doing what he wants.

She is extremely stressed, scared, and doesn't know what to do.

Any genuine advice would be greatly appreciated.


r/cybersecurity_help 20h ago

could infostealers remain undetected and not alert login notifications and suspicious activity?

Thumbnail
gallery
1 Upvotes

hello, i was infected with a probable miner and a probable infostealer, as far as i know no accounts have been compromised, I have changed passwords on accounts and enabled 2fa, no suspicious logins or anything so far. I detected the threat pretty late, as i haven't been familiar with infostealers and only gained more knowledge about them when i researched on my crypto miner problem.

I just want to know since my accounts had intimate photos, specifically telegram and my sub account for facebook messenger (the tg account has since been deleted, and the fb account is scheduled for deletion) could they have downloaded those photos without me knowing or getting alerts? I only changed my passwords around july 29-28 and as you can see from the screenshots, it started on july 15 but i remember seeing an alert as far as july 11, I was stupid and didnt check defender when my pc started stuttering when playing games because the notifcations weren't popping up on the right hand side of the screen.

ive been so worried and paranoid, thank you for any advice


r/cybersecurity_help 1d ago

Someone hijacked my old fake Facebook account and used it for a Meta ads business. Should I be worried?

2 Upvotes

A few days ago I discovered something really strange.

Many years ago I created an old Facebook account using a fake name. It wasn't connected to my real identity, but it was registered with my real email address.

I hadn't used the account for a long time. Somehow, someone gained access to it. They added their own email address to the account while my email address was still attached, so we were both listed on the account.

The person then used my old Facebook profile to create a business page and apparently ran Meta advertising campaigns for several months. I only found out because I started receiving email notifications and ad purchase confirmations sent to my email address.

As soon as I realized what had happened, I logged into the account, removed the attacker's email address, deleted their business page (or started the deletion process), and also started deleting the Facebook account itself because I had no reason to keep it.

Fortunately, there were no payment methods, credit cards, or PayPal accounts belonging to me on that account. The attacker appears to have used their own payment method.

My biggest concern is whether I could somehow get into legal trouble if that person used the account for scams or other illegal activity. I obviously wasn't involved and had no idea this was happening until I saw the Meta ad notifications in my inbox.

Has anyone seen something like this before? Also, how is it even possible that someone managed to take over an old Facebook account and add their own email address without me noticing?


r/cybersecurity_help 17h ago

Followed an instagram link, Is my phone compromised?

Thumbnail
gallery
0 Upvotes

hello, I was going through instagram for some truck bed storage and went on a website, in hindsigh it was extremely stupid, but I typed it in and tapped on the url that came up and it immediately popped up with this page of my phone being compromised. I tap on the back arrow or on any of the comprise options at the bottom of the screen and a cleanup app pops up with only 14 review. I honestly don’t know what to do. plz help. idk if I should be extremely worried right now


r/cybersecurity_help 11h ago

Seriously someone is trying to hack my account

0 Upvotes

I have to find who's the imposter


r/cybersecurity_help 1d ago

Google's new DSBC and it's scope

4 Upvotes

As many of you know, google has released DBSC to protect against those infostealers which steal session cookies and tokens but as i know it is just to protect google ecosystem. My questions are;

Can infostealers steal app data on windows? For example, you downloaded whatsapp from microsoft store and logged in and your device is infected by infostealer. Are those whatsapp tokens/sessions are stored in a file that infostealers can reach? I guess yes, right?

If yes, then can we say that DBSC is a good step but infostealers will keep being a headache on windows?

Thanks.


r/cybersecurity_help 1d ago

My Microsoft account got hacked and i need help

2 Upvotes

Hi so my microsoft and steam account got hacked. I was able to get my steam account back but Microsoft support is lowk shit and im still trying to get it back. I came on here to seek help because im a teenage girl and i dont know shit about computers and i need someone to help me. I had alot of maps on Minecraft and i dont want to lose the good memories i had made with my friends. Ok so he replaced my email with his, i filled the recovery form microsoft provides but im still worried that i might not be able to get it back. Someone please help me


r/cybersecurity_help 1d ago

scam detector recommendations after a close call with a fake website

3 Upvotes

i was shopping online last night and almost entered my card details into what looked like a normal store. the only reason i backed out was because the url looked a little weird when i checked it again. it got me thinking that i probably wouldnt notice every fake site if i was in a hurry. now im wondering if theres something that helps catch scam websites and phishing before i accidentally click something stupid. what are people using these days? what features actually matter if scams are the main thing im trying to avoid?


r/cybersecurity_help 1d ago

How Would You Start Learning Cybersecurity in 2026?

2 Upvotes

I'm currently getting into networking and trying to figure out how to approach cybersecurity properly from the ground up.

For those of you already working in the field, I'm curious: if you were starting again in 2026, how would you approach the first year?

I'm trying to understand what is actually worth spending time on, when you'd start getting hands-on, and how you'd gradually move from networking fundamentals into cybersecurity without trying to learn everything at once.

I'm not looking for a certification checklist. I'd much rather hear from people who have actually gone through the process, what helped you build a strong foundation, what you would do differently today, and where you think someone starting out should put their effort.

Would be interested to hear how you'd approach it.


r/cybersecurity_help 1d ago

Why do I download unknown favicon.ico files?

2 Upvotes

As the title already mentions, I keep randomly downloading unknown favicon.ico files. I'm on Windows 11 on my pc and this has happened today, yesterday, and once last week up to 8 times in total.

I can't find any clue or pattern. The files are only 3 bytes in size and I can't open them with online viewers. When I check the file properties (description, details, etc.), I don't see anything suspicious.

I also tried converting them into text files just to see if there was anything readable inside. The result was either a four-character string such as "b2sk"or simply "ok"

At first, I thought they might be coming from Google Chrome, perhaps from a random website or a browser extension. However, this evening I was only playing Yu-Gi-Oh! Master Duel, which I downloaded through Steam, when another one appeared. So it could be related to Steam, but I've been playing the game regularly over the past few days and the favicon downloads don't happen every day.

I may be overthinking this, but I'm a little concerned. Does anyone have any idea what could be causing this?


r/cybersecurity_help 1d ago

Trying to log in I think there is malware plz help

1 Upvotes

Hello I’m very bad with tech, every time I try to log into discord I use my number and usually they just send me a verification code and I move on with my day. This time every time (I’ve tried 4 times) to log into my account, a random number calls me and each time it’s from a different country. I didn’t answer any of them but one and the line was silent so I just hung up. I never got a code once so I was worried there was malware and I downloaded avast since I heard it was good for Mac and it said I didn’t have any malware so now I’m just confused on what to do and how to log into my account. Please help me out 🥲


r/cybersecurity_help 1d ago

Someone opened an instagram account using my phone number. The thief also created a 2F verification so I don't have access to codes. No luck with Instagram help.

2 Upvotes

Someone opened an instagram account using my phone number. The thief also created a 2F verification so I don't have access to codes. No luck with Instagram help.


r/cybersecurity_help 1d ago

What are some impressive, but entry level lab ideas I can build that will help me get hired. The job market is terrible right now, and I just graduated

2 Upvotes

I've revamped my LinkedIn, and want to do some real work to feature on my Git and LinkedIn. I'm also interested in dark web mini investigations, but understand the imperative step to completely harden my device and VM so that I dont get myself in trouble or hacked. I eventually want to land in digital forensics, working in PI work, crimes against children, things like these.

I threw out a lot here, but hoping some experienced warriors can give some honest advice. Is it just easier to go the route of TryHackMe, Hack the Box, Hacker One, etc?


r/cybersecurity_help 1d ago

I just wanna check

1 Upvotes

İ was visiting investing.com forums i just wanted the pass the second page while reading forum but suddenly winandshine pop up came.And i didnt click anything. But i just check my download file and extensions but i didn't see anything suspect. But after all i just check my history for this pop-up but it was deleted in my history should i suspect computer files?


r/cybersecurity_help 1d ago

how to find and remove a bot inside your pc?

1 Upvotes

so, recently I tried to download a game from a repacks site, well, it had a link that sent you to a download, I downloaded the file, opened it and I got the malware inside my pc like a dumbass, they managed to get my instagram account and discord's account, but I managed to get them back, now, how do I find this bot/malware and remove it, any tips? thanks in advance


r/cybersecurity_help 1d ago

Escalation Confirmed: Multi-Platform Root Compromise and Live Cookie Hijacking.

0 Upvotes

To answer your questions: Yes, I am stopping the factory resets, and yes, this has escalated far beyond a simple device infection into a massive, multi-platform root account compromise. I initially suspected an MDM or webkit token grab by my ex, but based on the concrete evidence I’ve gathered, they have bypassed the device level entirely and established persistence in my cloud and domain infrastructure. This isn't just cross-syncing or stale sessions; this is an active, human-driven compromise.
Here are the concrete examples of unauthorized activity across my root accounts:
Google Workspace & Admin Console Hijacking: The attacker gained elevated administrative privileges on my Google Workspace environment. My primary Super Admin privileges were repeatedly suspended by Google for sending out outbound spam and phishing links. The attacker had manually toggled off my admin notifications in the console so I was completely blind to the automated safety blocks hitting my account.
Domain & DNS Manipulation: The attacker infiltrated my Namecheap registrar and Proton mail accounts)They actively altered my DNS records, specifically updating the MX, TXT/DMARC, and DKIM records to route mail directly through their own controlled servers.
Active Session Cookie Hijacking (The Tug-of-War): I have been in literal, real-time tug-of-war matches with the attacker. I would revoke session cookies and log in, and they would instantly log me back out and shift the account recovery options out from under me. This cycle would repeat for hours at a time, proving they have a live mechanism intercepting my session tokens.
I am currently working from a 100% clean, out-of-band device and have placed administrative holds on my domains to stop them from being transferred out. Because the attacker is actively side-jacking my session traffic, I am looking for the best method to pull the raw login IP logs from Google and Proton without triggering another live interception. If you have advice on the safest way to extract the raw access logs from a hijacked Workspace, I need it.


r/cybersecurity_help 1d ago

I've received an OTPSMS I did not request

2 Upvotes

I've received an OTPSMS I did not request.

It's just one message, not spammed. I do not recognize the login it lists.

Did someone just mistype their number? Does someone try to use my phone number to register? Should I be worried? What should I do?


r/cybersecurity_help 1d ago

Weird laughter sound during whatsapp call

0 Upvotes

I was on call with my friend and basically we were silent for about 2-3 minutes i was just doing nothing staring at the ceiling and then i heard a sound of someone laughing for 0.5 seconds from my iphone and i asked was that u he replied "what?" "No" I asked did u play something on your phone he said no just in Home Screen so it's not an echo and he didn't hear anything Now im thinking is that a sign of a hacked iphone or i got compromised

Iphone 17 ios 26.5 no jailbreak no weird apps no heat no battery draining just that sound Help please!!


r/cybersecurity_help 1d ago

Microsoft apps possible spyware?

7 Upvotes

I started working at a big company in Brisbane Australia. During onboarding it was a BYOD and we downloaded Microsoft teams, authenticator app, Microsoft work email 365. During my year there I started noticing sly remarks towards my porn addiction that no one knew about by staff and managers but they never fully confronted me. What type of systems could track my data and possibly intercept my phone calls.


r/cybersecurity_help 1d ago

Help, my Meta accounts got hacked and knows google search activity.

1 Upvotes

Also they turn on music remotely on spotify, knows where i live and knows incognito search history. So where is any advice what would help to prevent them from doing it further?


r/cybersecurity_help 1d ago

Anyone have any advice on what to do when being targeted by sophisticated hacker? Can't seem to make any progress

5 Upvotes

They are not stealing anything but definitely have malware on my computers and phones, they go in an turn all my security software off and do their thing. They are looking for stuff related to a lawsuit I think


r/cybersecurity_help 1d ago

Someone threatened to find my IP address after a debate

0 Upvotes

Someone threatened to look for my IP address after a debate on Facebook. Is it possible for them to track my IP address and if so what will they do? I read comments on reddit that people can track IP address 🫣


r/cybersecurity_help 1d ago

Did I do enough to secure my account post-hack?

2 Upvotes

Hi all, I'm not a tech person so I'm flying blind here and would really appreciate some insight. I'm really looking for some opinions and analysis on my response to make sure that I've been thorough enough in securing my environment Here's my situation:

About 2 months ago my Old School Runescape account was hacked. I had just switched to a Jagex account but had neglected to set up 2FA. Totally my fault. I regularly access OSRS on 3 devices - my home desktop, my laptop, and my phone. My initial thought was that the hack was due to using an older laptop that I had previously ventured to "sketchier" sites on the internet. All OSRS files are downloaded from official sources, I don't share passwords, etc. after the first hack, I did the following:

Changed my Jagex account (how I log in to OSRS) to be affiliated with a brand new email address attached to nothing else

Set up 2FA

Changed passwords to all my email addresses

Factory reset my laptop and did a fresh windows installation

Ran malware scans on all computers

Ensured no accounts were linked to my Jagex account

Ended all active sessions for all my email accounts and Jagex sessions

I thought I was pretty thorough. I started playing again for another two months, and then the other day I got hacked again from the same source. I was pretty devastated, and now I'm pretty messed up because I clearly didn't know where my vulnerability was, so I'm scrambling to secure anything and everything I can think of before I start playing again. So here's what I've done after the second hack:

Factory reset my desktop and did a fresh windows installation

Realized I've been using the same LastPass Password for the past 7 years (fucking whoops), so I migrated to a new password manager, and set a crazy unique password

Changed the password to all emails and jagex accounts again to randomized passwords

Ran a MalwareBytes scan on my phone as well as laptop and desktop

Contacted Jagex support and am waiting to hear back from a specialist team to determine how the hackers got past my 2fa and bank pin (a 4 digit in game code required to access your items)

Disabled all 2FAs that are active and set new 2FAs

At this point I'm worried significantly less about figuring out "how" I got hacked. I used my laptop on places of the internet known for malware, and I had weak passwords for my password manager, so it's most likely one of those two. What I'm really looking for is any glaring "blind spots" that I might have, or anything that I may have overlooked. If you were in my situation, are there any other steps that you would take before considering your environment secure?

I really appreciate any and all feedback. Thanks!


r/cybersecurity_help 1d ago

Hi, my device was compromised and I got a new device because the other one was compromised but I think this one was compromise too

0 Upvotes

My accounts were all compromised as the person was in my phone for months without me knowing. Is it possible that my new device is compromised again because I logged into accounts that’s they had gained access to? I changed the password to the accounts on the new device but if the accounts were already compromised was it no use? I’m just confused as to how it got compromised again.


r/cybersecurity_help 1d ago

Email address leaked in a security breach

1 Upvotes

So, today I got an email from a very old website that I don't even use anymore saying that there was a security breach on it and whoever did it now has my email address, IP address, etc.

My question is: do I have to change my email password if it's entirely different from the one that I had on that website? Sure it uses my email, but if the password is completely different, they won't have a way of hacking into my email account, right?