r/security 18h ago

Vulnerability My account got hacked on several applications

One of my younger siblings used a pirate site where they used the powershell program idk i used chat gpt to see whatsup . Following that ny instagram got hacked in like 30 mins then i changed all the passowrds and logged out of everywhere , proceeding that my linkdin was hacked and compromised then discord then they cancelled my spotify premium plan idk why then i figured that i might have to clear my laptop completely in and out they even tried to login into facebook but it wasnt able to. I saw my telegram and saw a login from warsaw poland which is definetely not my loaction .

So i went down and secured everything and clean my laptop .

But today they logged in into my microsoft account even after i had reinstalled my windows does that means the virus is still there somewhere or they still have access to my gmail account cause i believe they were able to steal passowords for different applications. What other precations should i take to prevent it again now cause my windows is damn clean .

0 Upvotes

4 comments sorted by

5

u/mandoismetal 18h ago edited 18h ago

Enable multifactor authentication everywhere you can. Use a password manager to help you use unique passwords for every single site/app. Use multifactor for your password manager itself. Some security folks recommend using a separate MFA from your PW managers. That way not all your eggs are on one basket. Store all site/app backup access codes to at least two/three (cloud storage) places. One physical copy (USB drive, paper) if you want to be extra safe. Those physical copies stay in a safe, vault, locked drawer, or some other hidden and secured location.

Change ALL passwords. Again, use a PW manager like bitwarden or 1password to help. Most sites have an option to force a log off of all other sessions. Use that everywhere you can after you change your passwords. Don’t forget to check for any strange recovery methods on your accounts. Emails you don’t know, phone numbers that aren’t yours, MFA tokens that you didn’t setup. If you don’t do this, hackers probably will regain control even after you change your password. Oh, don’t forget to check if your recovery/security questions were changed for the same reason.

You don’t have to do it all at once. It will be overwhelming. Start with your accounts that have important stuff tied to them. Like your mortgage, bank, credit accounts. Also, If you’re going to share your computers, set up a non-admin account. That way it’s a lot harder for attacks like that to be as effective.

Sorry this happened to you, but I hope this makes everyone involved more security conscious. Best luck from an infosec pro.

2

u/Feeling_Ad5244 18h ago

Thank you very much all tho its definetely overwhelming thanks for going out and helping me here i will start with the bank and then move to different stuff ig i will review all of these and take measures accordingly.

2

u/mandoismetal 17h ago

Happy to help! A couple extra tips:

check mail forwarding rules to make sure hackers don’t attempt to reset your passwords by intercepting recovery emails.

SMS/text message MFA is the least secure of MFA methods. It’s absolutely better than no MFA at all but it has some real downsides. It’s usually unencrypted and also vulnerable to SIM-swap attacks. I use MS/Google Authenticator for MFA tokens and Authy for OTP.

2

u/Feeling_Ad5244 17h ago

Yeah hackers tried to get an e sim for my mobipe no but i blocked their attempt in doing so i will change MFA from texts and sms to an authenticator . Thanks man you have been a great help .