Hacked

Author
Discussion

Mojooo

Original Poster:

12,971 posts

186 months

Sunday 8th October 2023
quotequote all
A week or so ago, I look at my phone and see my Gmail account is getting loads of spam - its very unusual as I might only see one a month as the spam filter is good. I look through the messages and I can see some from Amazon buried in there. They are emails relating to gift cards.

I login to my Amazon account and can see £50 has been loaded on in 4 amounts of 15 15 10 and 10. I change my password before the money is spent. I was fortunate to spot this at pretty much the same time it was happening. Incidentally if they had not spammed me at the time to try and hide those Amazon emails I may not have noticed because I get Amazon emails quite often so I may have ignored the gift card ones had it not been for all the spam. I'd have prob just assumed they were to do with an order.

Its highly probable I have a virus because I let someone else (young) use my PC to download files the day before. I reinstall Windows.

I change my Gmail password and put on 2 factor security so now I have to approve everything on my phone.

The next day I see emails saying that my Facebook password is being resent. I then find they have changed the password, email and telephone number so I am locked out. They hide my profile so none of my friends can see it. I am not worried about the FB account but am worried about personal photos and my account being used for fraud. I send FB a copy of my driving licence and surprisingly, they restore my account within 2 or 3 hours.

I am a bit worried now because I am wondering if they somehow have access to my emails. They only way they can reset the FB account is surely by accessing the code that gets sent to my Gmail account.

By chance I happen to meet someone at work who works in cyber security and tell him the above - he tells me to check if my Gmail is set to forward emails as its a way of them seeing my emails if I change the password - I check but no forwarding set on.

Today I look at a backup Yahoo email account i have. Additional things happened last week but I only saw them today
- they have gone in and taken my LinkedIn and Instagram accounts - not fussed as throwaway accounts
- they have taken over an old/spare Facebook account I had.
I change the Yahoo password. I am not too fussed about losing the above accounts as none have anything identifiable to me.

At some stage I have had a virus or malware which has allowed the hackers to either see where I am logged into or somehow access my emails and then change passwords but curiously they don't seem to have tried to take over the email accounts themselves..

I wondered if maybe my phone was hacked but I have never logged into the Yahoo account on that

It was quite scary when it was happening - so much of my life is tied to my Gmail so it would be a pain to lose it.

Also cancelled my debit card linked to my Amazon account.


Any thoughts on what is going on.

BlueMR2

8,691 posts

208 months

Sunday 8th October 2023
quotequote all
Do you use any passwords more than once?

Plenty of places being hacked and losing customer data all the time.

Actual

977 posts

112 months

Sunday 8th October 2023
quotequote all
Mojooo said:
but curiously they don't seem to have tried to take over the email accounts themselves..
My dad's btinternet email was hacked and they setup the forwarding thing but didn't change the passwords. They then sent "I need help please send me an Amazon gift card" to everyone with a different surname in his address book. Amazingly people he had not spoken to for years sent Amazon gift cards.

I was able to change the password and remove the forwarding. It took a few goes because I think they were still logged in somewhere.

I don't know why they didn't lock us out of my dad's account.

Mojooo

Original Poster:

12,971 posts

186 months

Sunday 8th October 2023
quotequote all
Passwords are all different on these sites

Gmail allows you to see what other computers are logged into your account so I was able to log everything else out

BlueMR2

8,691 posts

208 months

Monday 9th October 2023
quotequote all
Actual said:
Mojooo said:
but curiously they don't seem to have tried to take over the email accounts themselves..
My dad's btinternet email was hacked and they setup the forwarding thing but didn't change the passwords. They then sent "I need help please send me an Amazon gift card" to everyone with a different surname in his address book. Amazingly people he had not spoken to for years sent Amazon gift cards.

I was able to change the password and remove the forwarding. It took a few goes because I think they were still logged in somewhere.

I don't know why they didn't lock us out of my dad's account.
Probably to give themselves time to get some vouchers through before you notice.

BlueMR2

8,691 posts

208 months

Monday 9th October 2023
quotequote all
Mojooo said:
Passwords are all different on these sites

Gmail allows you to see what other computers are logged into your account so I was able to log everything else out
If they had access to your email then they may have just requested new passwords for common services they found and hope you don't have 2fa on.

Edited by BlueMR2 on Monday 9th October 00:52

eeLee

837 posts

86 months

Monday 9th October 2023
quotequote all
they likely have 2 motives:

1. Social engineering of friends and contacts ("I'm in Limassol and need money" scams
2. Leveraging stored credit cards for digital good purchases (no delivery involved, easy to move on)

Your young person likely downloaded the malware when stealing some software, it's often the case. I would not encourage them to do this any more.....

wyson

2,443 posts

110 months

Monday 9th October 2023
quotequote all
When you said you reinstalled Windows, you formatted the hard disk right? Nuked the lot and started from a new partition?

wyson

2,443 posts

110 months

Monday 9th October 2023
quotequote all
Also, how are you connecting to the internet? I’d nuke the router as well, do a hard reset and reset the password. That is a little computer in itself. My router often blocks exploits when I visit certain websites smile

Edited by wyson on Monday 9th October 12:57

Mojooo

Original Poster:

12,971 posts

186 months

Monday 9th October 2023
quotequote all
Yes windows formatted new partition.

Wifi no - but can do - no one else been affected.

the-norseman

13,192 posts

177 months

Monday 9th October 2023
quotequote all
Sounds to me like your usernames/passwords have been purchased from the darkweb and they are just going after social media and email accounts.

wyson

2,443 posts

110 months

Monday 9th October 2023
quotequote all
Mojooo said:
Yes windows formatted new partition.

Wifi no - but can do - no one else been affected.
You have to be proactive and assume the worst if you don’t know whats going on, otherwise you could end up just chasing your tail.

Edited by wyson on Monday 9th October 14:00

wyson

2,443 posts

110 months

Monday 9th October 2023
quotequote all
Once I nuked my equipment, I’d start changing every single password I can and setting up 2FA on them.

rallye101

2,170 posts

203 months

Monday 9th October 2023
quotequote all
This happened to me just like you've described, lost all my old Facebook photos....they'd forwarded my emails too, was nice to wake up one morning to find I'd apparently been on all all night Uber trip for £700ish quid