Hi everyone,
I’ve implemented strong security measures like 2FA, password managers, and even security keys to protect my accounts. Despite all this, I’ve still experienced hacking incidents that don’t seem to fit common explanations like session hijacking or phishing.
I’m trying to understand what advanced attack vectors or vulnerabilities might be at play here, and what steps I can take beyond the usual advice to secure myself better.
Has anyone faced similar issues or can share insights on deeper cybersecurity operations, attack methods, or advanced defenses? What should be the next steps when standard protections fail?
Thanks in advance for your expertise!
The term “hacking” gets tossed around to describe all kinds of different behaviors that may each require a different level of response.
You’ll get more specific help by providing more specific symptoms/behaviors.
Infostealer malware can steal session cookies, which an attacker can then use to interact with online accounts completely bypassing the password and MFA.
If you have a keylogger, everything you type in might be intercepted. Ditto for anything pasted to your clipboard.
To start, you need to make sure you have a trusted OS environment - that means wiping and reinstalling the OS using installation media that was prepared from another trusted device - not your potentially compromised device.
From there, you would have a trusted place to change all of your passwords. While in the security section of those online accounts, you would want to revoke all existing sessions. Some services have a “sign out everywhere” function, others may require manual review of each session.
If you have an email account that was compromised, be sure to check the mail forwarding settings.
For SSO accounts, audit your list of connected apps and services. Revoke and reinstate access for anything that can be set up again (e.g Google Drive Desktop App)