Recommended Posts

I woke up this morning to discover my Uni email , and two other personal emails were hacked what I have lost I cant tell. each email had different passwords. I have reset all three and changed passwords to brand new ones. Other passwords to games have be also hacked and im going though them , Can you give any advice about how this could have happened, and the best way about not letting it happen again?

Link to comment
https://www.neowin.net/forum/topic/1143936-just-got-hacked-need-advice/
Share on other sites

You probably have a keylogger on your PC, the way to stop it happening again is dont browse for dodgy porn and go on dodgy websites.

But for the time being you can scan with this - http://www.surfright.nl/en/hitmanpro/

Once infections have been removed, then change your passwords again.

No one gets 'hacked' nowadays, it's not possible. Phished, malwared, social engineered, yes.

Enable 2-factor authentication after you've reset everything, check your logs (gmail), sent items, trash etc.

I am curious...what is your definition of "hacked"?

http://www.merriam-w...ctionary/hacker

Definition 4 applies here.

a person who illegally gains access to and sometimes tampers with information in a computer system

http://www.merriam-w...dictionary/hack

intransitive verb 4b applies here.

b : to gain access to a computer illegally

I would argue that those dictionary definitions are not really valid. This is where general understanding is often behind technology. If I broke into my library and turned on their PC is that hacking? IMHO no. To me, "hacking" would be:

Gaining access to a computer system by means of exploiting technical vulnerabilities.

That distinguishes it from social engineering and so on. Also seeing as "ethical hacking" is a common phrase, and something we (as a company) pay for (as penetration testing) - it's not illegal at all, and yet still "hacking"!?

sometimes your emails could get hacked without anything happening on your end. if you register on websites and forums using the same password as your email,if the site gets compromised,so does your email account. the sites might not even know they've been compromised. Once they have access to one email,the floodgates open.

That is true. I have got control over everything again.

I was wondering how it just happened. I have got new and different passwords for everything. Changed security options, Removed trusted emails to a trusted phone number.

2 step verification added to supports accounts.

uh it was so strange how the "person" just changed stuff on some things not others and yet he left a paper trail of all the reset emails lol.

uh it was so strange how the "person" just changed stuff on some things not others and yet he left a paper trail of all the reset emails lol.

it could have been a she....

/troll

I would argue that those dictionary definitions are not really valid. This is where general understanding is often behind technology. If I broke into my library and turned on their PC is that hacking? IMHO no. To me, "hacking" would be:

Gaining access to a computer system by means of exploiting technical vulnerabilities.

That distinguishes it from social engineering and so on. Also seeing as "ethical hacking" is a common phrase, and something we (as a company) pay for (as penetration testing) - it's not illegal at all, and yet still "hacking"!?

As dog is not the same as hot dog, ethical hacking is not the same as hacking.

From what you've mentioned, looks like it was someone you know as this person knew even your gaming habits. A friend of mine once did it to another as a joke by slipping a keylogger into his study notes. You should talk to your university IT department and see if they can tell you what IP was used to request for a password reset.

great you use other passwords for other sites. But as touched upon already..

lets say your main email is [email protected] - and all the other sites you login too, even other email accounts you setup [email protected] as recovery, etc..

If I get into [email protected] because your password was compromised, bruted, guessed then I could just look into your email to where you got logins from, game sites, forums, etc.. And then from there access them and ask for resets to be able to get in, etc.

as already mentioned, access to something like your main email account could open a flood gates to access to all your other accounts. You really need to turn on 2 factor for your main email account if possible. Or use a very strong password on this account.

  • Like 1
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • I have a Motorola, one of the lower end ones, it works fine. It is possible to get rid of the Gemini app and also to disable googles assistant , but A.i is still apps. I try to avoid all LLM A.I, is i can, I use no Ai duck duck go.
    • Free Software Foundation Europe pushes EU to force Google to allow AI uninstalls on Android by Paul Hill Credit: Pexels Users should be able to fully uninstall AI-based features from Android devices and be able to access interoperability functions, free from Google’s verification requirements, the European Commission has heard as part of an Android interoperability consultation under the Digital Markets Act. These measures were proposed by the Free Software Foundation Europe (FSFE) last week when it submitted its documentation. The FSFE noted that Google had started silently installing AI models without telling users. It noted that the EU’s DMA requires companies like Google to allow users to uninstall pre-loaded software from their devices, but in the case of the AI models Google is installing, they reinstall if you delete them, contravening the DMA. To get Google back under control, the FSFE has told the European Commission that there needs to be improvements within the Android Open Source Project (AOSP). First, it said that users should be able to fully remove pre-loaded AI components from their devices, with companies being prohibited from silently reinstalling or reactivating them. Second, access to Android interoperability features should not be contingent on registration, authorization, or contractual relationships with Google. This pertains to Google’s attempt to force developers to register with Google, even to publish apps to alternative app stores like F-Droid. Discussing its submission, Lucas Lasota, FSFE Legal Programme Manager, said: Google is planning to roll out its Android Developer Certification in September 2026. This will force every Android app developer to register with Google before their software can be installed on certified Android devices, but it should affect those who have removed Google Apps from their device. The program is controversial because it entails the signing of contracts and payment of account fees to Google, as well as the handing over of the identities of developers. It said: The FSFE said that if the Commission’s draft measures remain unchanged, then Google will be allowed to make developers verify their identity. The FSFE believes that asking developers to register is contrary to the text and spirit of the law. In summary, the FSFE has told the Commission that no developer should need a Google account, a Play Store presence, or any agreement with Google to access Android’s interoperability features.
  • Recent Achievements

    • Conversation Starter
      sumytbe earned a badge
      Conversation Starter
    • One Year In
      B4dM1k3 earned a badge
      One Year In
    • One Year In
      DarkWun earned a badge
      One Year In
    • Dedicated
      Almohandis earned a badge
      Dedicated
    • Dedicated
      JuvenileDelinquent earned a badge
      Dedicated
  • Popular Contributors

    1. 1
      +primortal
      519
    2. 2
      +Edouard
      189
    3. 3
      PsYcHoKiLLa
      87
    4. 4
      Michael Scrip
      81
    5. 5
      Steven P.
      72
  • Tell a friend

    Love Neowin? Tell a friend!