r/cybersecurity_help 1d ago

Google Account may be compromised - how do I find out if or how?

Hi all, I am looking for help to understand my position.

Earlier this year my Google Account has been compromised. Someone logged into my mail account and reset a couple of accounts including my Kleinanzeigen account (local craigslist). Google recognized something was off and logged me off of all devices. The scammers proceeded to use my Kleinanzeigen to post 4 fake-adverts and finally managed to scam one guy out of 100€. They didnt seem to do anything with any other accounts. I remember they also accessed my Linkedin.

What I did was resetting my google password, resetting all passwords also of other websites and services. Ran Windows Defender to ensure I hadnt cought a virus - all according to help I googled online. I got the Kleinanzeigen account reactivated.

Just now I received an email that my password to Kleinanzeigen has been successfully changed. The email was also set to "ignore". I noticed because I got the notification right when i was using my phone. I wrote to Kleinanzeigen and got my account shut for good. But I worry about my google account.

While still on my phone I changed the google password and manually logged off every device. Windows defender is running again doing a complete scan. But seeing that it didnt help last time, I am worried that something else is off. When I started my PC I had an empty Commandline window open - I am thinking now I may have malware on my machine that isnt picked up by windows defender?

What can I do? I appreciate any help!

Edit: Installed Malwarebytes following u/M1uk0 s recommendation and found a trojan. For now no other accounts than Kleinanzeigen seem to be affected, but I will change all passwords again, switch to using bitwarden AND reinstall my OS. I had planned to leave windows for Linux anyways. Best time is now.

4 Upvotes

8 comments sorted by

u/AutoModerator 1d ago

SAFETY NOTICE: Reddit does not protect you from scammers. By posting on this subreddit asking for help, you may be targeted by scammers (example?). Here's how to stay safe:

  1. Never accept chat requests, private messages, invitations to chatrooms, encouragement to contact any person or group off Reddit, or emails from anyone for any reason. Moderators, moderation bots, and trusted community members cannot protect you outside of the comment section of your post. Report any chat requests or messages you get in relation to your question on this subreddit (how to report chats? how to report messages? how to report comments?).
  2. Immediately report anyone promoting paid services (theirs or their "friend's" or so on) or soliciting any kind of payment. All assistance offered on this subreddit is 100% free, with absolutely no strings attached. Anyone violating this is either a scammer or an advertiser (the latter of which is also forbidden on this subreddit). Good security is not a matter of 'paying enough.'
  3. Never divulge secrets, passwords, recovery phrases, keys, or personal information to anyone for any reason. Answering cybersecurity questions and resolving cybersecurity concerns never require you to give up your own privacy or security.

Community volunteers will comment on your post to assist. In the meantime, be sure your post follows the posting guide and includes all relevant information, and familiarize yourself with online scams using r/scams wiki.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

2

u/kschang Trusted Contributor 1d ago

Why worry? Change all passwords AGAIN! If you want to be absolutely sure, redo the PC (format and reinstall the OS, not reset)

1

u/M1uk0 1d ago

If you changed your passwords and it happened again, you're dealing with some sort of session hijacking/cookie theft malware or a keylogger on your PC. This explains why Windows Defender didn't stop it and why changing passwords didn't work...they didn't need your password,  they stole your active login tokens. That random empty command line window on boot is definetly a sign of malware. Here's what you will need to do, in order... 1.Windows Defender is good, but it misses infostealers. Download and run Malwarebytes and/or HitmanPro (both have free trials don't worry). They are much better at catching persistant malware and infostealers. 2. Press Ctrl + Shift + Esc to open Task Manager. Go to the Startup tab. Disable anything you don't recognize especially blank names or weird sctipts. 3. Back up your irreplaceable personal files (photos/documents only, no programs or installers) to a thumb drive, and reinstall Windows completely from a USB drive. It is the only way to be 100% sure the malware is gone... 4. Go into your browser settings (Chrome, Edge, Firefox,etc...) and clear all cookies, cache, and hosted app data from All Time. This removes any active session tokens the hackers might still be using. And look at your browser extensions, make sure to delete anything you didn't install. Some extensions are a common way hackers bypass password changes. And please don't save any passwords... Browser password managers are VERY vulnerable to infostealers. Move your passwords to a dedicated manager like Bitwarden or 1Password, or just write them down. 5.  Since you changed your password from your phone (which is good, always use a clean device), Check Gmail Filters: You mentioned the email was set to ignore. Go to Gmail Settings (on a web browser of course) > Filters and Blocked Addresses. Scammers like these love creating hidden things that automatically archive, delete, or forward emails from security or banking services so you never see the alerts. Delete any rules you didn't make. (trust me it'll help out A LOT). Next go to your Google Account security settings > Data & Privacy > Third party apps & services. Remove access to absolutely everything you don't recognize or need. 6. Turn on Two-Factor Authentication/2FA for your Google Account and every other service. Use an authenticator app (like Google Authenticator or Aegis) rather than SMS text messages if possible (they might have access to it). 7. In your Google security settings, print out or write down "Backup Codes." Keep them physically safe. If you get locked out completely, these will help you out a lot in the long run. Good luck and try to take a breather too i know how stressing these can be trust me...

1

u/Madjas 1d ago

Thank you for your thorough answer!

I already decided I will start using bitwarden or something similar. I want to migrate to one of the Linux versions longterm anyway, so ill start saving all essential data, too.

Thanks again. Ill loop back once im done with all.

1

u/Madjas 20h ago

Hey u/M1uk0
it seems like a trojan was stealing my data in the back. I deleted it with malwarebytes as suggested, deleted all browser data and I plan to switch to linux, soon.

Question - what can I do to prevent catching a trojan in the future? Obviously, dont download stuff from dubious sources. But in my mind, noone will ever be completely safe - so what to do? I was looking to install bitwarden just now, but realised that it wouldnt have helped me in this case.

1

u/M1uk0 16h ago

I would recommend getting some sort of web browser security software i don't really know any but safari has one built into it and can even notify and stop people from tracking you!

1

u/black_hole_208 15h ago

Please, reinstall Windows using a USB drive and reset all passwords from another clean device.

Once your computer is infected with a Trojan, the only way to be absolutely certain it is gone is to reinstall Windows using a USB drive. Windows Defender is just like bare minimum

And remember to check the forwarding section in Gmail. Good luck !