if this is happening right now
Disconnect the infected computer from the internet, then do everything below from a different device — a phone on mobile data is fine. Anything you type on the infected machine can be stolen again.
~/help
Malware stole your passwords and logins. Here's how to get everything back.
Written for people who are not security experts. If you downloaded a game, a crack, a mod or a file from someone and then started losing accounts, this is almost certainly what happened — and the order you do things in matters more than anything else.
Do these five things first, in this order
The order is not optional. Changing passwords while the infected machine is still running online just hands the attacker the new ones.
- 01
Get the infected computer off the internet
Unplug the network cable or turn off Wi-Fi. Don't shut it down if you might want evidence later — just disconnect it.
- 02
Switch to a clean device
Another computer, or your phone on mobile data. Everything from here happens there, not on the infected machine.
- 03
Change the password on your main email account first
Email is the master key — whoever controls it can reset everything else. Do this one before any other account.
- 04
Sign out of all devices, everywhere
This is the step people skip and it's the one that actually evicts the attacker. Look for “sign out everywhere”, “log out of all sessions” or “manage devices” in each account's security settings.
- 05
Check what they added to your accounts
New recovery emails or phone numbers, new two-factor apps, new email forwarding rules, new authorised apps. Attackers add these so they can walk back in after you change the password. Remove anything you don't recognise.
What did the malware actually take?
Modern info-stealers are not subtle. They run once, copy everything of value in a few seconds, send it to the attacker and often delete themselves. Assume all of the following left your machine.
Saved passwords
Everything saved in Chrome, Edge, Firefox or Brave. Browsers encrypt these, but the malware runs as you, so it can decrypt them exactly like the browser does.
Your logged-in sessions
The files that keep you signed in. These are the dangerous ones: they let an attacker enter your account without your password and without triggering two-factor, because that check already happened when you logged in.
Autofill and card details
Names, addresses, phone numbers and anything else the browser fills in for you.
Crypto wallets
Wallet files on disk and browser wallet extensions. Also any file with a name like seed, backup, wallet or recovery.
Messaging apps
Desktop Signal, WhatsApp and similar. Enough to read your conversations and in some cases to impersonate you.
Email programs, FTP and SSH keys
Saved credentials from Outlook, Thunderbird, FileZilla, WinSCP and developer tools.
Files it was told to look for
Operators configure it to grab documents, images and text files by name or extension. Screenshots of your desktop are common too.
This is why an antivirus scan is not enough. The theft already happened. Cleaning the machine stops it happening again; it does not undo anything.
They changed my password and recovery options — am I locked out for good?
Usually not, but the normal “forgot password” link won't work any more. You need the provider's account recovery process, which verifies you as a human using what you remember about the account.
What makes recovery succeed
- Use a device, browser and internet connection you have used with that account before. Providers weigh this heavily.
- Answer with things you actually remember — old passwords, the month you created the account, names of folders or contacts. A confident partial answer beats a wrong precise one.
- If you have ever bought anything through the account, have the order details ready. Purchase history is strong proof.
- Expect to try more than once, and expect it to take days. Repeated submissions with better detail are normal, not a sign it failed.
Where to start, by service
Type these addresses into your browser yourself rather than clicking a search result — including from this page. Fake recovery pages are common and they specifically target people in your situation.
- Microsoft / Outlook / Xbox
account.live.com/acsr - Google / Gmail / YouTube
accounts.google.com/signin/recovery - Instagram
instagram.com/hacked - Facebook
facebook.com/hacked - Discord
support.discord.com - Steam
help.steampowered.com - Apple
iforgot.apple.com
If an account is tied to a phone number you still control, or to a bank card you still hold, say so in the recovery form. Those are among the strongest proofs of ownership available to you.
They're posting from my Instagram but my password still works
That's stolen-session theft rather than password theft. The attacker is riding a copy of your logged-in state, so your password never stopped working and no login alert ever fired.
The fix is the same on every platform: change the password, then explicitly end all active sessions — Instagram calls it “Log out of all sessions”, Google calls it “Sign out of all devices”, Discord has “Log out of all known devices”. Until you do that, the copied session keeps working no matter how many times you change the password. Then turn two-factor on, or off and on again, which invalidates old tokens on most platforms.
What about stolen cryptocurrency?
Be prepared for the honest answer: if crypto left a wallet you control, it is almost certainly gone. Transactions are final and nobody can reverse them. Anyone who tells you otherwise for a fee is scamming you a second time.
What is still worth doing:
- Move anything remaining to a brand new wallet, created on a clean device. Never reuse the old seed phrase — the attacker has it.
- Revoke token approvals from the old wallet, using the revoke feature in your wallet software itself rather than a site you found in search results.
- If funds sat on an exchange rather than your own wallet, contact that exchange immediately. They can sometimes freeze accounts and stolen funds are occasionally recovered when they pass through one.
- File a police report, and in the US also an IC3 report. It rarely gets funds back but it creates the record you'll need for insurance, taxes or any future case.
- Never enter your seed phrase into anything, ever, including a "recovery tool". That is the single most common follow-up scam.
Watch out for the second wave of scams
Searching for help after being hacked is itself dangerous. Those searches are saturated with paid "account recovery services", "ethical hacker for hire" sites and fake support accounts that reply within minutes on social media. They exist because people in your position will pay anything.
- No legitimate recovery ever costs money. All of it is free and on the provider's own site.
- Real support will never DM you first, and never asks for your password, seed phrase or a 2FA code.
- Anyone guaranteeing results is lying — no one can guarantee a provider's decision.
- If someone contacts you about your hack unprompted, they are involved or they are a scammer.
How do I clean the computer?
Reinstall Windows from scratch. It sounds drastic, but these infections routinely arrive bundled with other tools designed to survive removal, and you cannot verify a clean-up worked. A reinstall you can trust.
- Back up your personal files first, but not programs or installers.
- Reinstall from Microsoft's official media, not a recovery partition that may itself be tampered with.
- Only sign back into accounts after you've reset their passwords and ended their sessions.
- Don't restore a system image from after the infection — it brings the malware back.
How do I stop this happening again?
- Stop saving passwords in the browser. Use a dedicated password manager with its own master password — stealers grab browser stores by default.
- Switch to passkeys where offered. They can't be copied off your machine the way a password or session file can.
- Cracked games, "free" paid software, cheat tools and mods from strangers are the single most common delivery route. That's what happened here.
- Keep crypto of any real value on a hardware wallet. It cannot be stolen by software alone.
Common questions
How do I know if malware stole my accounts?+
Common signs: you get locked out of an account you know the password to, friends receive messages you didn't send, your email has new forwarding rules, security settings changed without you, or money moved from a crypto wallet. If you installed a cracked game, a 'free' program or a file someone sent you shortly before, that is the likely source.
I changed my password but I'm still getting hacked. Why?+
Because the attacker probably isn't using your password. Info-stealers copy your logged-in browser sessions, which already passed your password and two-factor check. Changing the password does not end those sessions. You have to sign out of all devices, which every major service offers, and you have to do it from a clean device after the infected computer is off the network.
The hacker changed my password and my recovery email. Can I still get my account back?+
Often yes, but it takes a formal account recovery request rather than the normal reset flow. Every major provider has one. It works best from a device, browser and network you have used with that account before, and you should answer with old information you genuinely remember rather than guesses. Expect it to take days and to need more than one attempt.
Can I get stolen cryptocurrency back?+
Almost never. Blockchain transactions are final and there is no support desk that can reverse them. If funds were on an exchange rather than your own wallet, contact that exchange immediately because they can sometimes freeze an account. Anyone who promises to recover your crypto for a fee is running a second scam on you.
Is it enough to run an antivirus scan?+
No. By the time you notice, the data has already been copied and sent. Removing the malware stops further theft but does not un-steal anything, and stealers are often bundled with other tools that survive a clean-up. The safest option is to reinstall the operating system, and to change your passwords from a different device rather than the infected one.
Should I pay someone to recover my account?+
No. Searching for account recovery help surfaces a lot of paid 'recovery services' and outright 'hacker for hire' sites. They target people who are panicking. Every legitimate recovery route is free and runs through the service's own website.
for the technically inclined
This guide came out of taking one of these infections apart. If you want the full analysis — the fake game, the four-stage loader, how the payload was hidden inside its own build file, and the indicators for hunting it — that's written up separately.
read the technical analysis →