HomeYoutubeFind out if you've been hacked and what to do about it

Find out if you've been hacked and what to do about it

Hacking attacks are a daily occurrence with many victims worldwide. Everyone is vulnerable to cyber hackers, but the threats are not the same for everyone.

The average person will likely face fewer threats than, for example, a senior politician, activist or CEO. High-profile individuals are targeted with phishing emails that attempt to steal secrets from corporate networks or initiate large transfers of money. You, your friends and family will likely face different threats: from individuals seeking revenge or , more likely, criminal groups using automated tools to obtain passwords.

“We all want to believe that we won’t fall victim to social engineering or other cyberattacks, but the truth is that even smart, aware people still get caught up in online scams that can have very damaging consequences,” says Jake Moore, a cybersecurity expert .“Many people will even admit that they don’t click on phishing emails, but they may still be involved in online scams.”

Understanding threats is key. Everyone has a threat model that includes things they care about most – what’s important to you may not be as important to someone else. You go online every day for a variety of reasons: from Facebook and Netflix to online banking and shopping. If one of your accounts is compromised, your passwords can be used on other online services or for financial transactions.

While Facebook, Twitter, Instagram , and other social networks are less likely to contain your credit card information, there are other types of risk. Compromised social media accounts can be used to post messages that could embarrass or defame someone, be used for harassment, or create a false image of who you are.

“Finding out that you’ve been hacked can be a pretty complicated task,” Moore adds. “One way to tell is if your accounts are lost, so it’s best to take some security measures to prevent this from happening in the future.” If you think you’ve been hacked, here’s what you can do about it.

Spot an unusual behavior

hacking

The clearest sign that you've been hacked is when something has changed. You might not be able to access your Google using your regular username and password, or there have been suspicious purchases charged to one of your bank accounts. These are pretty obvious signs that you've been hacked in some way — and hopefully your banks will catch any suspicious payments before things get worse.

However, before one of your accounts is compromised, there may be warning signs. The account someone is trying to access can alert you to unusual login attempts: for example, Facebook and Google will send notifications and emails notifying you of attempts to access your account. This usually happens if someone tried to log in and failed, but the notifications can also mean that someone has successfully logged in from unknown locations.

Rarely does a day go by without some company, app, or website suffering a data breach – from Adobe to Dungeons and Dragons. These breaches can include phone numbers, passwords, credit card information, and other personal information that would allow criminals to steal your identity, among other threats. Companies should be able to quickly let you know if they’ve been hacked, but using a breach notification service can also do the same. Services like Haveibeenpwned and F-Secure will let you know about past data breaches, but they can also alert you to new instances where your information has been exposed by compromised accounts.

Take back control

hacking

Regaining control of an account may not be simple – depending on who has access to it – and there is a possibility that it may involve multiple administrators.

First of all, you should contact the company you created your account with. Each company has its own policies, procedures, and recovery steps when it comes to compromised accounts – which can be easily found through an online search.

When recovering a hacked online account, you are likely to follow different steps depending on whether you can still access it or not. If you can access the account, companies will ask you how it was compromised and suggest steps to take. If you can’t access it, you will likely be asked to provide more information about how you used the account (previous passwords, email addresses, security questions, and more). If an individual or group claims to have accessed your account and has sent you messages about it, you should not click on any links they send, as they may contain malicious material and/or further attempts to access personal information.

Account recovery through the company where your account was compromised is the first step to regaining control. You need to make sure that all the apps and software you use (on your phone and PC) are up to date. Your next step will depend on the type of breach. For example, if you can get back into a compromised email account, it's worth checking your settings to make sure they haven't been tampered with, such as having a setting enabled to automatically forward all your emails to another account.

You should change the password of the compromised account and any other accounts that use the same password, and reach out to anyone who may have been affected by the breach. For example, if messages have been sent from your Instagram account or you are forced to create a brand new social media account, you may need to inform your friends and family of the new account details.

Secure everything

Find out if you've been hacked and what to do about it

The best way to reduce the chances of hacking is to limit your attack surface. By giving hackers less space, you reduce the chances of them attacking you.

“Your information is the key to a successful attack, so minimizing your personal information available online will push the attacker to the next less fortunate victim,” says Moore. If your accounts have been compromised once and are being attacked by an organized group, there’s a greater chance that you’ll be targeted again.

When thinking about your online presence, you should consider how much information you share there. “When you post your photos on Instagram, or you post on Facebook, or you tweet something about your location, people can take that stuff and use it against you.”

In practice, there is a lot that can be done to create online accounts. Everyone should use a password manager to create and maintain unique, strong passwords. No one should use the same password on multiple websites, even if you perceive the risk of a breach to be low.

If one of your accounts has been compromised, you should check your other online accounts by updating passwords and checking your security settings. When updating accounts, you should also use complex security questions, where possible with answers that only you know.

In addition to a password manager, multi-factor authentication (MFA) should be enabled for as many websites and services as possible. This is one of the most effective ways to protect your accounts from hacking. The most common type of MFA is two-factor authentication, where another piece of information, on top of your password, is required to log in to a service. This is usually an SMS, an authenticator app, or a physical security key.

For those with higher threat levels, there are many additional measures that can be taken. To increase your online privacy and anonymity, you can use a VPN, Tor , or Google's advanced protection program.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS