We'd like to remind Forumites to please avoid political debate on the Forum... Read More »
We're aware that some users are experiencing technical issues which the team are working to resolve. See the Community Noticeboard for more info. Thank you for your patience.
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
PC been hacked how do I protect my bank accounts ?
Options
Comments
-
km1500 said:Sg28 said:km1500 said:it would be interesting to know how clicking on a link and downloading an attachment and even running an attachment would lock you out of your Steam account and your google account.
does anybody have any idea how this works?
2 -
km1500 said:Sg28 said:km1500 said:it would be interesting to know how clicking on a link and downloading an attachment and even running an attachment would lock you out of your Steam account and your google account.
does anybody have any idea how this works?
1 -
running an arbitrary exe on your system would cause user account control to kick in and I can't believe someone would just arbitrarily say yes please run this
changing your Google password when you are logged in does not require 2fa as you say but it certainly requires you to enter your old password first so an exe could not do that
I am not 100% the full story is being told here1 -
User random and unique passwords for every website and use 2FA wherever possible and make sure you use it when it's anything you value.
If you're trying to use almost any online service and you use the "forgot password" link what does it do nine times out of ten it sends you an email.
Pay massive attention to securing your email account as it's essentially the key to your online life and if the bad guys can get into it and you can't they can really mess up your life.
3 -
km1500 said:running an arbitrary exe on your system would cause user account control to kick in and I can't believe someone would just arbitrarily say yes please run thisI wouldn't describe myself as a Windows user, but have to use it at work, and UAC only kicks in on executables under certain circumstances. Nevertheless, people do get fatigued by this and just click through it. The last PC I bought for home use had the UAC slider dragged right down to the lowest level on the preinstalled Win11 Home. It was actually not so easy to set it up to log in as limited user and prompt for elevation to a separate admin account when needed. Perhaps that's a drawback of home vs pro or enterprise.km1500 said:changing your Google password when you are logged in does not require 2fa as you say but it certainly requires you to enter your old password first so an exe could not do thatThat's why step 1 is getting the user to enter their "old" password, either by clearing the cookie in their local browser profile and waiting for them to get prompted for it naturally, launching a phishing login page in the default browser, or some other technique. This would work even on a limited user account.km1500 said:I am not 100% the full story is being told here
1 -
km1500 said:running an arbitrary exe on your system would cause user account control to kick in and I can't believe someone would just arbitrarily say yes please run thisThere are ways round that. One way is to change a program that runs legitimately.km1500 said:changing your Google password when you are logged in does not require 2fa as you say but it certainly requires you to enter your old password first so an exe could not do that
I am not 100% the full story is being told here0 -
I also find this all a bit hard to believe. You often read about people being “hacked” when it’s nothing of the sort. The more likely explanation is that this person uses the same username and password for multiple sites and someone has got access to them via a credential leak. If it was a file that they ran then what website were they on, why would they ignore the warnings that any modern system would throw up, etc.? It’s not credible unless there was also some element of social engineering too.
2 -
I for one would like to learn more about what happened and wouldn't want to be dismissive or disparaging of the OP/son and as a consequence deter them from coming back and sharing more. These incidents can contain useful learning points. Although it occurred under different circumstances as described here, I'm reminded of the incident where well known scambaiter Jim Browning fell for a scam involving his Youtube channel and graciously described it in detail here. Hopefully the OP's son will recover his online accounts and then we can dig a little deeper into what happened and how.1
-
NithyaH said:I also find this all a bit hard to believe. You often read about people being “hacked” when it’s nothing of the sort. The more likely explanation is that this person uses the same username and password for multiple sites and someone has got access to them via a credential leak. If it was a file that they ran then what website were they on, why would they ignore the warnings that any modern system would throw up, etc.? It’s not credible unless there was also some element of social engineering too.Ex Sg27 (long forgotten log in details)Massive thank you to those on the long since defunct Matched Betting board.0
Confirm your email address to Create Threads and Reply

Categories
- All Categories
- 351K Banking & Borrowing
- 253.1K Reduce Debt & Boost Income
- 453.6K Spending & Discounts
- 244K Work, Benefits & Business
- 598.9K Mortgages, Homes & Bills
- 176.9K Life & Family
- 257.3K Travel & Transport
- 1.5M Hobbies & Leisure
- 16.1K Discuss & Feedback
- 37.6K Read-Only Boards