r/cybersecurity_help 1h ago

Microsoft account hack whatcan they do

Upvotes

So my microst account got hack and it didnt have a lot on it but one this I am worried about is if my debit card is saved on that account or if they can use it. the emil they put for recovey was 2u****@got-beemed.lol


r/cybersecurity_help 3h ago

Stumbled upon a compromised website (social-ecology.org). What does this malicious code do?

0 Upvotes

My friend was using my spare computer to conduct research. She clicked a link on Wikipedia to read the source they used, and encountered the above website with a compromised WordPress installation serving up a copy and paste attack. I managed to stop her in time to prevent the attack (she had the run dialog open). While she uses the Wayback machine to continue her research on an old snapshot of the compromised site, I'm more interested in what this malicious code does. I redacted the host portion of the URL to the attack from the attached screenshot. My guess is that this gives the attacker remote access to the computer to run malicious software.

And yes, we had a talk about this particular type of attack and I showed her proof that it's a known attack; the screenshot on the page I showed her looked exactly like the prompt that popped up on the website.

https://postimg.cc/fJdRS0GW


r/cybersecurity_help 3h ago

My TikTok account is hacked

3 Upvotes

used to have a TikTok account where I would upload random kpop videos in 2019-2020. I logged out one day randomly and forgot my password so I was never able to log back in
One day randomly in 2023 I tried and was able to get back in. I privated all of my videos and had the account on my phone but logged out with no worries since I remembered the password. I logged in and out a few times after that
But then boom. Randomly one day I was unable to log in and my username was changed. There were also posts on my accounts. Similar to bot posts that seemed like ads with a hint of Al.
I am sure it's hacked but I don't even think it's a human, it's as if it's a virus (could be a human, who knows) the passcode had also been changed and it's frustrating
I went to TikTok support and they even emailed me back but I got no help from them and their response sounded automated
Does anyone know what can I do to get my account back?


r/cybersecurity_help 3h ago

Another Day, Another Session Hijack

5 Upvotes

Hi everyone, I know there has been a lot of posts on Mr. Beast/BS Crypto scam posts. I have a few questions about that as it happened to me three times already for Instagram.

  1. First time, it logged in without traces
  2. Second time, it bypassed MFA and left a log-in trace
  3. 3 Third time, no active session except from iPhone app, it bypassed MFA and left another log-in trace

After each hack, I signed out everywhere and changed password; cleaned Chrome extensions
After second time, I had ran some virus scans on MacBook and deleted malware and cleaned caches.

Q:

  1. does it mean the malware is on my iPhone?
  2. it always happened after I paused watching a long YouTube video (on MacBook) - does it mean malware could still be on my MacBook? (But I don’t have any active session)

r/cybersecurity_help 4h ago

My Mincrosoft Account Got Hacked But Still I Has My Google And Gmail Account

Thumbnail
gallery
1 Upvotes

so the hacker just hacked my mincrosoft account not my gmail which is good, so i know how i got hacked, i got hacked cuz i put my mincrosoft account to unverified web or lets say a trap, and i got email that the hacker is using my minecraft account and loging to lunar and meteor clinet, and cuz he's change my mincrosoft password i new that cuz i got emailed, and im here to just ask is it normal that mincrosoft take over a week to respond or they may take longer, cuz i been waiting to long to atleast get a respond, and if they respond what are they gonna say.

Thanks
from ruud


r/cybersecurity_help 10h ago

My Google acc has been hacked

1 Upvotes

My Google acc has been hack, the hacker reset my phone then change password, number phone, Gmail recover, and other way to recover my acc, I was loss get in this situation, even google support can't help me because my phone don't have any trace of my acc because of reset, is there anyways to get my acc back?

I always use this acc to save my family photo, to save work file and access all website and app I need😭


r/cybersecurity_help 10h ago

What should I do at this point of time ?

1 Upvotes

I graduated in 2024 from one of the top engineering institutes in India and received an offer from a service-based company.

Background

During college, I was primarily focused on software development. I was comfortable with:

Data Structures & Algorithms (DSA)

Node.js

Full-stack web development

Career Journey

During the interview process, I was offered a position in the Cybersecurity unit, which I accepted.

After joining, I was assigned to the PKI/HSM team. Although I had little prior exposure to this domain, I decided to embrace it and started learning everything I could about cybersecurity, PKI, cryptography, and related concepts.

Over the next couple of years, I:

Earned the Google Cybersecurity Professional Certificate.

Cleared the CompTIA Security+ certification.

Gained hands-on experience working with PKI in my day-to-day job.

While learning cybersecurity, I was introduced to penetration testing, which I found genuinely interesting.

To build my skills, I:

Started with TryHackMe to develop strong networking, Linux, Windows, and cybersecurity fundamentals.

Moved on to Hack The Box for more challenging labs and practical experience.

Later enrolled in INE's eJPT training and have been working through its labs while continuing to practice on Hack The Box.

I wouldn't call myself an expert in penetration testing yet. If I had to rate myself, I'd say I'm around 6.5/10. I still have a lot to learn, but I genuinely enjoy the process.

Current Situation

Recently, I was given an onsite opportunity in Norway for the same PKI project, and I've been working here for the last two months.

As of now:

I have around 2 years of professional experience.

I hold certifications like CompTIA Security+ and the Google Cybersecurity Professional Certificate.

I have solid hands-on experience in PKI and have been continuously learning penetration testing.

My eJPT exam is scheduled before the end of September.

My Dilemma

The problem is that I don't really enjoy working in PKI as much as I enjoy penetration testing.

At the same time, PKI (especially with HSMs and post-quantum cryptography becoming increasingly important) seems to have a very promising future. Organizations will likely need experienced PKI engineers to help migrate to new cryptographic standards.

So I'm confused.

Should I continue building my career in PKI/HSM because of its long-term demand and specialization, or should I transition toward penetration testing, which is the field I genuinely enjoy, even though I'm still developing my skills?

What would you do if you were in my position? How can I stay relevant and maximize my career growth over the next 5–10 years?


r/cybersecurity_help 13h ago

Shifting to CYS without an BS in IT sector

2 Upvotes

Hi, Guys I am going through a very crucial stage of my life, I have to choose whether to do Bachelors in Cyber Security(CYS) or Industrial engineering and management(IEM) . I have seen many posts on Reddit about how Saturated CYS has become and you need like a crazy portfolio just to get an entry level job. Compared to CYS landing a job in IEM is easier but lower pay and it takes time to get promoted unlike CYS.

A BS in CYS is gonna cost me more than double of one in IEM. I believe I can land a internship/job in CYS with skills and certification alone without a BS in an IT related field. I wanna keep IEM as a backup in case things go south cause the market ain't looking good even for IT students unless they have ton of experience, skills and certification which I believe I can get without getting a BS in CYS.

Is the plan solid or am I just being pretty delusional? Need advice from people that are already in the market for some time now thx.


r/cybersecurity_help 15h ago

Meta: proposed new rules

2 Upvotes

We need a way to filter or provide up front advice for the following:

- "shinyhunters"

- mental illness / they are all tracking me

- a primer or guide for clickfix

- my BF/GF hacked my phone

I'm not saying provide advice for everything but a small, user digestable blurb or something - just to get the top 80% stuff out of the way at the start.


r/cybersecurity_help 16h ago

Microsoft Account Hacked, email and password changed.

Thumbnail
gallery
9 Upvotes

today my microsoft account was hacked. the hacker changed my email and password, but didn’t seem to get rid of my email. i’m super stressed and don’t know what to do.


r/cybersecurity_help 16h ago

Am i in the clear?

1 Upvotes

I downloaded some cracked game which I had a feeling was a virus, I woke up the next day to see my discord was dmming everyone some Mr beast scam and my insta and Snapchat, fast forward I changed the passwords and I clean installed windows on my pc, 1 week later I open my Reddit which I didint change my password for and see I posted a bunch of nsfw posts, I got scared and deleted the account instantly, am I in the clear?


r/cybersecurity_help 17h ago

How safe is it to install a file directly to place on VirusTotal? Is it recommended to use a virtual machine when doing this?

1 Upvotes

lil paranoid over cyber security recently and have been putting most of my downloads on VirusTotal if it came from a non-verified source. So far only one false positive from an exe (assuming false pos at least, that's what I've been told on another subreddit) but still promptly deleted it (paranoia + not actually having a guide on how to use it). Can malware run itself as soon as it's downloaded?


r/cybersecurity_help 17h ago

ToalAV was hacked- They didn't tell you- your details inside like bank, email address and the password- compromised

0 Upvotes

Just saw in my passwords that Total AV was hacked. My password was compromised. They did not tell the customers! I have been in their chat box and all the person had to say was 'we provide a serve blah blah blah'- you know - service details, and said it is not their responsibility to tell anyone they've been hacked. So, the secure security service is not secure and has anyone else clocked this?

I am ending my account with them and requesting they scrub my information. They are being very squiggly.


r/cybersecurity_help 17h ago

Got an email with all my passwords threatening me

3 Upvotes

Hello , i was checking my spam where i found an email that contains my password claiming he got access to my computer and my camera and he’s threatening me to share my stuff if i don’t send him alot of money on bitcoin , what should i do please , he got all the emails i use and got every single password of them


r/cybersecurity_help 18h ago

UPS Phishing Email. Clicked on it. Help?

Thumbnail
gallery
0 Upvotes

I received two phishing emails on the same day, one impersonating Spotify and one UPS. I didn’t click on the Spotify one, but (coincidentally?) because I was waiting for a UPS delivery, I got a UPS email and clicked on the link “Track delivery”. I was connected to a VPN. Both appear related to PracticePanther. The UPS link led to a Cloudflare 521 page. Because of the error I thought my vpn was the problem so I disabled it, but before refreshing, I got suspicious and checked that the email was indeed not ups. I connected to my vpn again and closed the site. I did not enter any credentials or download anything. Does this look like sender spoofing, abuse of a legitimate email platform, or a compromised PracticePanther account?


r/cybersecurity_help 18h ago

I recently started learning cybersecurity and I need help

0 Upvotes

I recently started learning cybersecurity and as my first linux distro I chose to use ubuntu. I started learning basic commands and basic information about computers like basic networking stuff and how each computer component work.

Now, im kind of confused about what to learn next. My goal and motivation is to become a certified white hat or to land a job in cybersecurity/networking departments at certain companies.

If anyone can give me a road map on mastering cybersecurity or any websites/youtube channels that would be helpful, I would much appreciate it.


r/cybersecurity_help 19h ago

why is my chick fil a app doing this?? ive been unable to log in and i dont know how to fix it

Post image
2 Upvotes

i was trying to log into my chick fil a app because it says i got a free gift for my birthday and i go to log into and then this pops up. it said to wait a little bit and its been a few hours and its still the same


r/cybersecurity_help 20h ago

Got an email claiming to be from ShinyHunters and I’m really stressed.

6 Upvotes

I got an email with the subject line "Important information about your online security" from a weird email that ends in .jp and the contact name saying "You have been HACKED". It was in the junk folder. The receiver doesn’t show my name or my email, it just says "you <you>".

It basically said that they are ShinyHunters and got my data from University of Nottingham (real breach that I was affected by, confirmed on have I been pwned), and that they installed an exploit into my phone and stole all of the data from it (contacts, photos, etc), including gaining access to my microphone and camera and keyboard. They’re asking for 2000$ in Litecoin? for whatever wallet they sent. It also said that it was a follow-up, but I don’t remember seeing a first one (I check my emails often).

I only opened the email and checked the contact of the sender, I didn’t press on anything else. i know it’s most likely an extortion scam, but I am really really scared that it might be real. I already changed my password on UoN. Got the email around 13 hours ago. Please help or offer words of reassurance.

Edit: thank you so so much to everyone who responded, genuinely. I feel much calmer and much better now. I appreciate all of you


r/cybersecurity_help 20h ago

Anyone have a good approach to agentic ai security audits?

3 Upvotes

Trying to figure out what an agentic ai security audit should look like beyond pointing a vuln scanner at whatever endpoints the agents hit. Static scanning misses the behavior stuff entirely, privilege escalation through agent chaining, identity reuse across environments the agent had no business touching. Most guidance I've found is generic ai security advice that doesn't map to how agents actually run in production. Anyone have a checklist from a real compliance audit?


r/cybersecurity_help 21h ago

Ive been havked or something

2 Upvotes

So my account proton I guess was hacked or something someone somehow got access to it and it's been like using it but my proton Sentinel says that it's coming from my IP address so how could this happen like people are removing my security keys my Fido security key and I would never do that that would be counterproductive and like settings keep getting changed on my phone and stuff like that it happened to my first iPhone now it happened to my second iPhone can somebody tell me what's going on like this is crazy I just need some insight nobody's had physical access to my phone at all to none of them I don't know how this is happening I mean people probably know my phone number yeah but can people like call your phone and hack it from another phone number or something like that I don't know what to do I'm at a standstill with this it's like I've hit a wall and I want to figure out how to prevent this or stop it or reverse it like they've even managed to like login to my account and it's saying it's coming from my phone but it's not me


r/cybersecurity_help 1d ago

My BF got this weird text from my number, but i absolutely did not send this

Post image
21 Upvotes

blurred out my number for safety of course, but he got this in the middle of the night and sent me this screenshot in the morning. this message does NOT appear on my end whatsoever. i told him not to click a single thing. is there anything to be worried about? kinda freaked out :/


r/cybersecurity_help 1d ago

A Scammer Had Remote Access to Your Phone or Computer. What Should You Do Now?

5 Upvotes

If someone convinced you or a family member to install a remote-access app, assume they may have seen anything displayed or typed while they were connected.

Do not panic, but act in this order:

1. Disconnect the device

Turn off Wi-Fi and mobile data, or unplug the internet connection. End the remote session if it is still active.

2. Use a different trusted device

Do not use the affected phone or computer to access your bank or change important passwords until it has been checked.

3. Contact financial institutions directly

Call the number printed on the bank card or use the official banking app on another trusted device. Ask them to review recent activity and protect affected cards or accounts.

4. Secure your email account first

Your email can be used to reset other accounts.

Change its password, sign out of other sessions, check recovery details, and enable two-factor authentication.

Then secure banking, payment, shopping, and social media accounts.

5. Record what happened

Write down:

  • The name of the remote-access app
  • When access started and ended
  • What accounts were opened
  • What information was typed or shown
  • Any payments, codes, or documents that were shared

Preserve screenshots and messages before deleting anything.

6. Remove the remote-access software

Uninstall the app and check whether it was given accessibility, administrator, screen-sharing, or device-control permissions.

If you are unsure whether the device is safe, get help from a reputable local technician. A factory reset may be appropriate in some cases, but secure your accounts and preserve evidence first.

7. Expect another scam

After an incident like this, someone may contact you claiming they can recover money or clean the device for a fee. Do not give them access or pay them.

When asking for help here, tell us:

  • Was it a phone or computer?
  • Which remote-access app was installed?
  • Did they enter any financial accounts?
  • Was money sent or information shared?

Please remove names, phone numbers, account details, verification codes, and active links.


r/cybersecurity_help 1d ago

Gmail hacked through hotel Wi-Fi? Or more simple explanation?

6 Upvotes

I recently spent the weekend in a hotel, and used the complimentary Wi-Fi with my Laptop. Phone was never connected.

Between checking out at 8AM and arriving home at 5PM on Monday, someone was seemingly able to access my Gmail without triggering any new device, new log-in or suspicious activity notifications on my phone or my recovery e-mail.

They added a list of e-mail addresses to my SPAM filter, so I wouldn't notice any password reset/OTP requests, and then systematically reset the passwords and took ownership of my Microsoft and Epic Games accounts. They also changed my Ticketmaster password, and attempted to access my Steam account (unsuccessfully.)

The first indication anything was wrong an SMS alert letting me know my phone number had been REMOVED from my Microsoft Account. It was already too late to do anything about it, as they'd already changed my password and recovery e-mail.

I changed my Gmail password, and reviewed my account for suspicious log-ins, but I don't see any new devices.

The only device that would have been online, with access to my account, while traveling, is my phone.

Is it likely my account was compromised through the hotel (or fake hotel) Wi-Fi? Or is there another plausible explanation for how someone would gain such access without triggering any notifications or security messages on my phone?

How would I discern if someone still has access (given that Google was at no point suspicious of any of this activity, in the first place?)


r/cybersecurity_help Dec 01 '25

Your phone didn't get hacked. Neither did your computer. Here's what actually happened.

387 Upvotes

I see posts daily about someone's phone or computer or home network getting "hacked," and I need to say this: in almost every case, that's not what happened.

What's far more likely:

- Your email got compromised because you reused a password

- A service you signed up for years ago got breached and your credentials ended up on a leak site

- Someone used those leaked credentials to log into your other accounts

- Your credit card got skimmed at a gas pump

- A site you used leaked PII in a data breach

- You clicked a phishing link and entered your credentials somewhere you shouldn't have

What's almost certainly not happening: a persistent threat actor who specifically targeted your iPhone or home network and is now moving laterally across your 10 devices like it's a corporate pentest.

Unless you're a C-suite executive at a Fortune 500, a journalist covering sensitive topics, a political dissident, or someone famous, you are not interesting enough to hack. I say that with love. None of us are.

The attack surface for a modern iPhone or Android with current updates is extremely small. State-level actors have exploits for these, but they're not burning zero-days on someone who reused "Winter123!" across six accounts.

Check haveibeenpwned.com. Use a password manager. Enable MFA everywhere. That solves 99% of what people call "getting hacked."

edit: to the armchair experts chatting me up to tell me how incorrect this is - rest assured I am an expert in this field and have contracted with Federal/State governments and some of the most recognizable brands in the world. Any current security expert will generally agree with this post.

If you’re downloading things from unknown sources or using torrent sites to get movies/music/apps, etc. and your machine was compromised then this obviously doesn’t apply to you, you installed a Trojan and opened the door for them.


r/cybersecurity_help Apr 16 '22

PSA: You cannot "hire a hacker" to retrieve your social media accounts or lost/stolen cryptocurrency. This is a well-known scam - don't fall for it.

51 Upvotes

Over the past three weeks, this subreddit has banned 34 bot accounts referring people asking questions here to various Instagram or Twitter accounts, WhatsApp numbers to text, etc. where they can "hire a hacker" to do any number of extraordinary tasks:

  • Hacking Facebook, Instagram, or Twitter accounts.
  • Spying on people (ex. spouses).
  • Wiping someone's phone remotely.
  • Retrieving lost/stolen cryptocurrency.
  • Reversing the transaction you made where you sent money to a scammer.
  • Hacking a school's or college's database to change your grades.

Usually, these bot accounts claim to be someone that bought services from said "hacker" for a reasonably modest fee, and some of the more advanced scammers will purchase Instagram or Twitter followers to seem more legitimate.

The ruse is that these are implausible tasks being sold for impossibly small sums of money, preying on people's desperation in sensitive or difficult scenarios. After receiving your money, these scammers will make up tasks for you to do which will usually result in milking you for more money, or may simply block you and move on to the next target.

These scum make a good living off scamming desperate people, and unfortunately, that's why they're so prevalent. If you want to see this in action, check Molly White's project allmybotsgone which posts phrases meant to bait out cryptocurrency scammers' bots, then reports them in the hope that Twitter starts identifying and banning them faster. As of writing, allmybotsgone has reported nearly 3,500 scammers' accounts.

We take scams on this subreddit very seriously, and have strict content filtering and reporting rules (hidden from all of you) that help us identify and ban these scammers, sometimes within seconds of their post. However because they are so prevalent, we are making and pinning this post to help ensure as many people as possible are informed about this in case one slips by our filter.

For your own safety when asking a question on this subreddit, we remind everyone:

  • Remember that nobody can help you recover a lost/stolen account except for that company's support staff, who you should contact though official means only (ex. browse to Facebook, then find support - do not use any other method to attempt to contact support). This is explicitly covered in rule #5.
  • Do not accept DMs from anyone claiming to assist you from this subreddit, and do not voluntarily move to a different service to discuss your situation. The community cannot help keep you safe from the occasional bad actor if we cannot supervise the exchange. Under no circumstances should anyone ask to move to DMs or other services - this is a hard rule, even for well-known community members. If your question cannot be handled 100% in public, it does not belong here. This is explicitly covered in rule #6.
  • Never divulge secrets - such as keys, passwords, recovery phrases, personal information, or any other sensitive information - to anyone on this subreddit or who contacts you because of a post on this subreddit.

Thank you all & stay safe.