Back to blog

How to give hackers the boot

16 July 20264 min read
passwordshacked credentials

I got a call last week from a family friend, their first words: "I think I've been hacked."

They'd been receiving thousands of emails from someone, which itself is just spammy and not a sign of trouble, but what got my attention was that the language of all of the Outlook stuff around the emails had been changed to Vietnamese(!)

Yep, definitely hacked.

More than that, my friend was starting to receive SMS messages on their phone with two-factor authentication codes for their bank, their share trading account, even their Netflix!

So not only had the hacker broken into the email address using a weak password that was probably part of a data breach, now the hacker was using that same email/password combo to get into a bunch of other websites, all of them probably scraped off the email inbox (the hacker sees an email in the inbox for Commonwealth Bank, and has a go at logging in there, and what do you know, same username and password!!)

There are a lot of preventative measures to stop this mess from happening in the first place, and I'll get to those, but first we need to kick the hacker out!!

Kicking Out the Hacker

  1. Translate the page. (Oddly enough) use the Google Translator that comes with Chrome to translate the Vietnamese; it's bloody hard to find the "settings" button in a language you've got no idea about!!
  2. Change the password. Head to the account settings page, head to security, and then change the password.
  3. Log off on all devices. Pick the option in the security setting to "Log off on all devices". This means the hacker gets punted off on their end over in Vietnam, and when they try to log in with the username and password that got them in in the first place, they're blocked by the new password.

Success!

The last step is to clean up loose ends: call the highest risk places (bank, share trading platform) and let them know about the breach. Then, one by one, update all the places where that hacked password was being used, make the password change (to a different, unique password!), and then do the same "logout all devices".

Pretty tedious. But luckily no money lost! The scary bit is someone having access, even if briefly, to your inbox and all your contacts. The mind boggles with what they could do with that information!!

So, How to Prevent This in the First Place

One: Password manager. If you're like the vast majority of people, you use passwords that you keep in your head - often the same one for many logins. This hack was a perfect example of how brittle this is: one password hacked and the hacker gets access to your whole online life. Disaster. To stop this, get a password manager (like Bitwarden) and generate a random, fresh password for every website you use. It may sound tedious, but if you don't do it, it'll be tedious and stressful (and, potentially, expensive) if your password is ever guessed or part of a data breach. The best time to start this is yesterday, and, failing that, today. Get into the habit of logging in with your old password, and that being the trigger to reset the password to something that's stored in your password manager.

Two: Two-factor authentication. If there was two-factor authentication on the email account, the hacker would have been stopped dead in their tracks; they enter the correct email and password, but then are faced with a screen that says "we've sent you a code, please enter it to continue". These are rapidly becoming a non-negotiable part of online life; many places won't let you use their services without setting it up. You should set it up for everything.

And that's it! Two small fixes that can save you a massive headache!

If you want help setting these up, or if you're ever on the wrong side of a hacking (or know someone who is), give me a call and I'll sort you out!

Your message could not be sent. Please try again, or try emailing me at luke@scamsafe.me.
Your contact has been received. I'll be in touch shortly.