[-] red_teamer@infosec.pub 1 points 16 hours ago

You can search for it. I believe 20,000 accounts were compromised, and unfortunately, I was one of them.

[-] red_teamer@infosec.pub 1 points 17 hours ago

My Instagram and Facebook were compromised through the internal system/help tool exploit that allowed higher-level access to change email addresses and account details—I verified this directly by checking the confirmation emails in my inbox.

​However, I am still unsure about my Discord and Telegram accounts. It is possible that they were compromised through another vector.

[-] red_teamer@infosec.pub 1 points 3 days ago

Could you maybe suggest some services and explain their usage in more detail? That would be more helpful than having me research and potentially choose the wrong one.

[-] red_teamer@infosec.pub 4 points 4 days ago

Can anything be done about this?

[-] red_teamer@infosec.pub 3 points 4 days ago

I use Windows and primarily browse with Edge, Chrome, and Firefox. For Gmail and mail-related activities, I use Brave.

[-] red_teamer@infosec.pub 1 points 4 days ago

Your assumption is partly correct regarding storing passwords and passkeys in Bitwarden. However, my MFA is managed separately through Google Authenticator, and the recovery codes are stored in a separate account that itself is protected by multifactor authentication, including access only via a hardware security key.

Additionally, my Bitwarden account is secured with a 32-digit random master password, multi-factor authentication, and a security key.

So while I understand the potential attack vectors you mentioned, I’ve taken steps to keep these components isolated and strongly protected.

[-] red_teamer@infosec.pub 2 points 4 days ago

I’m facing repeated personal account hacks on platforms like Instagram, Facebook, and Discord (twice). I described the situation and asked Discord support for help, but they only recommended the usual security measures and then closed the query as resolved.

In the case of Telegram, everything I built was compromised, and the attacker even joined some Russian channels using my account.

I’ve asked the same question on Defcon Discord and other places but received no answers. I also tried Reddit’s cybersecurity community, but nothing there either.

red_teamer

0 post score
0 comment score
joined 4 days ago