Accounts hacked despite 2-step verification

Mars B 0 Reputation points
2024-08-19T10:29:25.84+00:00

Hi, something very strange happened to me today.

Yesterday night I get an email with a verification code for Linkedin. It was an old profile that I don't use anymore and, since I was confused by this, I just deleted the Linkedin account right away. Then, same thing happened with Tinder. I was surprised again and so, just to be safe, I went through all my gmail accounts (I have many) and activated recovery emails, 2-step verification, passkeys for ALL of them.

Then I wake up this morning, and I see security alerts for all my gmail accounts. No sign-ins, just security alerts telling me that there has been suspicious activity in my account.

But I do have a sign-in notification for one of my microsoft accounts linked to one of my gmail addresses. Also, I can see emails with verification codes for all my microsoft accounts and I can see this sign-in that happened during the night. The strangest thing? It tells me that the sign-in happened from my own IP address. I was SLEEPING and alone in the house. How is this possible? Please refrain from telling me I sleepwalked or something as that is not a possibility.

Thankfully nothing happened (I checked everything), but someone DID manage to log in all my accounts. Wth happened? I don't understand. Does this mean someone hacked my phone number, too? If I look at the different times when I got verification codes and sign-in activity, it seems like this person who hacked me (maybe an automated thing?) literally worked at hacking all my accounts from midnight until around 7:30 in the morning. It was only then that google decided to take action and disconnect all my accounts from the computer all the activity was happening in, and I received the critical alerts. I can only see "Windows" and "unknown computer" though when I check for the computer the suspicious activity was recorded from, so I have no idea where this happened from.

I've changed all my passwords ever since. Should I do something else? Also, can someone explain what happened? I didn't even get any notifications on my phone from the 2-step verification, but maybe that's because I had my phone disconnected from the internet during the night? Shouldn't I still have gotten some sign-in notification on my phone upon turning it on again? What was even the point of getting into all my emails and microsoft accounts if nothing happened?

Very confused and a little worried. Any and all help will be appreciated.

Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
5,497 questions
Outlook
Outlook
A family of Microsoft email and calendar products.
4,013 questions
Outlook Management
Outlook Management
Outlook: A family of Microsoft email and calendar products.Management: The act or process of organizing, handling, directing or controlling something.
5,281 questions
Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,852 questions
Windows 11
Windows 11
A Microsoft operating system designed for productivity, creativity, and ease of use.
9,896 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Yanhong Liu 12,180 Reputation points Microsoft Vendor
    2024-08-20T03:05:58.64+00:00

    Hello

    Thank you for posting in Q&A forum.

    Hackers can only attack you if they get their hands on you. Normally, you can get information through a link or an app to launch an attack. Therefore, we generally think about whether we clicked on any links before the attack started at the beginning of the attack. What apps have been installed. If you have obtained your account information through a link, you will need to change the password of your account that may have been compromised. If the attacker is your own computer, you may need to uninstall the requesting program.

    Best regards

    Yanhong

    =====================================

    If the answer is helpful, please click "Accept answer" and upvote it

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.