Normal view
How SMBs use threat research and MDR to build a defensive edge
Protecting education: How MDR can tip the balance in favor of schools
Tax Scams Hit Nearly 1 in 4 Adults. Spot the Red Flags
John C. isn’t the person you picture getting scammed.
He’s 36. He’s tech-savvy. He’s a mechanical engineer leading a team at a national energy lab in Denver. And he told us his story for one reason: “Scammers will target anyone.”
It began with a phone call from someone claiming to be the IRS. They said John had underpaid his taxes and needed to resolve it quickly. The caller sounded polished and convincing, so convincing that John didn’t stop to question it.
“I thought maybe they sent back too much money [in my refund], and they needed it back,” he said. “I was just so busy and overwhelmed that I never really stopped to think about the situation.”
A follow-up email arrived with IRS logos, clean formatting, and a big payment button. John was trying to move fast between classes as he finished up his PhD, and he wanted to correct the situation as quickly as possible.
“I was like, let me just hurry up and do this, get it over with.”
He clicked. He paid. But later, when he checked his statement, he saw the charge didn’t look like an IRS payment at all. In fact, it was an international charge. The whole thing was a scam.
John said the scammer on the phone had appealed to his emotions and been incredibly convincing.
“It was absolutely masterful,” John said. “I would give him an Oscar for it.
And new McAfee research shows John isn’t alone, with nearly 1 in 4 (23%) US adults surveyed revealing they’ve lost money to a tax scam.

Key findings from McAfee’s 2026 Tax Season Survey
Here’s what our January 2026 survey of 3,008 U.S. adults found:
The big picture: lots of worry, not enough confidence
- 82% of Americans say they’re concerned about tax fraud this season.
- 67% say they’re seeing the same or more tax scam messages than last year.
- 40% say tax scam messages are more sophisticated than last year.
- 84% are concerned about AI making tax scams more realistic.
- Only 29% say they’re very confident they could spot a deepfake tax scam.
How often scams are reaching people
- 34% say they’ve been contacted by someone claiming to be the IRS or another tax authority (phone, text, or email).
- 38% say they’ve been asked to click a link or send payment related to a “tax issue.”
- Common asks include SSNs (15%), birth dates (11%), addresses (10%), “you owe back taxes” pressure (9%), and banking details (8%).
Who is getting hit hardest
- Nearly 1 in 4 Americans (23%) say they’ve fallen for a tax scam.
- Young adults report the highest exposure: 42% of 18–24-year-olds say they’ve fallen for at least one tax scam.
- 11% of Americans report tax-related identity theft, rising to 17% among ages 25–34.
The money is real
- Among people who say they’ve fallen for a tax scam, the average loss is $1,020.
- Separately, nearly 1 in 5 Americans say they’ve lost money to a tax scam.
Tax filing is increasingly digital (and that changes the risk)
- 55% say they file taxes online (software or IRS Free File).
- 75% say they receive refunds or pay taxes electronically (direct deposit, cards, apps, EFTPS, etc.).
- 30% say they plan to use an AI tool (like ChatGPT) to help prepare taxes, especially younger adults. This is highly dangerous, even with platform security protections. For example, if an AI tool were compromised in a data breach, user messages with personal tax information (like social security numbers, home address, and more) could be made public.
Tax Scams Now Hit Year-Round, McAfee Labs Finds
In addition to our consumer survey findings, McAfee Labs analyzed malicious URLs, apps, texts, and emails in the months leading up to filing season.
The major takeaway: tax scams don’t wait for April.
Scam activity began climbing as early as November and has again continued building steadily into 2026.
Between September 1, 2025, and February 19, 2026, McAfee Labs identified 1,468 malicious or suspicious tax-themed unique domains, an average of 43 new fake tax websites every day.
In early November 2025 alone, the average number of new tax-themed malicious domains nearly doubled in just over a week. After a brief dip in late December, activity resumed climbing into February, a pattern we expect to intensify as the April filing deadline approaches.

Fake IRS Websites Are A Major Threat
Scammers are rapidly creating lookalike IRS domains that mimic official government URLs.
They use small changes, extra letters, added words, subtle misspellings, to trick taxpayers into believing they’re on a legitimate IRS site.
Examples include domains that insert additional text around “irs.gov” or add misleading subdomains designed to pass a quick glance.
These fake portals are used to:
- Steal login credentials
- Harvest Social Security numbers and tax IDs
- Capture payment details
- Charge bogus “processing fees”
In some cases, these sites don’t just steal, they overcharge.
McAfee Labs observed scam services offering to file for an EIN (Employer Identification Number), something the IRS provides for free, and charging as much as $319 for it.
![]()
Example of a scam website we found charging for an EIN.
The official IRS website explicitly warns: you never have to pay a fee to obtain an EIN.
Other scam sites misuse legitimate policy terms, like the “Fresh Start Initiative,” to harvest personal data and enroll victims in aggressive robocall and marketing campaigns.
Tax scams don’t always steal outright. Sometimes they monetize confusion.

How a Typical Tax Scam Unfolds
Most tax scams aren’t one single message. They’re a sequence, designed to make you panic, click, and comply.
Below is the common playbook, plus the red flags that show up repeatedly.
*Note: Scammers may swap the details like AI voice, fake IRS videos, cloned websites, or impersonating tax software, but the pattern stays familiar.
| Step | What happens | Red flags you’ll see at this step | Red flags that are true every time | What to do instead |
| 1) The hook | You get a call, text, or email claiming there’s a tax issue (refund problem, underpayment, verification needed). | Message arrives out of nowhere, often during busy hours; “final notice” language; spoofed caller ID. | Unexpected contact + urgency. | Don’t engage. Pause. Go directly to IRS.gov or your tax provider’s official site (type it in). |
| 2) The authority move | They lean hard on being “the IRS” or “state tax authority,” sometimes with personal details. | They sound polished; may use AI voice cloning; may cite a “case number.” Fake or meaningless case numbers are very common. | They want you to trust the title, not verify the source. | Ask for written notice and time. Real tax issues can be verified through official channels. |
| 3) The link | They send a link to a “secure portal” or “refund page.” | Lookalike website, subtle misspellings, weird domain, shortened link, email button that says “Pay Now.” | They’re trying to pull you off official channels. | Never click the link. Navigate to the real site yourself. If unsure, delete it. |
| 4) The data grab | The site (or “agent”) asks for SSN, banking info, login credentials, or details from a prior return. | Requests that are broader than needed; “verify identity” prompts; form fields that feel too invasive. | They want sensitive info fast. | Stop. Don’t type anything. If you already did, assume it’s compromised and act quickly (see next section). |
| 5) The payment push | They demand payment to “avoid penalties,” “release your refund,” or “resolve a mistake.” | Gift cards, crypto, wire transfers, payment apps; pressure to pay today; threats. | Urgency + unusual payment method. | The IRS does not demand immediate payment via text/social, and doesn’t require gift cards or crypto. Verify independently. |
| 6) The escalation | If you hesitate, they intensify: threats, “law enforcement,” or AI video/audio that “proves” it’s real. | Deepfake IRS video, intimidating language, “you’ll be arrested,” “your license will be revoked.” | Fear is the product. | Hang up. Save evidence. Talk to a trusted person. Contact official support through verified numbers. |
| 7) The aftermath | You realize it was a scam—often after noticing a strange charge or login activity. | Charges from odd merchants; new accounts; IRS account alerts; failed tax filing due to “duplicate return.” | Shame keeps people quiet—scammers count on that. | Report it and protect your identity right away. You’re not alone, and it’s not your fault. |
Key point: A message can look “official” and still be fake. AI is making scam language smoother and scams more believable. The safest habit is simple: slow down, and verify using official sources you navigate to yourself.
What to do if you’ve been involved in a tax scam
First: take a breath. Scams are designed to trick you, especially when you’re overwhelmed, rushed, or just trying to fix a problem quickly.
John said it plainly: “Don’t be embarrassed. It does happen. It’s common… they will target anyone.”
And he’s right. The most important thing is what you do next.
1) Stop the bleeding: cut off contact
- Stop replying
- Don’t click anything else
- Don’t send more information or money
2) Capture proof (before it disappears)
Take screenshots and save:
- Phone numbers, email addresses, usernames
- The message content
- Links (don’t click them, just copy)
- Payment receipts and transaction IDs
3) Lock down your accounts (especially email)
If a scammer gets into your email, they can reset passwords for everything else.
Do this today:
- Change your email password first, then banking/tax accounts
- Turn on two-factor authentication (2FA)
- If you reused passwords anywhere, change those too
Important: If you clicked a suspicious link, downloaded a file, or gave someone remote access to your computer, make sure you use a different, trusted device (like your phone or another computer) to change passwords. Why? If a scammer installed malware or has access to your computer, they may be able to see all of your brand-new passwords as you’re making them.
Tip: A password manager like McAfee’s can help you create strong, unique passwords quickly, without having to memorize them all.
4) Check for identity theft signals
Tax scams often turn into identity theft. Watch for:
- IRS notices about a return you didn’t file
- Trouble e-filing because a return was already submitted
- Alerts about a new IRS online account you didn’t create
If you suspect tax-related identity theft:
- Consider filing an IRS identity theft report (commonly done with IRS Form 14039, Identity Theft Affidavit).
- Create or log into your IRS account periodically to review account activity (John now does this every few months).
McAfee’s Identity Monitoring can help restore your sense of security and privacy online.
5) Report it (even if you feel weird about it)
Reporting helps you and helps stop the next person from getting hit.
Common reporting options include:
- FTC report: Report scams and identity theft at the FTC’s reporting site.
- IRS phishing email: If you received a scam email posing as the IRS, you can forward it to phishing@irs.gov.
- Your bank or card provider: If you paid, contact them immediately. Even if recovery isn’t guaranteed, speed matters.
6) Clean up your digital footprint
Scammers don’t just use what you give them. They also use what they can look up.
Removing your personal details from risky data broker sites can reduce how easily scammers can target you again. Tools like Personal Data Cleanup can help you identify where your information is exposed and guide removal.
7) Add protection for the next attempt
Tax season scams often come in waves, especially if scammers think your info is “good.”
Helpful layers include:
- Web protection to warn you about risky links and lookalike sites before you enter info – get our free WebAdvisor download here
- Scam detection that can flag suspicious messages
- Identity monitoring to alert you if key personal info shows up in risky places
- Run a free antivirus scan to check your device for malware or unwanted programs (especially if you clicked a link or downloaded anything)
The key takeaway
Tax season creates the perfect storm: time pressure, sensitive data, and a lot of official-looking communication.
Our research shows most people are worried, and for good reason. Scammers are getting more convincing, and AI is raising the bar on what “real” looks and sounds like.
“Tell your friends, tell your family,” John said. “Everyone I know at some point has heard this story, and it might just prevent someone from losing… thousands of dollars.”
If you remember just three things this season, make them these:
- Pause before you click.
- Verify through official channels you navigate to yourself.
- If something happens, act quickly, and don’t blame yourself.
The post Tax Scams Hit Nearly 1 in 4 Adults. Spot the Red Flags appeared first on McAfee Blog.
Weekly Update 493
The Odido breach leaks were towards the beginning during this week's update. I recorded it the day after the second dump of data had hit, with a third dump coming a few hours later, and a final dump of everything the day after that. From what I hear, it dominated the news in the Netherlands, and we sure saw that through the traffic stats. Clearly, the leak cadence was designed for maximum news impact, and it seems to have achieved that. It may not have put any cash in the extortionist's pockets, but it's set a very visible precedent and, I suspect, put a massive law enforcement target on them. It's hard to image leaks of this impact continuing for much longer...
Who is the Kimwolf Botmaster “Dort”?
In early January 2026, KrebsOnSecurity revealed how a security researcher disclosed a vulnerability that was used to build Kimwolf, the world’s largest and most disruptive botnet. Since then, the person in control of Kimwolf — who goes by the handle “Dort” — has coordinated a barrage of distributed denial-of-service (DDoS), doxing and email flooding attacks against the researcher and this author, and more recently caused a SWAT team to be sent to the researcher’s home. This post examines what is knowable about Dort based on public information.
A public “dox” created in 2020 asserted Dort was a teenager from Canada (DOB August 2003) who used the aliases “CPacket” and “M1ce.” A search on the username CPacket at the open source intelligence platform OSINT Industries finds a GitHub account under the names Dort and CPacket that was created in 2017 using the email address jay.miner232@gmail.com.
Image: osint.industries.
The cyber intelligence firm Intel 471 says jay.miner232@gmail.com was used between 2015 and 2019 to create accounts at multiple cybercrime forums, including Nulled (username “Uubuntuu”) and Cracked (user “Dorted”); Intel 471 reports that both of these accounts were created from the same Internet address at Rogers Canada (99.241.112.24).
Dort was an extremely active player in the Microsoft game Minecraft who gained notoriety for their “Dortware” software that helped players cheat. But somewhere along the way, Dort graduated from hacking Minecraft games to enabling far more serious crimes.
Dort also used the nickname DortDev, an identity that was active in March 2022 on the chat server for the prolific cybercrime group known as LAPSUS$. Dort peddled a service for registering temporary email addresses, as well as “Dortsolver,” code that could bypass various CAPTCHA services designed to prevent automated account abuse. Both of these offerings were advertised in 2022 on SIM Land, a Telegram channel dedicated to SIM-swapping and account takeover activity.
The cyber intelligence firm Flashpoint indexed 2022 posts on SIM Land by Dort that show this person developed the disposable email and CAPTCHA bypass services with the help of another hacker who went by the handle “Qoft.”
“I legit just work with Jacob,” Qoft said in 2022 in reply to another user, referring to their exclusive business partner Dort. In the same conversation, Qoft bragged that the two had stolen more than $250,000 worth of Microsoft Xbox Game Pass accounts by developing a program that mass-created Game Pass identities using stolen payment card data.
Who is the Jacob that Qoft referred to as their business partner? The breach tracking service Constella Intelligence finds the password used by jay.miner232@gmail.com was reused by just one other email address: jacobbutler803@gmail.com. Recall that the 2020 dox of Dort said their date of birth was August 2003 (8/03).
Searching this email address at DomainTools.com reveals it was used in 2015 to register several Minecraft-themed domains, all assigned to a Jacob Butler in Ottawa, Canada and to the Ottawa phone number 613-909-9727.
Constella Intelligence finds jacobbutler803@gmail.com was used to register an account on the hacker forum Nulled in 2016, as well as the account name “M1CE” on Minecraft. Pivoting off the password used by their Nulled account shows it was shared by the email addresses j.a.y.m.iner232@gmail.com and jbutl3@ocdsb.ca, the latter being an address at a domain for the Ottawa-Carelton District School Board.
Data indexed by the breach tracking service Spycloud suggests that at one point Jacob Butler shared a computer with his mother and a sibling, which might explain why their email accounts were connected to the password “jacobsplugs.” Neither Jacob nor any of the other Butler household members responded to requests for comment.
The open source intelligence service Epieos finds jacobbutler803@gmail.com created the GitHub account “MemeClient.” Meanwhile, Flashpoint indexed a deleted anonymous Pastebin.com post from 2017 declaring that MemeClient was the creation of a user named CPacket — one of Dort’s early monikers.
Why is Dort so mad? On January 2, KrebsOnSecurity published The Kimwolf Botnet is Stalking Your Local Network, which explored research into the botnet by Benjamin Brundage, founder of the proxy tracking service Synthient. Brundage figured out that the Kimwolf botmasters were exploiting a little-known weakness in residential proxy services to infect poorly-defended devices — like TV boxes and digital photo frames — plugged into the internal, private networks of proxy endpoints.
By the time that story went live, most of the vulnerable proxy providers had been notified by Brundage and had fixed the weaknesses in their systems. That vulnerability remediation process massively slowed Kimwolf’s ability to spread, and within hours of the story’s publication Dort created a Discord server in my name that began publishing personal information about and violent threats against Brundage, Yours Truly, and others.
Dort and friends incriminating themselves by planning swatting attacks in a public Discord server.
Last week, Dort and friends used that same Discord server (then named “Krebs’s Koinbase Kallers”) to threaten a swatting attack against Brundage, again posting his home address and personal information. Brundage told KrebsOnSecurity that local police officers subsequently visited his home in response to a swatting hoax which occurred around the same time that another member of the server posted a door emoji and taunted Brundage further.
Dort, using the alias “Meow,” taunts Synthient founder Ben Brundage with a picture of a door.
Someone on the server then linked to a cringeworthy (and NSFW) new Soundcloud diss track recorded by the user DortDev that included a stickied message from Dort saying, “Ur dead nigga. u better watch ur fucking back. sleep with one eye open. bitch.”
“It’s a pretty hefty penny for a new front door,” the diss track intoned. “If his head doesn’t get blown off by SWAT officers. What’s it like not having a front door?”
With any luck, Dort will soon be able to tell us all exactly what it’s like.
Update, 10:29 a.m.: Jacob Butler responded to requests for comment, speaking with KrebsOnSecurity briefly via telephone. Butler said he didn’t notice earlier requests for comment because he hasn’t really been online since 2021, after his home was swatted multiple times. He acknowledged making and distributing a Minecraft cheat long ago, but said he hasn’t played the game in years and was not involved in Dortsolver or any other activity attributed to the Dort nickname after 2021.
“It was a really old cheat and I don’t remember the name of it,” Butler said of his Minecraft modification. “I’m very stressed, man. I don’t know if people are going to swat me again or what. After that, I pretty much walked away from everything, logged off and said fuck that. I don’t go online anymore. I don’t know why people would still be going after me, to be completely honest.”
When asked what he does for a living, Butler said he mostly stays home and helps his mom around the house because he struggles with autism and social interaction. He maintains that someone must have compromised one or more of his old accounts and is impersonating him online as Dort.
“Someone is actually probably impersonating me, and now I’m really worried,” Butler said. “This is making me relive everything.”
But there are issues with Butler’s timeline. For example, Jacob’s voice in our phone conversation was remarkably similar to the Jacob/Dort whose voice can be heard in this Sept. 2022 Clash of Code competition between Dort and another coder (Dort lost). At around 6 minutes and 10 seconds into the recording, Dort launches into a cursing tirade that mirrors the stream of profanity in the diss rap that Dortdev posted threatening Brundage. Dort can be heard again at around 16 minutes; at around 26:00, Dort threatens to swat his opponent.
Butler said the voice of Dort is not his, exactly, but rather that of an impersonator who had likely cloned his voice.
“I would like to clarify that was absolutely not me,” Butler said. “There must be someone using a voice changer. Or something of the sorts. Because people were cloning my voice before and sending audio clips of ‘me’ saying outrageous stuff.”
Further reading:
Jan. 8, 2026: Who Benefited from the Aisuru and Kimwolf Botnets?
Jan. 20, 2026: Kimwolf Botnet Lurking in Corporate, Govt. Networks
Jan. 26, 2026: Who Operates the Badbox 2.0 Botnet?
Feb. 11, 2026: Kimwolf Botnet Swamps Anonymity Network I2P
Mar. 19, 2026: Feds Disrupt IoT Botnets Behind Huge DDoS Attacks
This month in security with Tony Anscombe – February 2026 edition
This Week in Scams: Conduent Data Breach and AI Olsen Twins
This week in scams, we’re looking at three very different stories with the same underlying theme: trust is being exploited at scale.
A massive government contractor data breach has quietly grown to affect more than 25 million people. Meanwhile, a viral AI-generated image of Mary-Kate and Ashley Olsen posing in a fake luxury campaign is spreading across social media, fooling some users and alarming others.
And in a new threat report, OpenAI detailed how its own tools are being misused for dating scams, impersonation, and influence operations.
Let’s break it down.
The Conduent Data Breach Now Impacts 25+ Million People
The fallout from a ransomware attack on Conduent, one of the largest government contractors in the U.S., continues to expand.
According to reporting from TechCrunch, updated state-level breach notifications now indicate that more than 25 million people across the U.S. have had personal data exposed.
Conduent provides services tied to state benefit programs, including food assistance, unemployment systems, and other government payment processing operations. The company has said its services reach over 100 million people.
Data reportedly exposed in the breach includes:
- Names
- Dates of birth
- Addresses
- Social Security numbers
- Health insurance and medical information
TechCrunch noted that the majority of affected individuals appear to be in Oregon and Texas, based on state breach disclosures. Other states have also reported an impact.
The attack has been described as one of the largest government-contractor-related data breaches in recent memory.
Why this matters: When companies that process government benefits are hit, the exposed data often includes highly sensitive identity information. Social Security numbers combined with medical or insurance details can significantly increase the risk of identity theft and fraud.
How to Protect Yourself After a Major Data Breach
If you believe your data may have been exposed:
- Monitor your credit reports for unfamiliar activity
- Consider placing a free credit freeze
- Be wary of phishing emails or texts referencing benefits or account verification
- Never share personal information in response to unexpected outreach
Breaches like this often lead to secondary scams months later. The breach itself is only phase one. Phishing campaigns usually follow.
That Viral Olsen Twins “Louis Vuitton” Image? It’s AI.
A supposed luxury campaign featuring Mary-Kate and Ashley Olsen began circulating widely on X and Facebook this week, racking up millions of views.
The images show the twins styled in what appears to be a high-end fashion shoot, drawing numerous comments over their styling. But social media users quickly pointed out visual irregularities and inconsistencies commonly associated with AI-generated imagery.
A screenshot of one of the AI images making thr rounds across social media.
While this doesn’t fall into our typical “scam” roundup, the normalization of AI-generated visuals that look close enough to real to confuse people are a growing issue that can lead to real confusion and distrust.
We have entered a phase where:
- Fake ads look legitimate
- Public figures appear in campaigns they never participated in
- Synthetic images spread faster than corrections
Today it’s a fashion ad. Tomorrow it could be a fake political endorsement, financial announcement, or emergency alert.
The takeaway: If you see a surprising campaign or announcement, verify it through official brand websites or verified accounts before assuming it’s real.
OpenAI Details How ChatGPT Is Being Misused
In a newly released threat report, OpenAI outlined several ways its tools have been abused by bad actors.
According to Reuters’ reporting:
A cluster of accounts used ChatGPT to run a dating scam targeting Indonesian men, allegedly defrauding hundreds of victims per month.
Some accounts used the tool to generate promotional copy and ads for a fake dating platform that pressured users into completing costly “tasks.”
Other accounts posed as law firms, impersonating real attorneys and U.S. law enforcement to target fraud victims.
OpenAI also banned accounts linked to activity believed to be part of influence operations, including efforts targeting Japanese political figures.
OpenAI stated that the activity was detected and accounts were removed.
Why this matters: AI tools themselves are not inherently scams. But they dramatically lower the cost and increase the scale of fraud operations. Writing persuasive emails, generating fake legal letters, building scam ads… these now require fewer technical skills than ever before.
The technology doesn’t create the criminal intent. It just accelerates it.
McAfee’s Safety Tips This Week
- Assume viral images could be AI-generated until verified
- Verify unexpected announcements through official websites
- Treat post-breach emails as suspicious by default
- Be skeptical of online “consultation” invites that promise payment
- Never send money to someone you’ve only met online
We’ll Be Back Next Week
From ransomware breaches to AI-generated impersonations, the pattern is clear: scammers are scaling trust manipulation with technology.
Stay skeptical. Verify before you click. And we’ll be back next week with another breakdown of what’s making headlines, and what it actually means for your security.
For more reading on AI deepfakes and breaches:
Taylor Swift Tops List of Most Deepfaked Celebs
What to Do If You’re Caught Up in a Data Breach
Everything You Need to Know to Keep Your Passwords Secure
The post This Week in Scams: Conduent Data Breach and AI Olsen Twins appeared first on McAfee Blog.
Mobile app permissions (still) matter more than you may think
X (Twitter) Account Hacked: What to Do Right Now
X (formerly Twitter) hacks tend to hit fast.
One minute you’re scrolling like normal. The next, your account is posting crypto promotions, sending spam DMs, or following hundreds of random accounts you’ve never heard of. Sometimes you don’t even notice until a friend asks why you’re suddenly “giving away” gift cards.
If you use X for work, your personal brand, or your business, a takeover can do real damage quickly. And in many cases, the hacker isn’t just trying to cause chaos, they’re trying to use your account to scam your followers while you still look trustworthy.
This guide walks you through exactly what to do if your X account has been hacked: how to spot the warning signs, how to regain access, and what to change immediately so it doesn’t happen again.
If you’re still locked out after trying these steps, X also offers an official support form for hacked or compromised accounts.
Signs Your X Account May Be Compromised
X account takeovers don’t always start with a full lockout. Often, the first signs are strange activity you didn’t authorize.
Watch for these red flags:
Unexpected posts: Tweets you didn’t write, especially spam, crypto links, or promotions.
Unusual DMs: Messages sent from your account that you don’t remember sending.
Account behavior changes: Random follows, unfollows, blocks, or profile changes you didn’t approve.
Security notifications: Alerts from X that your account may be compromised.
Account info changed: Notifications that your email, phone number, or password was updated without your permission.
Password suddenly stops working: You’re prompted to reset your password even though you didn’t request it.
If any of these are happening, assume your account is compromised and start recovery steps immediately.
What to Change Immediately If Your X Account Was Hacked
If your X account was hacked, assume your login details may have been stolen.
That means simply getting back into your account isn’t enough, you also need to update the passwords and settings attackers could still use.
Here’s what to change right away:
- Change your X password
- Change the password for the email account connected to X
- Turn on two-factor authentication (2FA)
- Confirm your email address and phone number are correct
- Revoke access for any suspicious third-party apps
- Review X Pro / Teams access (if you use it) and remove unfamiliar users
- Update any other accounts that share the same password
- Delete unauthorized posts and DMs (once you regain control)
If you suspect the hack started through malware or phishing, it’s also smart to update passwords for other sensitive accounts tied to your identity, like banking apps, payment apps, or your Apple/Google account.
Using a password manager like McAfee’s can help you create strong, unique passwords for every account, and store them securely in one place.
Step-by-Step: How to Recover a Hacked X Account
X offers different recovery options depending on whether you can still log in.
| Step | What to Do | Why It Matters |
| 1. Change your password immediately (if you can still log in) | Go into your X account settings and update your password to something strong and unique. | This is the fastest way to cut off unauthorized access. |
| 2. Reset your password if you’re locked out | Use the “Forgot password” option on the login screen to start account recovery. | This can help you regain access even if the hacker changed your password. |
| 3. Secure your email account | Change your email password and enable 2FA. Make sure only you can access it. | If your email is compromised, the hacker can keep resetting your X account. |
| 4. Reverse suspicious email changes if possible | If you receive an email about an account email change, check for an option to undo it. | This may allow you to regain control before the hacker fully locks you out. |
| 5. Revoke third-party app access | While logged in, review connected apps and remove anything you don’t recognize. | Some takeovers happen through malicious apps, not direct password guessing. |
| 6. Revoke mobile app sessions if needed | If suspicious activity continues, revoke access for X mobile apps from your settings so they’re forced to re-authenticate. | X notes that password changes may not automatically log out mobile sessions. |
| 7. Update your password anywhere it’s saved | If you use trusted apps or services that store your X password, update it there too. | Repeated failed login attempts can temporarily lock your account. |
| 8. Turn on 2FA | Enable two-factor authentication as soon as you regain control. | This adds a strong layer of protection even if your password gets stolen again. |
| 9. Contact X support if you still can’t regain access | Submit X’s hacked/compromised account request form. Include your username and the last date you had access. | If self-recovery fails, support may be able to help restore access. |
If you’re still unable to log in after attempting recovery, visit X’s official hacked account support form for next steps.
Watch for Phishing “X Support” Scams
One of the most common ways X accounts get hacked is through phishing.
Scammers impersonate:
- X support
- “verified account” teams
- copyright warnings
- fake sponsorship offers
- fake security alerts claiming your account will be suspended
They try to pressure you into clicking a link and logging in on a fake page designed to steal your password.
If you receive a suspicious email or DM, don’t click.
Instead, open X directly in the app or browser and check your account settings from there.
Final Tips: Recovering From an X Hack
A hacked X account can spread scams quickly, especially if the attacker uses your account to message followers directly.
The most important steps are:
- Act quickly
- Change your password immediately
- Secure the email account connected to X
- Revoke suspicious third-party app access
- Review X Pro / Teams access if applicable
- Enable two-factor authentication (2FA)
- Delete unauthorized posts once you regain control
- Scan your device for malware
McAfee offers a free antivirus scan that can help you detect malware or suspicious programs that may have compromised your account in the first place.
And if you’re still locked out or something doesn’t look right, use X’s official support request form to report the account as hacked or compromised.
Frequently Asked Questions
| Q: How do I know if my X account was hacked? A: Common signs include posts or DMs you didn’t send, unusual follows/unfollows, account changes you didn’t authorize, security alerts from X, or a password that suddenly stops working. |
| Q: If I change my password, will the hacker be logged out? A: Changing your password is critical, but some mobile sessions may remain active. X recommends revoking app access in your settings if suspicious activity continues. |
| Q: What should I do if my email address was changed? A: Check your inbox for an email from X about the change. In some cases, you may be able to reverse it using the security link. If you can’t, start account recovery immediately and submit a support request if needed. |
| Q: Should I remove third-party apps after a hack? A: Yes. X notes that malicious or untrusted third-party apps can compromise your account. Remove anything you don’t recognize or no longer use. |
| Q: What if I still can’t log in after resetting my password? A: Submit a hacked account support request through X’s official form. Be sure to include your username and the last date you had access. |
| Q: What’s the biggest mistake people make after their X account gets hacked? A: Only changing their password. If the attacker still has access through connected apps, a compromised email account, or saved sessions, they can regain control quickly. |
The post X (Twitter) Account Hacked: What to Do Right Now appeared first on McAfee Blog.
My Instagram Has Been Hacked – What Do I Do Now?
Instagram hacks don’t always start with a dramatic “you’ve been locked out” moment.
More often, it starts with something small: your followers asking why you just sent them a weird link. Your account suddenly following hundreds of random profiles. A post you didn’t write showing up in your feed. Or an email from Instagram saying your login details were changed.
By the time you realize what’s happening, scammers may already be using your account to impersonate you, message your followers, or promote fake giveaways and crypto scams through your profile.
This guide walks you through exactly what to do if your Instagram account has been hacked: how to spot the warning signs, how to regain access, and what to change immediately so it doesn’t happen again.
And if you’re still having trouble at any stage, be sure to visit Instagram’s official recovery tools for additional support.
Signs Your Instagram Account May Be Compromised
Instagram account takeovers don’t always look obvious at first. In many cases, the first signs are subtle changes you didn’t make.
Watch for these red flags:
Password or email changes you didn’t request: You may receive an email saying your account information was updated.
Suspicious login alerts: Notifications about a login attempt, new device, or verification code you didn’t request.
Posts, Stories, or Reels you didn’t publish: Scammers often post crypto promotions, fake giveaways, or sketchy links.
DMs you didn’t send: A common tactic is using your account to message your followers with phishing links.
Your account starts following random accounts: Hackers may use compromised accounts to inflate scam pages or bot networks.
Your profile info has been edited: Name, bio, profile photo, or website links changed without your permission.
If any of these are happening, assume your account is compromised and start recovery steps immediately.
What to Change Immediately If Your Instagram Account Was Hacked
If your Instagram account was hacked, assume your login details may have been stolen.
That means simply getting back into your account isn’t enough, you also need to update the passwords and settings attackers could still use.
Here’s what to change right away:
- Change your Instagram password
- Change the password for the email account connected to Instagram
- Turn on two-factor authentication (2FA)
- Log out of all active sessions/devices
- Remove suspicious third-party apps connected to your account
- Confirm your phone number and email address are correct
- Check Accounts Center and remove linked accounts you don’t recognize
- Update any other accounts that share the same password
If you suspect the hack started through malware or a phishing link, it’s also smart to update passwords for other sensitive accounts tied to your identity, like banking apps, payment apps, or your Apple/Google account.
Using a password manager like McAfee’s can help you create strong, unique passwords for every account, and store them securely in one place.
Step-by-Step: How to Recover a Hacked Instagram Account
Instagram provides several recovery options depending on what information you still have access to (email, phone number, username, or trusted device).
| Step | What to Do | Why It Matters |
| 1. Visit Instagram’s hacked account recovery page | Use Instagram’s official hacked account recovery flow in your browser or app. | This is often the fastest way to secure your account and start recovery. |
| 2. Check your email for security messages from Instagram | Look for messages about password changes or email changes. If Instagram gives you a link to undo the change, use it immediately. | If a hacker changed your email address, this may be your quickest chance to reverse it. |
| 3. Request a login link | Use “Forgot password?” to request a login link sent to your email or phone number. | This can restore access even if your password was changed. |
| 4. Request a security code or additional support | If login links aren’t working, follow Instagram’s prompts to request further help. Use an email address only you can access. | If the attacker changed your contact info, you may need additional verification steps. |
| 5. Complete identity verification if prompted | Instagram may ask you to verify your identity, including submitting a video selfie if your account contains photos of you. | This helps Instagram confirm you’re the real account owner. |
| 6. Change your password immediately after regaining access | Reset your password to something strong and unique. | This cuts off access and helps prevent repeat takeovers. |
| 7. Remove suspicious linked accounts and apps | Check Accounts Center and remove anything unfamiliar. Revoke access for any third-party apps you don’t trust. | Hackers may leave behind access routes to get back in later. |
| 8. Turn on 2FA and login alerts | Enable two-factor authentication and set alerts for new logins. | This makes it much harder for attackers to regain access. |
If you’re still unable to recover your account, visit Instagram’s official support and recovery tools for additional help.
Watch for Phishing “Instagram Support” Scams
One of the most common ways Instagram accounts get hacked is through phishing.
Scammers impersonate:
- Instagram support
- verification teams
- copyright violation notices
- “your account will be deleted” warnings
- fake giveaway collaborations
Their goal is to pressure you into clicking a link and entering your password on a fake login page.
If you receive a suspicious email or DM, don’t click.
Instead, open Instagram directly in the app and check your security settings from there.
If you think you entered your login info into a suspicious link, change your password immediately and secure your account right away.
Final Tips: Recovering From an Instagram Hack
A hacked Instagram account is stressful for a reason: it doesn’t just affect your profile. It affects your followers, your reputation, and your private messages.
The most important steps are:
- Act quickly
- Check your email for Instagram security alerts
- Use Instagram’s official hacked account recovery tools
- Change your password immediately
- Log out of all active sessions
- Remove suspicious apps and linked accounts
- Enable two-factor authentication (2FA)
- Scan your device for malware
McAfee offers a free antivirus scan that can help you detect malware or suspicious programs that may have compromised your account in the first place.
And if you’re still locked out or something doesn’t look right, follow Instagram’s official recovery guidance and contact Instagram support directly.
Frequently Asked Questions
| Q: How do I know if my Instagram account was hacked? A: Common signs include password or email changes you didn’t request, suspicious login alerts, DMs you didn’t send, posts you didn’t publish, or unexpected changes to your profile details. |
| Q: What if my Instagram email address was changed? A: Check your inbox for an email from Instagram about the change. In some cases, Instagram may provide a security link that lets you reverse it. If you can’t undo the change, start the hacked account recovery process as soon as possible. |
| Q: What if I can’t log in at all? A: Use Instagram’s official hacked account recovery tools. Depending on your situation, Instagram may offer login links, security codes, or identity verification options to help you regain access. |
| Q: Should I remove third-party apps after a hack? A: Yes. Some account takeovers happen because an unsafe app was given access. Remove anything you don’t recognize or no longer use. |
| Q: What’s the biggest mistake people make after getting hacked? A: Only changing their Instagram password. If the attacker still has access through your email account, linked accounts, or suspicious third-party apps, they can regain control quickly. |
| Q: Can Instagram ask me to verify my identity? A: Yes. In some cases, Instagram may ask you to confirm ownership through verification steps. This can include submitting additional information or completing a video selfie process. |
The post My Instagram Has Been Hacked – What Do I Do Now? appeared first on McAfee Blog.
Weekly Update 492
The recurring theme this week seems to be around the gap between breaches happening and individual victims finding out about them. It's tempting to blame this on the corporate victim of the breach (the hacked company), but they're simultaneously dealing with a criminal intrusion, a ransom demand, and class-action lawyers knocking down their doors. They're in a lose-lose position: pay the ransom and fuel the criminals whilst still failing to escape regulatory disclosure obligations. Disclose early and transparently to individuals, which then provides fuel to the lawyers. Try to sweep the whole thing under the rug and risk attracting the ire of customers and regulators alike. It's a very big mess, and it doesn't seem to be getting any better.
Faking it on the phone: How to tell if a voice call is AI or not
‘Starkiller’ Phishing Service Proxies Real Login Pages, MFA
Most phishing websites are little more than static copies of login pages for popular online destinations, and they are often quickly taken down by anti-abuse activists and security firms. But a stealthy new phishing-as-a-service offering lets customers sidestep both of these pitfalls: It uses cleverly disguised links to load the target brand’s real website, and then acts as a relay between the victim and the legitimate site — forwarding the victim’s username, password and multi-factor authentication (MFA) code to the legitimate site and returning its responses.
There are countless phishing kits that would-be scammers can use to get started, but successfully wielding them requires some modicum of skill in configuring servers, domain names, certificates, proxy services, and other repetitive tech drudgery. Enter Starkiller, a new phishing service that dynamically loads a live copy of the real login page and records everything the user types, proxying the data from the legitimate site back to the victim.
According to an analysis of Starkiller by the security firm Abnormal AI, the service lets customers select a brand to impersonate (e.g., Apple, Facebook, Google, Microsoft et. al.) and generates a deceptive URL that visually mimics the legitimate domain while routing traffic through the attacker’s infrastructure.
For example, a phishing link targeting Microsoft customers appears as “login.microsoft.com@[malicious/shortened URL here].” The “@” sign in the link trick is an oldie but goodie, because everything before the “@” in a URL is considered username data, and the real landing page is what comes after the “@” sign. Here’s what it looks like in the target’s browser:
Image: Abnormal AI. The actual malicious landing page is blurred out in this picture, but we can see it ends in .ru. The service also offers the ability to insert links from different URL-shortening services.
Once Starkiller customers select the URL to be phished, the service spins up a Docker container running a headless Chrome browser instance that loads the real login page, Abnormal found.
“The container then acts as a man-in-the-middle reverse proxy, forwarding the end user’s inputs to the legitimate site and returning the site’s responses,” Abnormal researchers Callie Baron and Piotr Wojtyla wrote in a blog post on Thursday. “Every keystroke, form submission, and session token passes through attacker-controlled infrastructure and is logged along the way.”
Starkiller in effect offers cybercriminals real-time session monitoring, allowing them to live-stream the target’s screen as they interact with the phishing page, the researchers said.
“The platform also includes keylogger capture for every keystroke, cookie and session token theft for direct account takeover, geo-tracking of targets, and automated Telegram alerts when new credentials come in,” they wrote. “Campaign analytics round out the operator experience with visit counts, conversion rates, and performance graphs—the same kind of metrics dashboard a legitimate SaaS [software-as-a-service] platform would offer.”
Abnormal said the service also deftly intercepts and relays the victim’s MFA credentials, since the recipient who clicks the link is actually authenticating with the real site through a proxy, and any authentication tokens submitted are then forwarded to the legitimate service in real time.
“The attacker captures the resulting session cookies and tokens, giving them authenticated access to the account,” the researchers wrote. “When attackers relay the entire authentication flow in real time, MFA protections can be effectively neutralized despite functioning exactly as designed.”
The “URL Masker” feature of the Starkiller phishing service features options for configuring the malicious link. Image: Abnormal.
Starkiller is just one of several cybercrime services offered by a threat group calling itself Jinkusu, which maintains an active user forum where customers can discuss techniques, request features and troubleshoot deployments. One a-la-carte feature will harvest email addresses and contact information from compromised sessions, and advises the data can be used to build target lists for follow-on phishing campaigns.
This service strikes me as a remarkable evolution in phishing, and its apparent success is likely to be copied by other enterprising cybercriminals (assuming the service performs as well as it claims). After all, phishing users this way avoids the upfront costs and constant hassles associated with juggling multiple phishing domains, and it throws a wrench in traditional phishing detection methods like domain blocklisting and static page analysis.
It also massively lowers the barrier to entry for novice cybercriminals, Abnormal researchers observed.
“Starkiller represents a significant escalation in phishing infrastructure, reflecting a broader trend toward commoditized, enterprise-style cybercrime tooling,” their report concludes. “Combined with URL masking, session hijacking, and MFA bypass, it gives low-skill cybercriminals access to attack capabilities that were previously out of reach.”
This Week in Scams: AI Search Traps, a Fintech Breach, and a $12M Louvre Hustle
AI is supposed to make the internet easier. But right now, it’s also making scams easier.
Every week, we round up the biggest scam and cybersecurity stories of the moment so you can recognize red flags, protect your accounts, and avoid the most common traps scammers are using.
This week in scams, we’re talking AI-powered search scams, a major fintech data breach, and an unexpected ticket fraud scheme that allegedly cost the Louvre millions.
Let’s jump in:
Google AI Overviews Are Being Used to Scam People Out of Money
Google Search doesn’t just show links anymore. Now, it often shows AI-generated summaries at the top of the page called AI Overviews, quick answers designed to save you time.
But according to reporting from WIRED, scammers are finding ways to exploit these AI summaries by planting fake customer support phone numbers into search results.
Here’s how the scam works: Someone searches for a bank, airline, or service provider, usually something like “Company name customer support number.” Then Google’s AI Overview pulls a phone number from somewhere online and displays it as if it’s legitimate.
The problem? Sometimes that number doesn’t connect you to the company at all.
Instead, it connects you to a scammer impersonating customer service, someone trained to sound helpful, calm, and official, while quietly steering you toward sharing payment information, account details, or verification codes.
This isn’t just misinformation. It’s a direct path into fraud.
Google told WIRED it’s working to strengthen anti-spam protections in AI Overviews, but also recommends users double-check customer support numbers through additional searches.
Key red flags to watch for
- The AI Overview provides a phone number without clearly showing where it came from
- The “support agent” asks for payment information immediately
- The person asks for your login credentials, bank info, or verification codes
- The caller pressures you to act quickly (“your account will be frozen”)
- The number doesn’t match what’s listed on the company’s official website
How to protect yourself
If you’re looking for a customer support number, don’t rely on an AI summary.
- Go directly to the company’s official website and find their contact page
- Verify the phone number through multiple sources
- If the person on the phone asks for passwords or MFA codes, hang up immediately
- Treat any urgency or threats (“you must act now”) as a scam signal
The big lesson: AI can summarize the internet, but it can’t always verify the truth.
Data Breach Watch: Fintech Firm Figure Exposes Nearly 1 Million Accounts
If you’ve applied for a loan, worked with a fintech service, or interacted with a home equity platform recently, this one is worth paying attention to.
According to BleepingComputer, fintech company Figure Technology Solutions was breached in a social engineering attack, with hackers reportedly stealing personal data tied to nearly 967,200 accounts.
The exposed data reportedly included names, email addresses, phone numbers, physical addresses, and dates of birth. And that’s exactly what scammers use to build believable impersonation attempts.
Why this matters
Even if you’ve never heard of Figure, data breaches like this can ripple outward fast. Once scammers have your email, phone number, and date of birth, they can launch more convincing scams like:
- Fake “account verification” calls
- Fraudulent loan or credit applications
- Phishing emails pretending to be financial institutions
- Identity theft attempts using your personal details
And because this breach was reportedly caused by social engineering, it’s also a reminder that the weakest link in security isn’t always technology, it’s human trust.
Key red flags to watch for after a breach
- Calls claiming your loan account needs immediate verification
- Emails asking you to “confirm your identity” using a link
- Messages that include personal details to sound legitimate
- Fake financial support agents asking for payment or login credentials
What to do right now
- Change passwords (especially if you reuse them across accounts)
- Turn on multi-factor authentication where possible
- Monitor your credit report for unusual activity
- Be skeptical of unexpected financial messages, even if they seem personalized
After breaches like this, scammers often wait weeks or months before striking, because they know people stop paying attention.
A Scam at the Louvre Allegedly Cost $12 Million
Not every scam story is about malware or phishing links. Some are about old-fashioned fraud, executed at a scale that feels almost unbelievable.
According to reporting from The New York Times, French investigators uncovered a ticket fraud scheme that may have cost the Louvre in Paris nearly $12 million over a decade.
Officials say the suspected scam involved tour guides allegedly reusing tickets multiple times, bribes paid to museum employees, and tourist groups being split up to avoid additional fees.
Last week, police reportedly arrested nine people in the case, including two museum employees.
Investigators also believe similar fraud may have taken place at Versailles.
The Takeaway
This wasn’t a one-time trick. Investigators believe the network may have been running for years, allegedly bringing in multiple tour groups per day.
It’s a reminder that scammers don’t always need to “hack” a system.
Sometimes, they just find a weak point, then repeat it until it becomes a business model.
The bottom line: the Louvre story is dramatic, but the lesson is familiar. Scams thrive anywhere oversight is stretched thin, systems are overwhelmed, and people assume someone else is double-checking.
Whether it’s a museum ticket scanner or an AI-generated search result, scammers will always look for the fastest path through the cracks.
McAfee’s Safety Tips for This Week
This week’s scam pattern is all about one theme: trust shortcuts.
AI summaries that feel official. Phone numbers that look real. Support agents who sound convincing. Breach data that makes phishing more believable.
The best defense is slowing down and verifying before you act.
Here are the smartest moves to make right now:
Don’t trust AI Overviews (or search snippets) for customer support phone numbers. Always verify through the company’s official website.
Treat “customer service” calls with caution, especially if they ask for payment info, passwords, or MFA codes.
Never share verification codes, even if someone claims they’re just “confirming your identity.”
Watch for phishing attempts after major breaches. Scammers often use stolen data to make messages feel personal and urgent.
Be suspicious of pressure tactics like “your account will be frozen” or “you must act immediately.”
If you think your personal data may be exposed, monitor your credit and update your passwords now, not later.
Use tools like McAfee Web Protection to avoid dangerous links, bad downloads, malicious websites, and more.
We’ll be back next week with another roundup of the scams making headlines, and what you can do to stay ahead of them.
The post This Week in Scams: AI Search Traps, a Fintech Breach, and a $12M Louvre Hustle appeared first on McAfee Blog.
YouTube Channel Hacked? Restore Owner Access and Stop Live-Stream Scams
You don’t always realize your YouTube channel has been hacked right away.
Sometimes it’s a sudden spike in notifications. Sometimes it’s a flood of confused comments. And sometimes it’s the worst-case scenario: you wake up to find your channel renamed, your videos hidden, and a scam livestream running under your brand.
This is one of the most common forms of creator-targeted account takeover today. Attackers hijack real channels because they already have an audience, and then use that trust to promote fake crypto giveaways, “investment” livestreams, or malicious links in video descriptions.
A YouTube channel hack can also put your account at risk of Community Guidelines strikes or monetization penalties, even if you didn’t upload the content yourself.
This guide walks you through exactly what to do if your YouTube channel has been compromised: how to regain owner access, stop scam live streams fast, and secure your Google Account so it doesn’t happen again.
Signs Your YouTube Channel May Be Compromised
A hacked YouTube channel usually means your Google Account has also been compromised, since every YouTube channel is tied to at least one Google Account.
Watch for these red flags:
Changes you didn’t make: Your channel name, profile photo, handle, description, or external links were updated.
Videos or live streams you didn’t create: You may see uploads you don’t recognize, scam live streams, or replays that weren’t posted by you.
You receive warnings or strikes: YouTube may send emails about Community Guidelines violations, copyright claims, or suspicious activity tied to content you didn’t publish.
You can’t log in or your password stops working: A sudden login failure may mean your password was changed or your account access was locked.
Monetization or AdSense settings changed: Attackers may try to redirect revenue or alter payment associations.
If any of these are happening, assume your channel is compromised and start recovery steps immediately.
What to Change Immediately If Your YouTube Channel Was Hacked
If your YouTube channel was hacked, assume your Google login details may have been stolen.
That means simply getting back into your channel isn’t enough; you also need to update the passwords and settings attackers could still use.
Here’s what to change right away:
- Change your Google Account password
- Enable two-factor authentication (2FA)
- Remove unknown devices and active sessions
- Check and update your recovery email and recovery phone number
- Remove any unfamiliar channel owners/managers/editors
- Remove suspicious connected apps or third-party access
- Review your AdSense/monetization settings for changes
- Update any other accounts that share the same password
If you suspect the takeover started through malware or phishing, it’s also smart to update passwords for other sensitive accounts tied to your Google identity, like Gmail, Google Drive, banking accounts, or payment apps.
Using a password manager like McAfee’s can help you create strong, unique passwords for every account, and store them securely in one place.
Step-by-Step: How to Recover a Hacked YouTube Channel
| Step | What to Do | Why It Matters |
| 1. Recover your Google Account first | If you can still log in, change your password immediately. If you can’t, start Google’s account recovery process. | Your YouTube channel is tied to your Google Account. If your Google Account is compromised, your channel will remain vulnerable. |
| 2. Secure your Google Account | Enable 2FA, review recent logins, and remove unknown devices. | Hackers often stay logged in through active sessions even after a password change. |
| 3. Remove unknown channel access | Check channel permissions and remove any unfamiliar owners, managers, or editors. | Attackers may add themselves as a manager to keep access even after recovery. |
| 4. Stop scam live streams and remove suspicious uploads | End any unauthorized livestreams, delete scam videos, and remove malicious links from descriptions. | Scam streams can damage your reputation and trigger policy strikes quickly. |
| 5. Revert channel changes | Restore your channel name, branding, About section, links, and settings. | This helps prevent your channel from being used to impersonate a brand or run scams. |
| 6. Review YouTube Studio for strikes or policy issues | Check for Community Guidelines strikes, copyright claims, or monetization restrictions. | Hackers often upload policy-violating content that can put your channel at risk. |
| 7. Scan your device for malware | Run a trusted security scan to check for spyware or password-stealing malware. | If your device is infected, attackers can steal your new password immediately. |
| 8. Contact YouTube/Google support if you’re still locked out | Use YouTube’s hacked channel support tools or Google Account recovery help. | If self-recovery fails, YouTube may be able to help restore access or guide you through next steps. |
If you’re still having issues after completing these steps, be sure to visit YouTube and Google’s official support resources for hacked accounts.
And, if you’re an eligible creator, you can also contact YouTube’s Creator Support Team.
Watch for Phishing “YouTube Support” Scams
One of the most common ways YouTube channels get hacked is through phishing.
Scammers impersonate:
- YouTube support
- YouTube Partner Program emails
- Copyright violation notices
- Brand sponsorship offers
- Verification or monetization warnings
They try to pressure you into clicking a link, downloading a file, or logging in through a fake Google sign-in page.
If you receive a suspicious email or message, don’t click.
Instead, open YouTube Studio directly and check your account status from inside the platform.
Final Tips: Recovering From a YouTube Channel Hack
A hacked YouTube channel is stressful for a reason: it doesn’t just affect your account. It affects your audience, your reputation, and your income, especially if monetization is involved.
The most important steps are:
- Act quickly
- Recover your Google Account first
- Change your password and enable 2FA
- Remove unknown channel managers and owners
- End scam live streams immediately
- Remove suspicious uploads and links
- Review YouTube Studio for strikes or violations
- Scan your device for malware
And if you’re still locked out or something doesn’t look right, follow YouTube’s official recovery guidance and contact Google/YouTube support directly.
YouTube may be able to help restore access, reverse changes, or provide instructions for appealing a termination if your channel was taken down during the hack.
McAfee also offers a free antivirus scan that can help you detect malware or suspicious programs that may have compromised your account in the first place.
Frequently Asked Questions
| Q: How do I know if my YouTube channel was hacked? A: Common signs include channel name or branding changes you didn’t make, scam livestreams, videos uploaded that aren’t yours, suspicious external links added to your channel, or being locked out of your account. |
| Q: Why does a hacked YouTube channel usually mean my Google Account was hacked too? A: Because YouTube channels are tied to Google Accounts. If your channel was taken over, your Google login credentials or active session may have been compromised. |
| Q: What should I do if my channel is live-streaming a crypto scam? A: End the livestream immediately if you still have access. Then change your Google password, remove unknown channel managers, enable 2FA, and remove scam links from your channel page and video descriptions. |
| Q: Can I get strikes or lose my channel because of videos the hacker uploaded? A: Potentially, yes. Scam uploads can trigger Community Guidelines or copyright violations. That’s why it’s important to remove unauthorized content quickly and review YouTube Studio for strikes. |
| Q: What if I can’t log in at all? A: Start Google’s account recovery process as soon as possible. If you’re still locked out after recovery attempts, visit YouTube’s official hacked channel support resources for next steps. |
| Q: How do I know if the hacker is fully kicked out? A: Review your Google Account security settings, logged-in devices, recovery email/phone settings, and channel permissions. Remove anything unfamiliar and enable 2FA to reduce the chance of re-entry. |
The post YouTube Channel Hacked? Restore Owner Access and Stop Live-Stream Scams appeared first on McAfee Blog.
PromptSpy ushers in the era of Android threats using GenAI
Is Poshmark safe? How to buy and sell without getting scammed
Reddit Hacked? How to Regain Access and What to Change Immediately
It usually starts with a small, uneasy moment.
A password reset email you don’t remember requesting. A login alert that doesn’t make sense. Strange comments showing up under your username that you swear you didn’t write.
Sometimes you don’t notice at all…until someone messages you asking why you’re suddenly promoting crypto giveaways, posting spam links, or commenting across random subreddits.
A hacked Reddit account isn’t just embarrassing. It can be a real security risk. Attackers often use compromised accounts to spread scams, steal personal information, or take advantage of your reputation in online communities.
This guide walks you through exactly what to do if your Reddit account has been compromised: how to spot the warning signs, how to regain control, and what security steps to take so it doesn’t happen again.
Signs Your Reddit Account May Be Compromised
Reddit account takeovers don’t always look dramatic at first. The earliest warning signs often feel subtle.
Watch for these red flags:
Password or email changes you didn’t make: You may receive an email from Reddit saying your password or email address was updated.
Posts, comments, votes, or chat messages you don’t recognize: Hackers often use your account to upvote scam content or spam communities.
Authorized apps you don’t remember approving: Some attackers compromise accounts through unsafe third-party apps or browser extensions.
Unusual login activity or unfamiliar IP history: Reddit allows you to review recent account activity, which may show logins from locations you’ve never visited.
Sudden account lock or forced reset notice: In some cases, Reddit may lock your account or prompt a password reset as a security precaution.
If any of these are happening, assume your Reddit account is compromised and start recovery steps immediately.
What to Change Immediately If Your Reddit Account Was Hacked
If your Reddit account was hacked, assume your login details may have been stolen.
That means simply getting back into your account isn’t enough, you also need to update the passwords and settings attackers could still use.
Here’s what to change right away:
- Change your Reddit password
- Change the password for the email account connected to Reddit
- Update any other accounts that share the same password
- Remove suspicious authorized apps
- Log out of all active sessions/devices
- Turn on two-factor authentication (2FA)
- Update your recovery options (email, phone, backup codes)
If you think the hack started from malware or a phishing link, it’s also smart to update passwords for other sensitive accounts, like banking, payment apps, or your Apple/Google account. Using a password manager like McAfee’s can help you create strong, unique passwords for every account, and store them securely in one place.
Step-by-Step: How to Recover a Hacked Reddit Account
| Step | What to Do | Why It Matters |
| 1. Reset your password immediately | Use Reddit’s password reset flow and create a strong new password. | This is the fastest way to cut off unauthorized access. Resetting your password can also log you out across devices. |
| 2. Check your inbox for Reddit security emails | Look for emails saying your password or email address was changed. Follow any “this wasn’t me” instructions if available. | If a hacker changed your account details, Reddit’s security email may be your best chance to reverse it quickly. |
| 3. Review account activity and active sessions | Check where your account is logged in and log out of unfamiliar sessions/devices. | Hackers often stay logged in even after making changes, especially if you don’t remove active sessions. |
| 4. Remove suspicious authorized apps | Review connected apps and revoke access for anything you don’t recognize or no longer use. | Some account takeovers happen through unsafe third-party apps, not password guessing. |
| 5. Scan your device for malware | Run a trusted security scan to check for spyware, password-stealing malware, or malicious browser extensions. McAfee offers a free antivirus scan service. | If your device is compromised, attackers can steal your new password(s) immediately. |
| 6. Secure the email account tied to Reddit | Change your email password and enable 2FA. Check recovery settings to make sure they’re yours. | If your email is compromised, the attacker can keep resetting your Reddit account and locking you out. |
| 7. Contact Reddit support if you’re still locked out | Submit a request and choose: Security problems → I think my account has been hacked. Include your username and details. | Reddit may be able to help restore access or reverse changes if self-recovery doesn’t work. |
Watch for Phishing “Reddit Support” Scams
One of the most common ways accounts get compromised is through phishing.
Scammers impersonate:
- Reddit moderators
- Reddit admin messages
- Security alerts
- Fake “copyright violation” notices
They try to trick you into clicking a link and logging in on a fake site.
If you receive a suspicious message, don’t click.
Instead, open Reddit directly in your browser or app and check your account settings from there.
Final Tips: Recovering From a Reddit Hack
A hacked Reddit account can feel strangely personal, because your profile reflects your interests, communities, and identity online.
The most important steps are:
- Act quickly
- Secure your email account first
- Reset your password and log out of all sessions
- Remove suspicious authorized apps
- Enable two-factor authentication (2FA)
- Scan your device for malware
And if you’re still locked out or something doesn’t look right, follow Reddit’s official recovery guidance and contact Reddit support directly.
Reddit may be able to confirm suspicious activity, restore access, or help reverse account changes.
Frequently Asked Questions
| Q: How do I know if my Reddit account was hacked?
A: Common signs include password or email changes you didn’t request, unfamiliar authorized apps, unusual IP history, and posts/comments/votes you don’t remember making. If any of these appear, treat your account as compromised. |
| Q: Will resetting my Reddit password log out the hacker?
A: In many cases, yes. Reddit notes that resetting your password can log you out across devices, which is one of the fastest ways to cut off unauthorized access. |
| Q: What if my Reddit email address was changed?
A: Check your email inbox for a message from Reddit. Reddit may provide instructions to reverse the change, but you’ll typically need to input the original email address associated with the account. |
| Q: What should I do if I can’t get my account back?
A: Submit a support request and select: Security problems → I think my account has been hacked. Include your username and explain what suspicious activity you noticed. Reddit also suggests checking r/help for additional guidance. |
| Q: Should I remove authorized apps after a hack?
A: Yes. Reddit specifically warns that unsafe authorized apps can lead to account compromise. Remove anything you don’t recognize or no longer use. |
| Q: What’s the biggest mistake people make after a Reddit hack?
A: Only changing their Reddit password. If your email account or device is compromised, attackers can regain access quickly. You should secure your email, scan your device, and update reused passwords. |
The post Reddit Hacked? How to Regain Access and What to Change Immediately appeared first on McAfee Blog.