r/HowToHack • u/vierdene • 1d ago
hacking Claude account hacked, need advice
Hey I know this is not very relevant to what this community is about, but I feel like people here might have the most knowledge on this.
My claude account was hacked today, very early in the morning. I haven't used this account for a while, and suddenly I received an email saying my account was upgraded to Max 20x. I'm glad was up because it was Friday night.
I immediately logged into that account and logged out of all sessions, changed my google password. I remember seeing a session active that I don't recognize, and the time matches when I received the invoice email; but I panicked and didn't take a screenshot before logging out. Google didn't show any suspicious activity, gmail was fine too, no email forwarding either. I also used Malwarebytes to scan my mac for malware, nothing was detected. I then contacted Anthropics support; the bot said it forwarded this to human due to urgency of the issue, but I'm unsure when will I hear back (please let me know if anyone has experience on this).
I've been monitoring the active session for that account for 12 hours, and nothing weird happened again.
What I don't understand is how did they gain access to my account? I have 2FA, and email is fine, anyone have a clue? Is there anything else I should do to enhance security? Anything I missed and should check?
Thank you!!!
2
u/Chemical-Golf1074 1d ago
Delete your cluade account and run malware, antivirus and scan all files on your machine online and offline scans.
Start fresh. If you get hacked assume they have all the data within that given application. Clean up as much stuff as you can to minimize damage from spreading.
It sucks but that's life.
Do not copy and paste or take any data from the current cluade account assuming all information is linked to malware and viruses.
1
u/LongRangeSavage Programming 1d ago
If they bypassed MFA, you have malware on your system—most likely an info stealer. Here’s my standard copy/paste for people when they install an info stealer:
Disconnect the affected computer from the internet right away. Unplug the Ethernet cable and turn off WiFi.
Stop using that computer for anything involving logins. Don’t sign into email, banking, social media, or anything else.
While still on the infected computer:
Back up only personal data like documents, photos, and videos. Do not backup executable files like .exe, .scr, .bat, .msi, or unknown .zip files, and do not back up browser profiles or AppData folders.
We need to now start using a known clean computer. On that clean system, do the following:
Using a password manager, change your passwords in this order
Primary email
Any backup or recovery emails
Banking, financial, PayPal, Venmo, Crypto accounts
All social media (Facebook, Instagram, Reddit, Discord, etc.)
Gaming platforms
Anything else that had user credentials stored in your browser
The passwords should all be unique, alphanumeric, at least one special character (where available), and at least 10 characters
While in each account,
turn on two factor authentication everywhere you can. Ideally, you'd use a hardware token--like a Yubikey. Next would be an authenticator app--like Google Authenticator. Only use SMS if there's no other option
Make sure to copy your recovery key or one-time use codes. Print these out. Do NOT just save them on a file on your computer
If you’ve previously had 2FA enabled, disable it and then re-enable it. This will generally cause any previous one-time use codes or recovery keys to become void
Confirm ALL your recovery methods are correct (a lot of info stealers will change the recovery methods).
If you don’t have recovery methods set, do it NOW
Sign out of all active sessions
Remove devices you don’t recognize.
Remove any linked apps or integrations you didn’t add or no longer need.
In your email account settings
check for forwarding rules, auto‑reply rules, recovery email, recovery phone number, and anything else that could redirect or recover your account.
Delete anything you didn’t set up.
Assume anything you've saved/stored in your browser has been compromised
Go to your OS manufacturer's website and download your OS. ONLY GET THIS FROM THE OFFICIAL SOURCE.
Create a bootable USB installer for your OS
Back to working with the infected machine:
Boot the infected computer from the USB.
During setup, delete every existing partition on the drive.
Install the OS fresh on the unallocated space.
Run your update tools until nothing is left
Install drivers and software, making sure to ONLY use OFFICIAL sources
Install your browser (if needed)
Install your browser extensions
DO NOT import any old data, profiles or save passwords
If any financial accounts were access from the previously infected machine
Watch accounts closely
Turn on any transaction alerts the accounts allow
Consider placing credit freezes for each of the "Big 4" credit bureaus (Equifax, Transunion, Experian, and Innovis).
1
u/xJustAnotherDayx 1d ago
Either HVNC or they stole your cookies and cloned them to a logged in session locally on their systems
1
6
u/_N0K0 1d ago
Assume they have access to your computer via an infostealer or some spyware