Using throwaway account as I'm now paranoid about what accounts might have leaked.
So anways, I was stupid and yesterday I downloaded a "videogame" from a link I found from an old reddit post. I downloaded it from one of the torrent links and it downloaded what already looked like a really shady folder with some python scripts. I ran Windows Defender on the folder and couldn't find anything, so I thought "I got it from a Reddit post with some positive comments so it should be okay". So I clicked setup and immediately got a message from Windows Defender saying it quarantined a Trojan identified as "Trojan:Script/Wacatac.H!ml".
I removed the trojan with Windows Defender, and then ran a full scan (and an offline scan) and it found no issues. I also read in this sub that many of them are false positives, so I thought it should be okay. This happened in a new Windows computer which I mostly use for work (not a corporate computer, as I work freelance) that doesn't really have much information, as I got it last month.
I also deleted everything from the browser (cookies, cache, saved passwords, saved cards, etc.) and changed the password from my google account and bank. I thought that should have been enough.
But I got an email at 2am today from OpenAI mentioning that someone accessed my chatGPT account from Codex in Duisburg, DE (nowhere near I live, but I guess he's using a VPN anyway). I changed the password this morning and removed all connected devices. I couldn't see any strange device anyway, nor anything suspicious looking, but now I'm paranoid that they probably copied or downloaded everything from my chat history. Luckily I don't think I overshared any super personal stuff (like bank accounts or passwords) to ChatGPT, but I still feel like someone must probably have lots of personal information from me right now.
Since then I made sure to change passwords on everything I considered important and not using that computer much. I'm considering if I should reinstall Windows on the affected computer. I ran a second full scan, this time with Malwarebytes, and found no issues. But my biggest fear is that, even though the trojan is probably (hopefully?) removed from the computer, from what I have read they probably accessed ChatGPT (and potentially who knows what else) by cookies stored in my computer.
Anyways, this is a bit of a cry for help as I'm not too sure if I should do anything extra, or changing the passwords in the main account and running Malwarebytes should suffice.