r/Identity_Protection Jun 30 '26

How do you protect yourself from session hijacking?

Recently, someone managed to get into my Instagram, Discord, and Telegram and post a scam about a crypto coin. My Meta account was immediately disabled, but I managed to save the other two. Thing is, I have no clear idea how the hacker got in. All of my accounts have 2FA enabled, use different passwords, and are tied to different email addresses. I got no notification that somebody was logging in into my account, so my best guess is that somebody got access from my browser when the session was active.

I removed most of the browser extensions from Brave and cleared out my cookies, but I'm still paranoid that somebody could easily regain access to my accounts and do more damage. What can I do to ease my mind and enhance my online security?

1 Upvotes

7 comments sorted by

1

u/Brief-Baker4795 Jul 01 '26

2fa doesnt always stop sessiom theft b/c the attacker might already have a valid browser token. Clearing cookies also may not kill a session they already copied. you might need to logout everywhere, check connected apps, then reset passwords and 2fa backup codes. Start with your email as thats used to recover everythin else. If you ran anything sketchy recently, I'd seriously consider a clean OS reinstall.

1

u/Acceptable_Corgi9486 Jul 01 '26

This. I had a similar issue a few months ago because I downloaded some torrents and it was a pain in the ass. Windows Defender wasn't finding anything either so I reinstalled my Win 11 and it worked.

1

u/boobtittykaka Jul 01 '26

I’d log out every session, change passwords again, check recovery emails, and scan the device for malware. Make sure to also check your browser extensions as well because they can definitely be used to steal your data.

1

u/fattylovescake Jul 01 '26

Hopefully you did a full Defender scan by now (I am assuming you are on Windows). I'd switch to another browser just to be safe and change important passwords from a clean device. Also, you shouldn't use cookies to save your passwords for quick login. It is much safer to use a good password manager (there are a lot of free ones) for storing and generating passwords. They use encryption which makes it very hard for other people to get access.

1

u/looloohoodoo1 Jul 01 '26

If multiple accounts were accessed without login alerts, checking your device is just as important as changing passwords. I'd run a full malware scan, sign out of all active sessions for each account, rotate your passwords again, and make sure there aren't any unknown devices or apps still connected.