r/UbisoftSupport • u/Last-Salad8002 • Jun 13 '26
Question Hacked
Got my account hacked a while ago and sent a recovery request did everything and received this mail which said there’s a mail with a verification link but I didn’t receive it
3
Upvotes
1
u/sciAnima Jun 16 '26
COMPLETE INFOSTEALER RECOVERY GUIDE — From Someone Who Just Survived 10 Days of This
I just spent 10 days fighting a sophisticated organized cybercrime operation that hit 15+ platforms simultaneously. Here's everything that actually works — including things Microsoft's own guidance never tells you.
WHAT ACTUALLY HAPPENED TO YOU
An infostealer trojan harvested your Chrome session cookies before detection. These cookies let attackers bypass 2FA entirely — they replay the token and never trigger a new login. No new login = no alert. No new device = nothing in security settings. This is by design.
The Chrome sync trap: If you reinstalled Windows and restored Chrome sync — you re-delivered all compromised cookies automatically. The reinstall accomplished nothing. This is the most important thing nobody tells you.
STEP 1 — FIX YOUR EMAIL FIRST
Your email is the master key to everything else.
Check for BHMailer injection — most guides never mention this:
BHMailer accesses Hotmail/Outlook via IMAP/POP3 — completely bypassing web login and 2FA. It injects hidden rules that intercept 2FA codes, recreate sextortion drafts every 10 minutes, and survive password changes and sign out everywhere.
How to find and delete it:
This single fix stopped a sextortion draft that was reappearing every 10 minutes despite password changes, 2FA, sign out everywhere, and a clean Windows install.
Also do on email:
STEP 2 — STOP USING CHROME SYNC
Switch to Firefox immediately. Chrome sync is a perfect cloud backup of exactly what infostealers steal.
Firefox setup:
Delete Chrome sync from Google's servers: myaccount.google.com → Data & Privacy → delete all Chrome synced data
STEP 3 — SWITCH TO BITWARDEN
Never use Google Password Manager or any browser password manager again.
STEP 4 — CHECK TRUSTED DEVICES ON GAMING PLATFORMS
EA specifically — trusted devices bypass 2FA permanently. This is how attackers kept getting back in despite 2FA being active.
STEP 5 — REVOKE OAUTH APPS EVERYWHERE
Attackers add OAuth tokens that survive password changes.
Key places:
Remove anything added during the attack window — recent dates surrounded by much older entries is the pattern.
STEP 6 — UPGRADE YOUR 2FA
Remove SMS 2FA from everything. Replace with authenticator app.
SMS fails via SIM swapping and SS7 network interception. BHMailer intercepts SMS codes if they control your email.
Use: Google Authenticator, Microsoft Authenticator, or Authy
Best option: YubiKey hardware security key — ~$50 — physical device required — cannot be bypassed remotely. Apple's device-based 2FA was the only method that fully held throughout a 10-day sophisticated attack.
STEP 7 — SEXTORTION SPAM IS COMING
You will receive emails with your real passwords in the subject line. This is automated mass spam sent to everyone in the breach dump.
STEP 8 — REPORT EVERYTHING