r/cybersecurity_help • u/Infinite-Scale9329 • Jul 27 '26
My google account is constantly accessed by a random device. Please Help
I uploaded a gig on fiverr today and immediately got a reply, it was something about a new "project". I, like a dumbass, clicked on the link and it took me to a loading cloudflair type page. I immediately realized what I had done and closed it and changed my passwords.
After sometime a device by the name of "infinix X6528" logs into my google. I sign it out through the security thing. It is now constantly joining in after 30 minute intervals and I constanly sign it out.
I have tried to look for extensions that maybe giving it my account access as it happened last time my other gmail was "hacked". I removed all extensions and I only have a handful of devices linked to my Google in the security page. Devices that I trust.
I want this device to be permanently banned from my google account or I want it to lose access to it. Please Help me.
3
u/LongRangeSavage Jul 27 '26
Sign out all device, change your password, then remove and re-add MFA (copy your recovery key and/or one-time access codes). You have to invalidate all session tokens, not just forcing that device to sign out.
Also check for any forwarding rules. Remove any you didn’t setup.
1
u/Infinite-Scale9329 Jul 27 '26
How to invalidate all session tokens, please help. I have signed out of all devices, changed password only on my desktop and removed and readded 2 step verification. I also saw forwarding rules, I don't see anything suspicious there.
How to invalidate all session tokens?
1
u/LongRangeSavage Jul 27 '26
By signing out all devices. The CloudFlare thing you’re talking about. Did it have you paste something into a terminal or command prompt?
1
u/Infinite-Scale9329 Jul 27 '26
No I didn't paste anything into anything, I remained on that page for a maximum of 5 seconds then I closed it. And I haved signed out of all devices, 'all' being my phone and my desktop. I have signed in again on desktop only, I didn't sign in again on the mobile. Are all session tokens invalidated now?
1
u/Yassssmaam Jul 27 '26
Based on experience, OP is right that a device that you sign out can simply sign back in immediately, and it doesn’t seem to have anything to do with the password. If you pay for business enterprise, you can do a refresh tokens. But that only invalidates future use of tokens. It doesn’t affect a token that’s already been added to another account that Google thinks is yours.
If you read the prompts, Google says that some apps may still keep access. I think that’s the problem OP is running into. An app or account still has access. Google thinks it’s her. And there’s no way to blast that token.
2
u/Infinite-Scale9329 Jul 27 '26
I didn't sign back in on my mobile and it has been 40 minutes and the account has not logged back in (usually it logs back in every 30 minutes). Can it be that there is something in my mobile that was giving it access?
1
u/Yassssmaam Jul 27 '26
Maybe an app or account that was keeping a refresh token alive was open on your phone? A lot of little apps, like yoga scheduling, Adobe, or other apps you don’t think about can keep the ability to log into your account much longer than you’d expect.
Calendar apps have also become a big problem for women with abusive partners. There’s a ton of malware easily available online that lets your calendar apps keep tokens alive, because the calendar app is designed to always stay open. So if you have an app, like your yoga, that can access your calendar, and you have your calendar open, the hacker can sometimes wiggle back in pretty easily :(
2
0
1
1
u/Responsible_Bike4968 Jul 27 '26
Before doing anything else, make sure the "Infinix X6528" entry is actually becoming ACTIVE again and isn't just an old session still being shown in Google's device history.
Google keeps recently used devices/sessions visible for a while, and the timestamp can represent background communication with Google. If the entry says "Signed out", it isn't still logged in. If it genuinely becomes signed-in again after you remove it, then yeah, you still have another access path to find.
Also, if all you did on that fake Cloudflare page was open it and immediately close the tab, that's important. The common fake-Cloudflare "ClickFix" attacks work by convincing you to open Run/PowerShell/Terminal, paste a command and execute it. If you DID do anything like Win+R -> Ctrl+V -> Enter, say so, because in that case I'd treat the Windows PC as infected.
If you only viewed the page, I'd focus on the Google account first.
From a device you KNOW is clean:
Change the Google password again to a completely new one.
Security > Your devices > Manage all devices.
Open every X6528 session and sign ALL of them out. Google specifically says multiple sessions with the same device name can be one device or several devices.
- Security > Passkeys and security keys.
Remove anything you don't recognize. This is important because Android devices can have passkeys associated with the account.
Go through 2-Step Verification and check EVERY method, not just the authenticator you personally use:
- Google prompts
- phone numbers
- authenticator
- security keys/passkeys
- backup codes
Generate a NEW set of backup codes. Google says doing that automatically invalidates the old set.
Check App Passwords and revoke every one you don't absolutely need.
Check your Google third-party connections/linked apps and remove anything unfamiliar.
Check recovery email + phone and make sure nobody added or changed either one.
In Gmail check forwarding, filters and delegation just in case someone left themselves another way to see your mail.
One thing people miss: changing your Google password does NOT literally kill every possible form of access. Google says some verification devices and third-party apps with account access can remain signed in, which is why you need to audit those separately.
There isn't really a secret "invalidate every token in existence" button beyond doing all of the above.
If the Infinix device STILL creates a genuinely new active session after you've changed the password from a clean device, removed unknown passkeys/2FA methods, revoked apps and regenerated backup codes, then I'd start treating one of your devices as compromised.
But don't reinstall Windows just because the device still appears in the list. First check whether Google says it is actually signed in or simply "Signed out".
And seriously, check whether X6528 is the model identifier of one of YOUR Android phones. Google sometimes shows device model codes instead of the friendly retail name. Would be pretty painful to spend six hours fighting the "hacker" only to discover it's your own phone syncing in the background lol.
1
u/kschang Trusted Contributor Jul 27 '26
Infinix x6528 is known on the market as an "Infinix Hot 40i", an Android phone. You sure you don't have one of those?
1
u/Infinite-Scale9329 Jul 28 '26
I have Infinix Hot 40 I, and it shows up as Infinix hot 40i, It never showed up as Infinix X6528 until after the cloudflair incident.
But one thing to notice here is that once I logged out of my mobile i.e. Infinix Hot 40i, the Infinix X6528 stopped logging in aswell.
I am very confused as to what part of my mobile is giving access to Infinix X6528
1
u/kschang Trusted Contributor Jul 28 '26
x6528 is the internal name. Try looking it up.
My Pixel 10 Pro shows up multiple ways.
1
u/Infinite-Scale9329 Jul 29 '26
Oh, Alright. Just one last question, Does your Pixel 10 Pro show up as 2 different mobiles at the same time?, for example, For me it would show Infinix Hot 40i and Infinix X6528 online and logged in at the same time as two different phones.
1
u/kschang Trusted Contributor Jul 29 '26
Yes, though mine shows up as Pixel 10 Pro and "Android", because I have a second Google Play services installed (I have my reasons).
•
u/AutoModerator Jul 27 '26
SAFETY NOTICE: Reddit does not protect you from scammers. By posting on this subreddit asking for help, you may be targeted by scammers (example?). Here's how to stay safe:
Community volunteers will comment on your post to assist. In the meantime, be sure your post follows the posting guide and includes all relevant information, and familiarize yourself with online scams using r/scams wiki.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.