I recently discovered that I've been hacked, and I'm really freaked out. It started when I got an email from Google saying my password was found in a data breach, but I was swamped with college work, so I didn't handle it immediately. Then, I received a 2-step verification email from Roblox, which showed a login attempt from Russia. I panicked and changed my Roblox password but realized later that the original email had been deleted. It hit me that my email was hacked, too. I managed to change my email password using phone verification, but it was too late—the hacker had already logged into my Discord and sent scam messages to my friends. I changed my Discord password as well, but I'm really nervous because I used the same password for multiple accounts. This is my first experience with a hack, and I'm scared. Can anyone provide advice on what I should do next?
1 Answer
First off, you definitely need to stop using the same password for every site. It's crucial to have unique and complex passwords for all your accounts, ideally at least 14 characters long with a mix of letters, numbers, and special characters. Change all your passwords now and enable two-step authentication whenever possible, or consider using a passkey for added security.
Thanks for the advice! I really appreciate your help; it means a lot right now.

I really recommend getting a password manager like Bitwarden. It helps generate unique passwords for each account and securely stores them. Also, definitely use multi-factor authentication (MFA) for everything you're able to, including Discord. Just a heads up, you’ll need to reach out to support for any compromised accounts to recover them.