I downloaded what I thought was a Minecraft modpack from someone I knew, but it contained an infostealer Trojan. It compromised my email and Discord accounts, logged me out everywhere, and the attacker changed my Gmail account into a supervised child account with themselves listed as the parent. I can't get through the normal recovery process because it now requires the attacker's login details, and the account isn't disabled or deleted. I've reported the incident to the authorities and contacted Discord, but they said they can't help because I no longer control the email address. I still have the malware on the computer, since it only appears to run when Minecraft is launched, and I have information about the attacker. What steps can I take to recover my accounts and secure everything else?
4 Answers
An infostealer may have taken browser cookies, saved passwords, tokens, and recovery information, not just your Gmail and Discord credentials. Don’t log into anything important from that machine before wiping it. Change your primary email password first from a clean device, then update financial, gaming, and other accounts, check recovery addresses and phone numbers, and notify financial institutions if payment details were stored in the browser.
For future downloads, avoid executable files from chat contacts—even real-life friends—unless you independently confirm they sent the file and understand what it does. Keep your operating system and security tools updated, use a password manager with unique passwords, and consider separate browser profiles for sensitive accounts.
The account may still be recoverable, but normal recovery can fail after an attacker changes the age and supervision settings. Use Google’s official account-recovery and child-safety support paths, provide older passwords, account creation details, previous recovery information, and any evidence showing the change was unauthorized. Keep screenshots, the attacker’s address, timestamps, and the malware sample for investigators, but don’t contact or threaten the attacker directly.
Treat every account that was logged in on that computer as compromised. From a different, trusted device, change passwords everywhere, make each password unique, revoke existing sessions and backup codes, and enable two-step authentication. Also contact the official account-recovery teams and explain that the account was converted into a supervised child account by an attacker. Don’t keep using the infected installation—disconnect it from the internet and perform a clean Windows reinstall, or have a professional inspect it first.

This applies even when the file came from someone you know online. Their account may have been taken over, and executable files should be verified through a separate trusted channel before opening them.