My Instagram, Facebook, Meta, Discord, and several other accounts have been compromised one after another. I factory-reset my phone and PC today and enabled two-factor authentication, but I'm still worried the attacker may have access. What steps should I take to secure my devices and recover my accounts properly?
4 Answers
A normal factory reset may not be enough if the computer itself is infected. Use a separate, trusted computer to create official Windows installation media, completely erase the affected PC’s drive, and reinstall Windows from scratch. Keep the clean device off the old network during setup if possible, then install updates and security software before signing back in.
If accounts were being taken over even though two-factor authentication was already enabled, check for stolen session cookies, recovery-email changes, malicious extensions, or a compromised phone number. Use the providers’ account-recovery processes, save evidence of unauthorized logins, and contact support if you can’t remove an attacker’s recovery method.
Before changing credentials, use each service’s security page to sign out of every device and remove unknown recovery methods, connected apps, and active sessions. Then change passwords again after the clean reinstall. Also scan cloud storage and avoid restoring suspicious browser extensions, programs, or backups that could bring the problem back.
Start with the email accounts connected to everything else, since access to an email inbox can be used to reset nearly every other password. Sign out of all active sessions, revoke unfamiliar apps and devices, then set a completely unique password. Repeat that process for every account—don’t use the same base password with a different number or symbol. A reputable password manager can generate and store unique passwords for you.

Enabling two-factor authentication on every account is worthwhile too, preferably with an authenticator app or security key rather than relying only on text messages.