I downloaded a suspicious file, and within a couple of days several of my online accounts were compromised. I ran a deep Windows Defender scan, which found and removed multiple trojans. I then replaced the Windows drive with a new SSD and installed Windows from scratch, but I'm still receiving login alerts and some accounts were apparently accessed again.
I've signed out of active sessions, reset my passwords, enabled or checked two-factor authentication, disconnected the PC, and flashed the BIOS. I didn't wipe every other internal or external drive because I'd prefer to avoid that unless it's necessary.
Could this be a motherboard or firmware rootkit, or are attackers more likely using previously stolen passwords or session tokens? What steps should I take to secure my accounts and verify that the rest of my system is clean?
3 Answers
Don’t overlook other drives. If the suspicious file or browser data was also present on a secondary or external drive, disconnect it and scan it from a trusted boot environment. Back up only personal documents you know are safe, then wipe and repartition the drives if you cannot confidently identify what was on them. Avoid restoring executable files, cracked software, browser profiles, or old extensions.
First separate failed login attempts from successful access. If the attackers only have your old usernames and passwords, automated attempts can continue for a long time even after you secure the accounts. Use a different, trusted device to change every password, sign out all sessions, enable 2FA, and check each account for unfamiliar recovery addresses, phone numbers, authenticators, forwarding rules, or active devices. Also review your password manager and change the password for the manager itself.
Some accounts were accessed and their passwords were changed without prompting for 2FA, so I’m concerned that session tokens were stolen. I’ve signed out of all sessions now and am checking recovery settings as well.
The stolen information may already be circulating, so new login alerts can continue even after the original infection is gone. If the alerts are only failed attempts, they don’t prove the new installation is compromised. For especially important accounts, move them to a new email address, use unique passwords, require an authenticator app or security key where available, and contact the provider if an attacker changed settings or bypassed 2FA.

I replaced only the Windows drive and the drive where I downloaded the file, so I may disconnect and inspect the remaining drives before using them again.