A few months ago, an ex-boyfriend from an online relationship claimed he had accessed my Discord account and read private conversations. He mentioned details that made me think he may really have been inside the account. He also claimed he could access my iCloud and WhatsApp. At one point, I heard sounds playing through my headphones via Discord even though we were not in a voice call, although he could not hear me.
I deleted my old email and social-media accounts, created new ones, changed my phone number, and reset my Windows PC. Since then, he has only contacted a friend to ask about me. I recently received a WhatsApp verification-code message that I did not request, which has made me worried that he is still trying to access my accounts.
Could the Discord incident have been caused by malware or a compromised account? Does a factory reset remove this kind of access, and am I still at risk?
4 Answers
A factory reset plus changing passwords from a clean device and enabling multifactor authentication usually removes ordinary malware and stolen-session access. Check each account’s active sessions and sign out anything unfamiliar. Use unique passwords, and prefer an authenticator app or security key when available. If your phone carrier supports it, add an account PIN to reduce the risk of number-porting attacks.
His previous success may have been because he knew an old password, had access to a logged-in session, guessed security details, or used social engineering. That does not automatically mean he can bypass strong current security. Keep recovery email and phone details under your control, enable every available security option, and treat any new verification-code request as an attempted login rather than proof that he is currently inside.
The Discord sounds do not necessarily prove that he controlled your whole computer. Discord has features such as soundboards, audio playback, and account or session abuse that could explain what happened. Without forensic evidence, nobody can reliably determine whether it was malware, a stolen login session, or manipulation. A completely clean reinstall from trusted installation media is an extra-cautious step if you still distrust the PC, but a normal reset is generally sufficient for common malware.
That WhatsApp message most likely means someone entered your phone number and requested a login code. It does not mean they successfully accessed the account. Do not share the code, do not approve unexpected login prompts, and review WhatsApp’s linked devices for anything unfamiliar. The same principle applies to Apple: review trusted devices, recovery information, and sign-in alerts, then remove anything you do not recognize.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures