Over the past two days, several of my accounts have been compromised one after another. My Discord account was used to send scam images, then my Instagram account was taken over, and someone attempted to buy a $200 Amazon gift card. Amazon canceled the order, but I also received suspicious-login alerts for a second email account and unexpected Amazon OTP messages. I've recovered the accounts, changed passwords, enabled two-factor authentication, changed my email password, moved money out of my spending account, and froze my card. Could an infostealer or stolen browser session token be allowing access to multiple accounts? Should I disconnect and completely reinstall Windows, and how should I safely protect my files and accounts?
3 Answers
Contact your bank and card issuer, monitor transactions and credit activity, and let Amazon and your email providers know that the accounts were compromised. Save evidence such as login alerts and transaction details. After reinstalling, update Windows, install software only from trusted sources, enable 2FA with an authenticator or security key where possible, and avoid restoring old browser data or unknown extensions.
This pattern strongly suggests that the computer or browser session may be compromised, possibly by an infostealer. Disconnect the PC from the internet and stop logging into accounts from it. Using a separate, trusted device, change every important password again, make each one unique, revoke active sessions and saved login tokens, and review recovery email addresses, phone numbers, payment methods, and 2FA settings. Then create Windows installation media from the clean device and perform a complete reinstall rather than relying on a quick reset. Back up only essential personal files, since copied browser profiles, extensions, executables, and other data could carry the malware back.
A full reformat may be excessive in some cases, since reused passwords or credentials exposed in an old breach can also explain several account takeovers. However, with repeated compromises despite password changes and 2FA, treating the PC as untrusted is reasonable. Reinstalling from clean installation media is the most reliable way to remove an infostealer, especially if you don’t know where the original infection came from.
The attempted purchase and continued login alerts make this more than a simple password-reuse problem. I’d choose the clean reinstall after securing the accounts from a separate device, rather than continuing to change passwords on a potentially infected computer.

I’ll use another device for the password changes and avoid copying anything from the old browser profile. I’m especially concerned about losing access to my accounts again if the sessions weren’t revoked.