My Discord account was compromised on July 31, 2026, so I changed its password. The next morning, Google warned me about suspicious activity and indicated that my device might contain malware. I also noticed a login from a macOS device on July 29, which was not me because I do not use a Mac. Shortly afterward, Steam warned me that the email address connected to my account had been changed without authorization.
Steam provided an IP address for the suspicious activity. I looked up its approximate location and found a phone number listed at that location, but I am not sure how accurate or useful that information is.
I have already found malware by scanning the computer with Malwarebytes. Should I simply remove it, or take additional steps? Should I report the IP address or location, and if so, where? Most importantly, what damage-control steps should I take? I am considering changing the passwords for all of my email accounts and any other services that use those email addresses.
4 Answers
Change passwords from a separate device that you know is clean—not from the potentially infected PC. Start with your primary email accounts, then your password manager, banking and payment accounts, gaming accounts, and anything else tied to those emails. Use new, unique passwords and enable two-factor authentication wherever possible. Also review account recovery emails, phone numbers, active sessions, connected apps, and forwarding rules.
The IP location is only an approximate lookup and may point to an internet provider, VPN, proxy, or another compromised computer. The phone number listed on a map is very unlikely to identify the attacker reliably. Save the Steam and Google security emails, login timestamps, and IP information, report the account takeovers through the official account-recovery channels, and contact local law enforcement if there is significant financial loss or identity theft. Do not contact the person or location yourself.
Treat the computer as untrusted until Windows has been completely erased and freshly reinstalled. Malware can survive ordinary scans or leave behind scheduled tasks and other changes, so removing the detected files may not be enough. Back up only personal documents you know are safe, perform a clean Windows installation, install updates, and then restore your files carefully.
A password change made before cleaning the computer could have been captured by the malware. Disconnect the affected PC from the internet while preparing the reinstall, and use a trusted phone or another clean computer for password changes and account recovery. Afterward, sign out other sessions and check for unfamiliar software, browser extensions, email rules, and saved payment methods.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures