When Your Account Starts Posting Things You Never Wrote

Your Facebook is sending messages to people you haven't spoken to in years, and your Instagram is pushing links to some random giveaway. Your name is all over it, but you didn't write a single word of it.

If this has happened to you or someone you know, there's a good chance it started with a downloaded file: a game mod, a cracked app, something that looked completely harmless. And by the time the posts started appearing, the damage was already done.

The file that did nothing (that you could see)

This type of attack uses what's known as an "infostealer," a piece of malware that runs silently in the background, takes what it needs in a matter of minutes, and leaves without making a sound.

What it's after is everything your browser has saved: passwords, autofill details, and something called session cookies. A session cookie is what keeps you logged into a site after you've already signed in. When an infostealer grabs those cookies, the attacker can walk straight into your accounts as if they were already sitting at your keyboard, without ever needing your password.

That's why changing your password often isn't the fix people expect it to be; the password was never the key.

Why the spread happens so fast

Once an attacker is inside an account such as Facebook, they've got access to everything: your friends list, your groups, your messages. They use that access to spread the same malicious links further, which means your name and profile picture end up attached to something that hits your contacts, your community groups, anyone who trusts you enough to click.

Platforms such as Discord, Steam, and gaming accounts are particularly popular targets because they're filled with communities built on trust. A message from a friend's account telling you to check out a free game or a giveaway doesn't raise the same red flags as would a cold email.

What to do if it happens

Speed matters here. Sign out of all active sessions on every affected account as soon as you can. Most platforms have this option in their security settings, and it kills any access the attacker still has. Then change your passwords and turn on two-factor authentication if you haven't already, but do it from a different device, not the infected computer. If the malware is still sitting on that machine, it can capture whatever you type, which means a brand-new password gets stolen just as fast as the old one.

It's also worth letting people know quickly, because some of your contacts will have clicked the link before you've had a chance to warn them.

Once the accounts are secured, the infected computer still needs attention. If you're not sure whether it's been cleaned properly, or you just want to be certain before you trust it with your accounts again, bring it in and we'll take a look. It's a lot easier to sort out sooner than later.