YouTube channel hacked: how, recovery, and timeline

preview_player
Показать описание
How I accidentally compromised my computer as a result of a social engineering attack, resulting in a session hijack attack on my main YouTube channel. Recovery, and analyzing the timing of how it happened.

My initial very short video about the hack:
Рекомендации по теме
Комментарии
Автор

I'm so glad you got your account back! That was actually pretty quick, too.

It annoys me so much that every time I travel, I have to jump through a bunch of hoops to log into my YouTube account, including verifications on my phone, and email, and sometimes I even have to use a VPN myself just to get into my own account reasonable amount of time. Meanwhile, creators routinely get hacked by some dude out of Russia and Google's system seems to think it's fine. 🙄

Also, I just checked my email, and I have that exact same email about a sponsorship with Black Magic. They really are targeting everyone. Creators have to be constantly vigilant.

Thank you SO much for sharing this experience, so that other creators can learn from this!

NotJustBikes
Автор

Shining this much light on this type of scam is immensely useful. Sorry it happened, and thanks for the detailed info.

qkrotor
Автор

1:55 first thing to do on a new windows install is to enable show file extensions

fuzzydk
Автор

My favorite part of this video was Matthias whipping out his custom-made wooden selfie stick, haha!

JeffGeerling
Автор

"Microsoft Defender didn't find anything"
I feel your pain!

zqzj
Автор

And now we are all waiting for episode two in this new series :-)

HansvanSchoot
Автор

I’ve seen so many of my favorite YouTubers get hacked by this same method. The in depth video and explanation of everything really caught my interest. And props to you for keeping time stamps of everything down to the second during this time. You never fail to entertain us!

TechmattOfficial
Автор

Thank you for sharing your experience. Too many people are too embarrassed to share these details that are so helpful in keeping other people safe. I can't imagine the stress of this whole mess, and I hope you have some time to do something fun and relaxing.

ericapelz
Автор

Good to hear that you are back up and running again!

jorisdesmet
Автор

If I am hearing you right, some of the lessons here are:
1- Be VERY careful what you click and download.
2- Use 2-factor authentication for your Google account
3- A Twitter account may be helpful to contact Google if you are hacked
4- Record your channel ID somewhere for future reference
5- A second established YouTube account is helpful, if you have one

What else would you recommend to help others avoid a similar situation, or to get themselves out of one?

StumpyNubs
Автор

I knew someone i followed was hacked but I couldn’t figure out who. I’m glad you got it back so quickly.

stevenmusante
Автор

The “Session Cookie Attack” was easily fixed by YouTube. How? Even with the session enabled, if you want to change your YouTube account or delete all videos, you should need MORE than one “active session”. For example, “2-factor authentication” when deleting videos, changing account name, etc.

allenpayne
Автор

Some bits to consider: There's a non-zero risk involved with your other PCs now when you used your USB drive between them. Another potential vector is any other devices that were on your network or that you had credentials for saved on the original PC or if anything else on the network is unsecured (I'm thinking raspberry pis or any devices which had remote access or shared folders or the like).

ThatEgghead
Автор

Thank you for making such a detailed video on this. Everything you make is excellent.

localwan
Автор

I'm happy to hear that you got the account back and up and running. It was "good" of them to set the videos to private instead of deleting them all.

Makebuildmodify
Автор

Glad you’re back & thanks for sharing this experience!

markelder
Автор

So glad to hear you got the account back. When I saw your previous video I went to their scam live stream and reported it, hoping I was joining a few thousands doing the same thing.

burgersnchips
Автор

Glad you're back! Thank you for sharing such details so we can learn not to fall for this attack. I wish I could give you 2 thumbs up!

HobbyHalloween
Автор

Ugh! So sorry you had to go through this. Stuff of nightmares. So glad you got your channel back; and they didn't delete your content.

davidahiwaaynet
Автор

Geesh! It's never ending with the hackers. They sit there scamming good people all day long. Sorry to hear this but so glad you recovered as most do not.

mitchellhw
join shbcf.ru