I believe I was hacked....

The problems began about 4 months ago. First my Yahoo account was hacked into, then about 3 weeks ago, my Facebook account was hacked. Then a few days ago I happened to be using my Safari browser and when I took a look at the TOP SITES tab there were sites on the list that I have NEVER accessed such as Twitter, EBAY, BBC and a site that I've never even heard of. I ran MacScan on the laptop..it only found 45 tracking cookies which from what I understand are annoying but not malicious..no Keyloggers. A friend of mine ran another program for Keylogger detection and didn't find anything. And I did the scan BEFORE I discovered what was going on with Safari. I took it in for servicing with an Authorized Mac repair center. The gentleman told me that they don't get involved with hacking situations because they don't want to compromise their servers but he told me that Macs are not immune to being hacked...if someone wants to get in, they will find a way. My question is, since MacScan didn't find a Keylogger on it, then how did I get hacked? If anyone can answer it would be greatly appreciated.

MacBook Pro with Retina display

Posted on Nov 27, 2013 8:44 AM

Reply
18 replies

Nov 27, 2013 12:47 PM in response to Kitty122868

Kitty122868,


I was away for awhile, sorry for the delay.

As Csound1 has suggested, change your passwords, and make them striong: upper and lower case, numerical, and include some symbols, 16+ characters. Do not use the same password(s) for multiple logins. Never share your logi password with anyone.


Also go to system preferences/sharing and turn off all sharing services and only use them when necessary especially any of the remote services.


Go to system preferences/security, general tab, and check the box "Require a password to unlock each System Preferences pane"


Keep others from having physical access to your machine. It is common for a "someone I know" scenario.

If it were to happen again, you can bring it to Apple, as they diagnose issues for free.


If it was "wiped and reinstalled it should be "clean" and changing your passwords to strong ones , as well as not allowing physical access as well as the afore mentioned steps, you should be OK.


Change all your important pswds, banking, shopping accts, etc...


All the Best

Dec 4, 2013 6:51 AM in response to Csound1

Csound and sanjampet..or anyone at this point..I got my laptop back from repair and after setting everything up..I got hacked again. Not only did he hack into my Facebook account again but now he set it up so a Guest User could sign into my laptop. I'm going to have to take responsibility for this because as I was checking the System Preferences settings as sanjampet suggested I discovered that my firewall wasn't on. So I'm assuming the last time it wasn't on either because I was under the assumption that Apple has it turned on by default when you purchase their computers. So at this point it appears that I'm going to have to take it to an Apple store. My question is, will they be able to trace an IP address for me to help me find out exactly who this jerk is? What do I ask them to do exactly? What CAN they do exactly?

Dec 4, 2013 7:47 AM in response to Kitty122868

Hi Kitty


I strongly doubt that you are being hacked, you can easily do a quick test. Use the machine without internet for a day, hacking would be difficult under those conditions.


Online (ie. Facebook) accounts becoming compromised is nothing to do with your Mac, the Guest user account is normal, it's present on all Macs when first setup. It can be disabled (users choice)


If you have a router (and I am sure that you do) then you are already protected by a firewall, adding a second doesn't do much.


You (and the Apple Store) can't trace the IP address, that is a job for the police.


Please describe exactly what is happening.

Dec 4, 2013 7:57 AM in response to Kitty122868

You can take it to Apple they may be able check the logs and possibly to a trace route, whois, Looup in network utilities.

This is beyond my knowledge, but most of these hacker types are pretty good at covering their tracks.


If they are able get an IP address, they may be able to find something. (If they will do that) I would think that local law enforcement would be your first step. Ask them what they think your options are (Ask Appple as well). I, fortunately have not had to deal with this, altough there are many who have, and I would think that this would be considered a cyber crime. I have always used my firewall, and never have any sharing preferences turned on. You will probably need to do the password changing proceedure again, and also check your important accounts for unusual behaviors.

STRONG passwords, make them alpha (upper/lower case), numeric, symbols, at this point change the format of your paswords as well (style that you create them, and make them nonsense.


I hope that you get this solved, good luck. Post back with your results.


Maybe Csound1 will have more info to offer

Dec 4, 2013 8:13 AM in response to sanjampet

Thank you both for your responses. And thank you again Csound1 for explaining the situation with the Guest Account. I think I'm becoming paranoid. As far as the FB account they're basically hacking in and posting..... let's just say VERY inappropriate things. They haven't threatened me in any way. It seems that whomever it is just hacked into FB and my email. THANK GOD that they haven't hacked into my bank account or any accounts that have my debit card info on it. They only seem to be doing mischievous things, nothing serious as of yet. And yes, I do have a router. I also changed my passwords as soon as I noticed that my FB account got compromised again. I do want to go to the police but I was under the impression that unless this person actually threatens me that they won't take my complaint seriously. I am VERY computer illiterate so I don't know how these things work.

Dec 4, 2013 8:21 AM in response to Kitty122868

You are correct that the Police will do little at this time, and you have taken the correct action by changing your password for Facebook. Change all other online passwords as well, make them strong and make them different from each other.


Leaving the Mac firewall on will not do much either way really. You can leave it on. Contact Facebook support, maybe they can help with the inappropriate posts.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

I believe I was hacked....

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.