大咖福利影院

Menu
大咖福利影院
Search
Magazine
Search

I was badly hacked in the USA, losing a lot and still am

rraypo

This is just a 鈥渇or what it鈥檚 worth


On September 23rd, I was hacked, quite seriously.


I woke up that morning like always, made my coffee, checked my WhatsApp, and then my email. I had a large number of unidentifiable SPAM/SCAM appearing messaging, none with return information, all simply stating 鈥淵our time is running out. Looking in my SPAM folder, these were the only messages there as well. My Drafts folder had been reduced from 21 pieces waiting to send, to just 4. Two of these were the same, however the other two were quite threatening. They demanded immediate payment in Bitcoin to an offshore Caribbean account or, they 鈥渨ould make my life hell鈥. Normally, I would just blow these off as a scam, but they posted both my daily email password and a copy of my address book. My own Drafts were gone.


After pausing for a moment, I quickly went to my US bank accounts to change passwords鈥OO LATE. I had five bank accounts, in three different US banks cleaned out. Debit cards locked, credit cards maxed out, loans applied for, new credit accounts at stores the list goes on. I had also made purchases, GLOBALLY. Yes, from a truck load of toilet paper from Walmart in Miami, to truck covers in London, Bitcoin buy in South Africa, and gift cards all over the world bought on Amazon Store Credit.


I began calling, then leaving to go to the banks. They froze accounts, assets etc. New accounts were opened, all to be rehacked with hours. The banks, and most store accounts totally blocked me. I could not even open new accounts. All passwords were changed, my computers scanned, the virus was so deep in my cell phones operating systems, they had to be disposed of. My web cams and microphones were hacked, and they have ALL of my computer and cell phone files. To this day, two months later, I have no access to bank statements from two of the three banks. Neither Walmart or Amazon would stop merchandise sales or gift cards that had not been shipped or cashed in.

I went two months without ANY banking ability, I was not allowed to open new accounts for the first month, and during the second month, I could not use any online banking or debit cards.


Yes, of course I changed all of my emaill addresses and phone numbers within the first 24-hours.


The story is long, I lost everything. Of the three banks, Chase was by far the worst and least helpful. They will never cover any of my losses. Columbia bank and I are negotiating, so far, they have paid me $23 US dollars. Yes, you read that right, $23 US dollars. I use Chime online bank for one tenant. Chime locked me totally out, I have zero access to any banking records, nor will they open a new account for me. However, Chime claims in 12-16 weeks they might refund my lost money. Amazon is STILL SENDING ME BILLS for those uncashed gift cards, now being cashed. They would not do anything. Amazon would not stop purchase shipments stating I was fully liable since the purchases from their point of view were legitimate. Walmart did NOTHING, they refused to stop shipments of entire truck loads of merchandise, all around the world. Walmart billed my Chase Bank accounts, which were of course, closed.

After two months, I have US bills I cannot yet pay as I am still locked out of the accounts. Yes, I called the three US Credit Reporting agencies. That was a joke in itself. My US credit score was at 840. Today I鈥檓 at 720 and falling


Final take-aways:


I will never see any of my stolen money. This is a federal crime in the USA, so you file a report with the FBI, not the police. The FBI offered to accept the report, but said it would never ne investigated. Insurance would not cover it as there were so many multiple thefts.


NEVER keep money in any checking account, anywhere. Checking account are extremely vulnerable to hacking. Keep your money in a savings account, transferring only when needed. Honestly, keeping your money in your own pillow is far safer than in a bank. (The bank fraud departments all told me about the lack of checking account safety right off)


Credit cards are far, far, safer than any bank account, anywhere. They were quick to work with me. Capital One was fast. I even had a new card in two days.


Do not leave credit or debit card information on eBay, Amazon, ETSY, Ali Express, Shein, Sam鈥檚 Club, etc. You are simply giving your money to the hackers.


Change all of your passwords now, right now. No bank accounts, credit cards, store accounts, etc., should ever have the same passwords.


If you can remember any of your passwords, they are far too simple. They need to long and complex to prevent automated password AI searches.


The computer shop said I should have paid the ransom. The cell phone experts said you should always do a factory reset, especially when buying any new phones. They said any new cell phone can be hacked before you buy it.


In the end, the experts believe I was hacked when using these new Two-Step Verifications. I have been told those six-digit security codes sent to us are loaded with Trojan horses and other viruses.


We are not safe, so be proactive and start right now. They did make my life Hell.

See also

Living in S茫o Paulo: the expat guideUK expats living in BrasilPirarcicaba (Sao Paulo) I think I spelt that correctlyOpen a college in Sao PauloAny word about correios problems in Sao Paulo?Renting an apartment- newcomer in BrazilTranslator
abthree

11/17/25 @rraypo.聽 I'm so sorry that this happened to you.聽 It's outrageous -- but not so surprising at the moment -- the the FBI has no intention of investigating your report.聽 I hope that it works out better for you than it appears right now.聽 It sounds like you've been doing everything right, which makes the response that much more disappointing.聽 聽Thanks for updating us, and providing the good advice.聽 All the best, as always.


I have one question, if you don't mind:聽 what security software, if any, were you using on your computers and phones?


And I would add one more suggestion for anyone moving permanently to Brazil or anywhere else abroad, and who doesn't expect to need any new credit accounts in his/her country of origin:聽 freeze your credit reports.聽 This doesn't affect your current accounts, but it should keep anyone from opening any new bank, credit, or loan accounts in your name, even with your identifying information, or at the very least make it more difficult.聽 Keep the unfreeze passwords in a safe place, because the credit agencies don't keep them on file.聽 I did it, and it helps me sleep a little easier at night.

NewBrazil

Sorry to hear this nightmare came true. Just another update if you didn鈥檛 know over 400,000 social security numbers were hacked. I used a service that found 2 people were using my number. So I called Social Security and had them put a block on my social security number also did a FBI REPORT. This means no one can use it to open a account. Question how did you recover what services did you use to help.

Pablo888

Change all of your passwords now, right now. No bank accounts, credit cards, store accounts, etc., should ever have the same passwords.

If you can remember any of your passwords, they are far too simple. They need to long and complex to prevent automated password AI searches.

- @rraypo


Dec 8, 2025

@rraypo, sorry to hear that you were hacked.聽 This is becoming more and more frequent these days.


Beyond passwords, it has become imperative to use one or more of the following:

  1. 2 Factor authentication - either through authenticator or messaging or push notification
  2. Use long, unique, multiple character and signs combination.聽 Long is a must - as long as you are allowed to do.
  3. Use hardware biometrics - touch sensor, hardware keys + password, etc....
  4. Use a password manager - and secure the hell out of this.聽 2Factor authenticator, biometrics + password is the minimum requirement.
  5. Finally, use a trusted VPN provider


On the social engineering side,

  1. please do not send any password or important info via SMS or What's App.聽 Those should be communicated verbally.
  2. You can use private bin () which is a private encrypted ephemeral message that will disappear after only one read.聽 Do not copy the information in the private bin or you will forfeit the goal of the private bin.
  3. When talking to anyone on the phone, please do not trust just the voice.聽 Have family password that you will need to change yearly - to make sure that you are not talking to AI.


Remember - to attempt to thwart hackers, you should have information that they do not have - and you need to take the effort to remember those as they are your protections.


With AI, it is easy to train agents who will think like most people do and then it is just a matter of asking the agent for the information.聽 You need to make it hard for agents to make the right inference.


Hope that this post helps to reduce or prevent attacks on the members of the site.

Fred

A tip.

A lot of internet sites ask for your date of birth.聽 NEVER give it.

I lie by one day - a typo should a problem arise - but an advantage if a hacker gets hold of your details.


As for card details on Internet sites - I used to keep one account for that. The bank was an online version of a big bank, but it has a virtual DEBIT card. I left it empty until I wanted to buy something,聽 then put enough cash on there to make the purchase.聽 That can get hacked all day long but the crims will get nothing.


As for the businesses that ignored your information- the purchases can't be considered legitimate once you've informed them. However,聽 they know they can bog you down in litigation for years, so they don't care.

Fred

A site just asked for my number. I gave them 12345

My date of birth got the usual lie

My address was fake, as was my full name.


That was just marketing crap, but a hacked site would expose my details so they can get stuffed. Same goes for 'download our app' and 'join our member savings' rubbish in shops.

If it isn't on Google Playstore it doesn't get downloaded, and stuff that I don't know goes onto my spare phone. That second phone has no sensitive data, and only has made-up聽 email accounts that I never check.