Your Facebook is messaging people you have not spoken to in years. Your Instagram is pushing a giveaway you have never heard of. Your name is on all of it, your photograph is next to it, and you wrote none of it.
Almost everyone reaches for the same fix first, and almost everyone is surprised when it does not work. The password gets changed and the posts keep coming. That is not bad luck. The password was never what was taken.
What a website trusts instead of your password
You type a password once. After that, the site stops asking, and it stops asking because it left something on your computer that says this person already proved who they are. It is called a session cookie, and it is the reason you are not challenged every time you open a page.
Think of it as a wristband at a venue. The door checked your ticket once and gave you the band. Nobody checks your ticket again, because the band is the proof now.
The software behind this goes looking for the wristband. It is called an infostealer, and it almost always arrives inside something somebody downloaded deliberately: a game mod, a cracked app, a free version of something that normally costs money. It takes what the browser has saved, those wristbands included, in the time it takes to read this paragraph.
Why changing the password achieves nothing
Someone holding a valid session cookie is not asked for a password, because as far as the site is concerned they already answered that question.
Changing it afterwards changes the answer to a question nobody is asking them. That is the whole explanation for the thing that confuses people most about this attack.
The step that works is signing out of all sessions, which most platforms keep in their security settings. That is the instruction that tears up every wristband, including the stolen one.
Why it spreads to the people who trust you
The attacker is not using your account for your photographs. They are using your reputation.
A link from a stranger gets ignored. The same link from an account people have known for years, with a familiar face beside it, lands in a group chat where nobody has any reason to be careful. Facebook, Instagram, Discord and Steam get hit hardest for exactly that reason: they run on the assumption that a familiar name is a safe one.
So the account is not really the target. Your standing with everyone who knows you is the target, and that is the part that cannot be reset from a settings page.
Do it in the right order, and from a different device
Sign out of all sessions first, then change passwords, then turn on the second sign-in step. Do all of it from a phone or another computer.
That last point is not a detail. If the machine is still infected, a password typed on it is collected on the way out, and a fresh one is gone as quickly as the old one. The computer gets dealt with before it is trusted with anything again.
The old way is changing the password and hoping it stops. The new way is tearing up every wristband first, from a device the attacker is not standing inside.
Here is a five-minute move: open the security settings on Facebook or Instagram, find the list of devices and sessions, and sign out of all of them, even if nothing looks wrong. Read that list before you close it.
Borked PC looks after home and family computers as well as business ones. Same people, same standards, scaled to a house.
📞 What we do for homes and families, or call us now on (610) 599-6195.
