@0xabad1dea@infosec.exchange
‘M sure others have linked / suggested ideas. I’d add
Work from a step away (an uninfected computer and accounts).
Maintain lists. Username and pwd, and any notes of things done on the impacted accounts which help reestablish owner is proper owner.
Search for stolen account support on the accounts.
Don’t delete accounts, apps, or wipe the primary devices for these things. They may be essential in recovering control.
Brainstorm a passphrase family for recovery. Can be as simple as Word2Word-ab, where ab are letters or a short word that come to mind for that site. This is so no two sites or accounts share a pwd, while keeping recovery focused on getting back in.
Alt: (Better but more hassle/work , install bitwarden on cousin’s phone and the recovery laptop, and do unique passphrases for every account).
Start on the critical accounts: anything with financial risk, an email used for password resets. Check/Delete any settings that forward email, make sure contact info is correct and in your control.
As for financial: Definitely check password and try to recover control, up to and including meatspace moves like driving to the bank or calling them. At first hint of corruption/loss of access, do these tasks NOYD!!!!
… at some point, the smell of ‘EVERYTHING’ may fade to ‘oh, it’s just these few things’. Calm a bit, but still march thru changing all the passwords, checking contact info.
I’m sure there’s more. Been thru it and it’s a fucking mess.