Account compromised — private repos deleted, profile defaced, 2FA was already on #197630
Unanswered
bestt3217
asked this question in
Repositories
Replies: 1 comment
-
|
Really sorry this happened — here are answers to each of your questions:
Deploy keys — check every repository individually under Settings → Deploy keys, not just your account level
|
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
🏷️ Discussion Type
Question
Body
My account was compromised even though I had 2FA enabled. The attacker defaced my profile (changed display name, bio, README), deleted several private repositories, and created a bunch of fake repos.
Since 2FA was on, I think they got in via a personal access token rather than a password login. I found a token I'm investigating and I'm working through revoking tokens/keys/apps and checking my security log.
My questions for anyone who's been through this:
Appreciate any pointers. Thanks.
Beta Was this translation helpful? Give feedback.
All reactions