Email 2FA or authenticator app 2FA?
i think that your cookie got stolen by visiting a suspicious link. changing the password should change it
or just go to your browser settings and delete all current cookies, as it could have stolen other cookies.
Delete Cookies
Chrome:
Browser Settings > Privacy and Security > Clear Browsing Data > Click Clear Data
Change Password
Roblox Settings > Security > Change Password
How to prevent something like this in the future?
Donβt visit any unknown links, or download something suspicious.
Put URLS and Downloads into VirusTotal before actually visiting/downloading them.
before downloading an extension, check the reviews to make sure that its legitmate. If you see too many 5 star reviews, it may indicate that theyβre bots.
Make sure you have a PIN on Roblox enabled. So the hacker wonβt be able to change anything until they know the PIN.
Have 2FA Enabled. The Hacker wonβt be able to actually login until they know the code from the email.
I Recommend not putting your phone number on your account. People could SIM Swap.
Change your Password every Month, 6 Months or every Year. Using a Password Manager should help.
This is my currrent Security Setup/Things i do before actually doing them. Hopefully this helps @kernelvox
Auth app 2FA, Isnβt it prefered?
Thatβs kindof how cookie logging works, it bypasses 2FA. Cookies are what allow you to stay on your account without logging in again, but if someone else gets the cookie then they are in your account.
that sucks, i use restore old server list to track down the opps but whatever, everything like searchblox ends up like this anyway
if its really causing this thats unfortunate
clear your cookies and click this in settings
Iβve logged out the suspicous accounts, And iβve found the username of the hacker.
report β β β β β β β β β β β β β β β β β β β β β β β β β β β β β
Having 2fa does nothing, Cookies bypass 2fa, When you log in, it gives you a cookie to remember you so you donβt have to log in everytime you visit roblox, When someone uses your cookie, it appears as if its the same session.
Didnβt they patch Cookie logging?
Well, they really just canβt, They can detect your location however this can be easily spoofed, and they dont do this as for mobile devices, they can move around alot therefor making it so they cant patch it