So, my Discord account of over a decade was hacked yesterday.
The account has been suspended and can't do any damage any more, but not after hours of my reporting the hack. Just in case the hacker can get to you via other hacked accounts, here's their MO:
They will greet you via PM (this will be someone you had friended in the past or at least talked to) if you've got a Nitro subscription - probably with "heyhey".
Then they will ask you to partner with you in a game because they need help with a quest. I actually did ask them why the game is not on Steam because this seemed fishy to me - but I thought I knew this person! So I did as they asked and went to the page soulsthief dot com. No warning from my browser, and the site looks professional and legit. I downloaded the "game", and my antivirus did not wig out until I actually started the exe.
Now, I didn't have 2FA activated for my account - it's so old, it just slipped my mind. That is on me.
Within seconds I was locked out of my account, and the hacker enabled 2FA for it so I couldn't just go and change the password.
So I immediately sent a report to Discord support - but...nothing happened. Nothing. Only after the hacker bought a Nitro gift, my account was finally suspended. But not before hours had passed and the hacker already tried to impersonate me to get to several of my friends! One almost lost her account too but her active 2FA saved her.
So if you are a Discord Nitro user, please beware of any of your friends and contacts asking you to install a game that is not on Steam, Epic, or any other reputable platform! And please activate 2FA.
Support is a complete shitshow and won't do shit if you get hacked.
You might also want to think really well if you wanna give your banking data to a company that won't protect your information in case something happens.