My Freepik account was hacked, 2M+ credits were stolen — unauthorized usage is STILL happening, and Freepik has stopped responding
I’m posting this because I genuinely need help understanding what is happening with my Freepik/Magnific account, and I want to know if anyone else has experienced this.
A few days ago, my account was compromised.
# What happened
* My account had **2FA enabled**.
* The attacker somehow accessed the account and **disabled 2FA**.
* Approximately **2 million AI credits/tokens were consumed without my authorization**, mainly through video generation.
* I immediately secured the account and used **“Log out of all devices.”**
* However, **video generation continued even after I logged out all devices**.
* I checked for API keys, MCP connections, automations, and other obvious integrations, but couldn't find anything that explained the activity.
* I immediately contacted Freepik/Magnific support and opened a security case.
* I completed their ownership/payment verification and provided everything they requested.
* Their support initially said they were investigating and later told me the case had been **escalated to a manager**.
# The situation is STILL ongoing
This is the part that concerns me the most.
**Even today, after securing the account and while Freepik is supposedly investigating, unauthorized activity appears to still be happening and additional credits/tokens are being consumed.**
I am deliberately **not using the account myself**, because I don't want my legitimate activity to be mixed with the attacker's activity while the investigation is open.
And now, **Freepik/Magnific is not providing any further response either.**
Their last meaningful response was that the case had been escalated to a manager. Since then, I have received no concrete investigation result, no explanation of how the unauthorized access occurred, no timeline for resolution, and no clear answer about how I can safely use my account.
# What I don't understand
If:
* 2FA was enabled,
* 2FA was disabled without my authorization,
* I logged out all devices,
* there is no visible API/MCP/automation explaining the activity,
* I reported the incident immediately,
* the case was escalated to their internal team,
**how can someone still be using the account and consuming credits?**
Could there be a persistent session/token, server-side job queue, OAuth authorization, hidden integration, or another authentication mechanism that isn't visible to the user?
I am especially interested in hearing from people who understand **session management, OAuth, authentication systems, or Freepik/Magnific's AI generation infrastructure**.
I'm not claiming at this point that Freepik itself was breached. I simply want to understand **how this could happen despite 2FA and logging out all devices**, and why the unauthorized usage appears to be continuing.
This is also causing a real business problem for me. I use Freepik professionally, but I'm afraid to use the account because I don't want legitimate usage to later be attributed to the unauthorized activity.
**Freepik/Magnific support case: 01714613**
If anyone has experienced a similar Freepik/Magnific account compromise, especially one where generation continued after logging out all devices, please share your experience.
And if anyone from Freepik/Magnific's security team sees this: **please investigate this urgently. I have already provided all the requested verification and have been waiting for a resolution while the unauthorized usage continues.**
I can provide screenshots and timestamps privately if useful.