Team Fortress 2

Team Fortress 2

496 ratings
A Trader's Guide to countering Phishers (OUTDATED)
By Neoprimal and 1 collaborators
Discussing how to avoid a friend request Phisher and what to look for when they add you.
   
Award
Favorite
Favorited
Unfavorite
Introduction
Hello, I'll be teaching you how to avoid a Phishing Bot's friend request and report them accordingly.
What are "Phisher Bots"?
"Phisher Bots" or "Phishing" in Real-Life Terms is the act of stealing another user's personal information for personal or financial gain. Phishing is illegal and as such will result in action from law enforcement as well as action from any Game related companies if so actions occur in the Virtual World.
Phishing is most commonly used in the Virtual World designed to steal other user items for their own financial gain in order to appear "rich" to the ordinary eye. This act as mentioned earlier is illegal and may result in legal action towards the bot's owner/creator. This has recently grown out of control so this guide has been put in place to prevent users falling for the extremely convincing tactics these bot owners come up with.
How does a Phisher Bot function?
Well Phisher bots are much like any other regular bot. They send automated messages in order for the user to "take the bait" and login to the suspected website, Once you login to said website the bot's owner will recieve all of your personal information like Steam Username and Password, Credit Card details and your own address. While the owner has all of this information he can choose to do whatever he wants with it; Whether it be steal all of your game items or just delete everything on your account it's up to him.
What sets Phisher Bots apart from regular users.
Okay, A few things set Phisher Bots apart from other Non-Bot users on the Steam Community.

1. Most if not all Phisher Bot accounts will be Level 0 or 1. Unless they are using a hijacked account with a higher level.

2. Most if not all Phisher Bot accounts won't feature a badge or any groups on their profile.

3. Every Phisher Bot sends links while online or occasionally while In-Game.

4. Phisher Bot accounts/Hijacked Accounts will almost always have their profile Private/Comments set to Friends Only or Private.

5. Alot of Phisher Bots will either have the Skull Icon for their Steam Profile Avatar or none at all.

Here's a look at a small amount of Phisher's i have on my Blocked list (Notice how most of them have the Skull icon as their Profile Avatar):
Common Phisher Bot phrases
Okay, So say you accepted the trade confident the user wasn't a Phisher Bot; You message him saying hi and he responds with an almost instant automated message which looks quite convincing, but then below it you see a link. Here's some really common Phishing Bot phrases i've encountered:

  • "Hi my friend want to add you but he cannot, i do not know why. can you add him?*
    [Phishing Link]
  • "Hi my friend encounter an error and want to trade with you, you add him instead?"
    [Phishing Link]
  • "Hi, I want pay full price on you item but item is on my bot account. add him to trade!"
    [Phishing Link]

NOTE: Most if not all Phisher Bots have extremely broken english.

Here's an example of one of the bots i've encountered:














If you encounter any of these kind of links refer to the post below in order to deal with them accordingly.
A great way to avoid Phisher Bots
Okay, So say you are getting tempted to click the link and you know full well it's a Phishing link designed to steal your items and get your account VAC/IP Banned, There are a few ways you can deal with these homeless nobodies:

Jessecar96's Steam Suite [jes.re]:
This handy little tool made by Jessecar adds several different protection instances to the Internet Browser version of the Steam Community. It's currently only available for the 'Opera', 'Google Chrome' and older versions of 'Mozilla Firefox'
SteamGuard
Having SteamGuard enabled will prevent phishers from gaining access to your account if you do happen to login to the suspected site as they will need to input another code sent to the email address registered with your steam account. If you are unsure on how to enable SteamGuard please refer to the guide below created by the amazing Jimo.
http://steamcommunity.com/sharedfiles/filedetails/?id=153396149

NOTE: SteamGuard disables your ability to Trade for 15 Days after initial Activation.
How to deal with Phisher Bots.
Okay, So you are confident the person that you recently spoke to was a Phisher and you want to report them to Valve so they can deal with them, There's 1 way i find you can achieve this.

Reporting via the "Report Violation" button
This is the fastest way i find you can report them, In order to do this please follow the below instructions:

1. Open the suspected Phisher Bot's Steam Profile (I'm using Robin's steam profile for reference, I'm NOT actually reporting him at all. <Please don't ban me Robin :C>)

2. Click the "More Options" Button next to the Bot's name:









3. Click the "Report Violation" button in the dropdown menu:





4. Check the "Suspected Hijacker or Phishing" bubble, Type in your message and click the "Submit Report" button.

Congratulations! You have successfully reported a Phishing Bot, But alas that probably won't do anything as these Bot owners will make new accounts for their bots to use to distribute their illegal links.
Conclusion and Closing Notes
Well, I hope you enjoyed my guide, As said earlier reporting bots will do almost nothing as bot owners will Hijack new users every day to do their dirty work.
NEVER click any links in steam chat even if it's a close friend unless you are absolutely sure it's a valid Steam Community Link.
Thanks again for taking a gander at my Guide, If you have any tips please feel free to add them below.

Credit:
Robin - For having a profile for me to template for my guide :D
Banana Bread - For giving me the idea to start this guide.

EDIT: 14/02/2016
I don't suggest clicking any links in the comment section of this guide, For some reaon i've been getting hundreds of comment notifications of phishers posting their malicious links in the comments of this guide, I'm trying my hardest to delete any i see but a few are bound to slip through. Please be careful out there :)

9/07/2014: Anti-Phisher Steam Group is up!
527 Comments
Neoprimal  [author] Apr 27, 2017 @ 2:29am 
To be honest, I've given up on this guide since i lost my ability to Trade. I'd probably update the guide if i updated my Phone Number so i could trade again but i can't be bothered to buy a new Phone and register it.
sievaxx Feb 14, 2016 @ 6:35am 
you could update it, but nothing much has changed in the art of phishing, other then what Valve have done.
Neoprimal  [author] Feb 13, 2016 @ 5:27pm 
@ Cvaxxbull (Anti-G.E.W.P)

Yeah... I should probably update it :O
sievaxx Feb 13, 2016 @ 3:34am 
old but still relevant. I like it.
Guts berserk Sep 10, 2015 @ 5:02pm 
+rep dis guilds the best
Neoprimal  [author] Apr 1, 2015 @ 6:13pm 
@Goop Sier 雌犬

Most likely they are. Did you try checking their profiles? If it's private or not set up then the chances of them being a Phisher are high.
Potion Seller Apr 1, 2015 @ 6:07pm 
So, I got this phishing bot friend invite a while ago by the name "[unassinged]" (minus the quotes) and I got a friend invite by someone of the same name, I'm wondering if they're a phishing bot. I tried talking to them but they aren't saying anything...
Almighty Sheldor Mar 25, 2015 @ 3:28pm 
The Most phisher Bots have an Gaben pic. now
Strange Child Feb 3, 2015 @ 2:06pm 
The phishing bots these days are shit. Why would they use the same question if everyone (atleast everyone) knows its fake.
Anyar Jan 31, 2015 @ 10:44pm 
Quote: "Hi my friend want to add you but he cannot, i do not know why. can you add him?*
[Phishing Link]".
I just realized how I almost got scammed/hijacked.
Once I received basically the exact same message from someone, and I was almost like "Sure ok" but then I realized (since I was and still is F2P) that I had literally nothing to trade but two trading cards that I wanted to keep. So I just ignored him. Later I blocked him, but it still was a close call.