Th3_Alg0n 28. maj 2021 kl. 11:14
[removed] discord steam scammer
I got a message from a Discord user named [removed] who's telling me to log out of my account. I already did one of his instructions but then got a little paranoid. I gave him a screenshot of my purchase history but it doesn't show any personal info or passwords or what not. I found out he was a scammer and I don't know if my account is at risk. What should I do?
Sidst redigeret af Monokuma; 28. maj 2021 kl. 12:18
< >
Viser 1-11 af 11 kommentarer
Wolf Knight 28. maj 2021 kl. 11:17 
report the discord account to discord
if you feel your account may be compromised, do the following.

Steps to take NOW:
1. Scan for malware https://www.malwarebytes.com/
2. Deauthorize all other devices https://store.steampowered.com/twofactor/manage
3. Change passwords from a clean computer
4. Generate new backup codes for your Mobile App https://store.steampowered.com/twofactor/manage
5. Revoke the API key https://steamcommunity.com/dev/apikey (there should be nothing in the APIKEY)

steam will never contact you thru discord
Mad Scientist 28. maj 2021 kl. 11:23 
OP:

-Stop using skin / trade / gambling / tournament sites aka stop giving sites your steam login and stop allowing API Keys to be used on your account.
-Remove such scam sites from your username
-Do the steps below, in the exact order:

Oprindeligt skrevet af Wolf Knight:
report the discord account to discord
if you feel your account may be compromised, do the following.

Steps to take NOW:
1. Scan for malware https://www.malwarebytes.com/
2. Deauthorize all other devices https://store.steampowered.com/twofactor/manage
3. Change passwords from a clean computer
4. Generate new backup codes for your Mobile App https://store.steampowered.com/twofactor/manage
5. Revoke the API key https://steamcommunity.com/dev/apikey (there should be nothing in the APIKEY)

steam will never contact you thru discord
T9 28. maj 2021 kl. 11:25 
trust no 1

Valve would communicate with you via their own application, right? It's good to be a bit paranoid
Sidst redigeret af T9; 28. maj 2021 kl. 11:26
Th3_Alg0n 28. maj 2021 kl. 11:28 
Oprindeligt skrevet af t9:
trust no 1

Valve would communicate with you via their own application, right? It's good to be a bit paranoid
Thanks for that. Glad I caught it.
Th3_Alg0n 28. maj 2021 kl. 11:38 
Oprindeligt skrevet af Wolf Knight:
report the discord account to discord
if you feel your account may be compromised, do the following.

Steps to take NOW:
1. Scan for malware https://www.malwarebytes.com/
2. Deauthorize all other devices https://store.steampowered.com/twofactor/manage
3. Change passwords from a clean computer
4. Generate new backup codes for your Mobile App https://store.steampowered.com/twofactor/manage
5. Revoke the API key https://steamcommunity.com/dev/apikey (there should be nothing in the APIKEY)

steam will never contact you thru discord

What is an API key and why am I revoking it? (Never seen it before)
Wolf Knight 28. maj 2021 kl. 11:47 
Oprindeligt skrevet af Th3_Alg0n:
Oprindeligt skrevet af Wolf Knight:
report the discord account to discord
if you feel your account may be compromised, do the following.

Steps to take NOW:
1. Scan for malware https://www.malwarebytes.com/
2. Deauthorize all other devices https://store.steampowered.com/twofactor/manage
3. Change passwords from a clean computer
4. Generate new backup codes for your Mobile App https://store.steampowered.com/twofactor/manage
5. Revoke the API key https://steamcommunity.com/dev/apikey (there should be nothing in the APIKEY)

steam will never contact you thru discord

What is an API key and why am I revoking it? (Never seen it before)
if you dont know what the APIKEY is or does, your account should not have one. the scammers use it to monitor your account and have a bot waiting for your account to trade. the bot will then cancel the trade, copy the account you wanted the items to go to, and recreate the trade sending your items to the scammers holding account. all this happens in less time then it takes for you to look away from your screen and accept the trade on your phone.
Th3_Alg0n 28. maj 2021 kl. 11:53 
Oprindeligt skrevet af Wolf Knight:
Oprindeligt skrevet af Th3_Alg0n:

What is an API key and why am I revoking it? (Never seen it before)
if you dont know what the APIKEY is or does, your account should not have one. the scammers use it to monitor your account and have a bot waiting for your account to trade. the bot will then cancel the trade, copy the account you wanted the items to go to, and recreate the trade sending your items to the scammers holding account. all this happens in less time then it takes for you to look away from your screen and accept the trade on your phone.

I clicked the link you sent to erase the API key thing but all it did was ask me to register. Does that mean I'm safe in that section?
Wolf Knight 28. maj 2021 kl. 11:54 
Oprindeligt skrevet af Th3_Alg0n:
Oprindeligt skrevet af Wolf Knight:
if you dont know what the APIKEY is or does, your account should not have one. the scammers use it to monitor your account and have a bot waiting for your account to trade. the bot will then cancel the trade, copy the account you wanted the items to go to, and recreate the trade sending your items to the scammers holding account. all this happens in less time then it takes for you to look away from your screen and accept the trade on your phone.

I clicked the link you sent to erase the API key thing but all it did was ask me to register. Does that mean I'm safe in that section?
yep
Fake 28. maj 2021 kl. 13:56 
Oprindeligt skrevet af t9:
trust no 1
Who is No. 1 and why should I trust him?
JVC 28. maj 2021 kl. 13:58 
Oprindeligt skrevet af Fake:
Oprindeligt skrevet af t9:
trust no 1
Who is No. 1 and why should I trust him?
He said "trust no one"
Oprindeligt skrevet af Th3_Alg0n:
I got a message from a Discord user named [removed] who's telling me to log out of my account. I already did one of his instructions but then got a little paranoid. I gave him a screenshot of my purchase history but it doesn't show any personal info or passwords ...

The screenshot of your purchase history shows your Steam account login name. The scammer uses that to make a password reset request. Then the scammer tells you that he sent a code to your phone and you need to give it to him to prove that this is really your account.

That text message from Steam probably tells you that the code is to reset your password (I have never reset my password so I haven't seen that particular text from Steam, but, when I got a text with a code to move my Steam Mobile authenticator to a new device, the text told me that it was for that purpose), but apparently there are many people who give that code to the scammer despite that warning.

The reason why the scammer told you to log out of your account is because once they change your password, you will not have access to your Steam account. They will then try to extort money from you. They would probably tell you to buy some dollar amount of Steam Wallet codes and to give them the codes to prove [insert ridiculous ♥♥♥♥♥♥♥♥ story here], and claim that then you will get access to your Steam account back and you will get the money back too. Of course you won't get either. If you do give them money, they will continue to try to extort more money out of you for as long as you let them. The only way you would get your account back is if you recover it with the help of Steam support.

So it is good that you stopped doing what the scammers told you to do.
< >
Viser 1-11 af 11 kommentarer
Per side: 1530 50

Dato opslået: 28. maj 2021 kl. 11:14
Indlæg: 11