This topic has been locked
Max Mar 26, 2023 @ 5:32pm
Valve lost my account in spectacular way
Here's my amazing communication with steam support: https://imgur.com/a/lCP9A7l

Long story short: my 10+ y.o. account got taken over despite all the security measures on (email, phone, guard app) and with 0 notifications when my password and email was being changed by an attacker.

The most amazing part is, however, my attempt to recover it through Valve's tech support. Grab some coffee and enjoy the long read -- with a bad ending unfortunately.

So children keep spending money on the skins which you will lose.
< >
Showing 1-15 of 223 comments
fluxtorrent Mar 26, 2023 @ 5:34pm 
Pebcak

but sure blame steam for your own inability to keep your credentials secure and then not providing the required information to recover.

Selfinflicted own and you want to advertise it, speaks volumes
Max Mar 26, 2023 @ 5:42pm 
Lol. I've kept everything secure. 2FA failed completely. And they are asking me for some obscure info from over 10 years ago from a company that doesn't even exist.

If you think Valve's security is tip top and this will never happen to you, I can only be jealous of your naivety.
fluxtorrent Mar 26, 2023 @ 5:44pm 
You literally admit you lost access to not only your gmail account but your steam account, you were phished so hard that Bill Gates felt it.

If you think this was at all anyones fault but your own you are so deep in denial that even the crocodiles cant reach you
Max Mar 26, 2023 @ 5:54pm 
>You literally admit you lost access to not only your gmail account but your steam account, you were phished so hard that Bill Gates felt it.

10 years ago, yes. Before any 2FA was introduced.
Max Mar 26, 2023 @ 5:57pm 
BTW didn't have any issues restoring the account through steam support in 2014, having WAY less info and credentials than I do now.
fluxtorrent Mar 26, 2023 @ 5:57pm 
Valve had 2fa via email and app at the time (2012 they introduced the app, email 2fa was much older), so did google.

You failed to keep your credentials secure and could not or would not provide the necessary information to recover the account. The fact that they info they need you no longer have is STILL on you, not them.

The fact this happens to you multiple times SHOULD tell you who the problem is, and its not the service. No one is hacking accounts. Gabens own password and login name are public knowledge but his account hasnt been breached BECAUSE the 2fa is reliable.

Last edited by fluxtorrent; Mar 26, 2023 @ 5:59pm
ShelLuser Mar 26, 2023 @ 6:12pm 
No lock is going to keep you safe if you give the keys away.

Account security is our (= the players) responsibility, so obviously Valve aren't going to do much if you managed to loose access to yours. This isn't about hacking or failed security, there's nothing wrong with Steam's 2FA. Any kind of 2FA will fail if you unknowingly give the code away to a 3rd party.

Assuming you can't access your account at all anymore then your only option is this:

https://steamcommunity.com/sharedfiles/filedetails/?id=1126288560

If you can't provide the proof they need then yah, that's also on you. 2FA comes with backup codes for example, with the urge to copy them and keep them safe in case of situations like these. It's also not up to Valve to remind you of keeping such things secured.
Max Mar 26, 2023 @ 6:14pm 
>The fact that they info they need you no longer have is STILL on you, not them.

That is an interesting assumption. I have tons of data, including credit card info, phone number, email, devices, and yet the only thing that can help me recover my account is some obscure payments info from a currently non existing payment service, which I am not even sure I used. As with systems like that ANYONE could've topped up my account and claim it as theirs.

You don't need to be convincing me that all of this is okay, Valve doesn't need you to defend them. I'm glad you're happy with everything.
Max Mar 26, 2023 @ 6:14pm 
> If you can't provide the proof they need then yah, that's also on you. 2FA comes with backup codes for example, with the urge to copy them and keep them safe in case of situations like these.

I have the recovery code. Where do I enter it? ;)
Max Mar 26, 2023 @ 6:18pm 
>No lock is going to keep you safe if you give the keys away.

Well, you assume I did give something away, and that's okay. Even if that's the case, my issue is that I got 0 notifications to my email, phone, or steam app when my credentials were being changed.

And the biggest issue is, well... Look at the list of things I have. I am very surprised everybody is defending a huge corporation and ♥♥♥♥♥♥♥♥ on me, while I have literally ALL the proof in the world. Or am I being unreasonable and only "Yandex payment" from 2012 is the only proof of my ownership, and not email, phone, devices, bank cards and statements, Id documents etc?
Max Mar 26, 2023 @ 6:37pm 
> Account security is our (= the players) responsibility

So you think companies that store your funds and personal information have 0 responsibility? Interesting point of view.

> This isn't about hacking or failed security, there's nothing wrong with Steam's 2FA. Any kind of 2FA will fail if you unknowingly give the code away to a 3rd party.

What makes you think I gave a code to a 3rd party? There were no 2FA requests at all on the day of the hijacking and long before. You keep assuming things. (Valve surely can't be wrong or have systems that don't work well!)
Originally posted by Max:
and only "Yandex payment" from 2012 is the only proof of my ownership
How do you know its from 2012, if you didnt know it was used, and the support didnt mention the date?

Anyway, if you have payment proof before that date, you should be able to prove more than they ask for.
you might want to educate yourself on how accounts can be hijacked...

you could of clicked on a link months ago and they have just been waiting
for the right time to strike...

on my old computer i was looking for drivers.. and clicked on links all over
the place... some seemed to work... but a few seemed odd...

its really simple to be in the zone and click on stuff and not realise what is
going on... and friends can even send you stuff unwittingly...

no big deal....

til months later when you find yourself in the situation your currently in....
Max Mar 26, 2023 @ 6:50pm 
> How do you know its from 2012, if you didnt know it was used, and the support didnt mention the date?

It has to be before 2014, as I have every receipt from that point on. It's explained in detail in my communication with support.

> ts really simple to be in the zone and click on stuff and not realise what is
going on... and friends can even send you stuff unwittingly...

no big deal....

I agree, many things can lead to account being hijacked. But the fact the I can't recover it with SO MUCH PROOF is amazing.
Originally posted by ragefifty50:
you might want to educate yourself on how accounts can be hijacked...

you could of clicked on a link months ago and they have just been waiting
for the right time to strike...

on my old computer i was looking for drivers.. and clicked on links all over
the place... some seemed to work... but a few seemed odd...

its really simple to be in the zone and click on stuff and not realise what is
going on... and friends can even send you stuff unwittingly...

no big deal....

til months later when you find yourself in the situation your currently in....
But its strange that he got no email about the email change. if this was the scenario.

So it must be something else like email being affected, or the email is still active on the account. Or the account was transfered to a new email by other means without a email change notification.
< >
Showing 1-15 of 223 comments
Per page: 1530 50

Date Posted: Mar 26, 2023 @ 5:32pm
Posts: 224