此主题已被锁定
Cylinder 2024 年 11 月 8 日 下午 1:15
discord + steam account unknown activity even with 2FA
I have never clicked on unknow links.
I ran Malwarebytes and it detected nothing.
I have 2 factors authentification on both my discord and steam account.
I have checked my mail on haveIbeenpwned but nothing popped up.

But still, I received notifications on my phones that I succesfully sold items on the steam market. It sold about 100 of these and then bought some dota 2 items overpriced. All of that without me having to confirm on my phone except for some tf2 cosmetics.

I deauthorized everything and revoked my API.

A few days later, someone sends "50$ steam gift cards" to like 7 of my discord friends. Discord detected that pretty quickly so I logged back in and deauthorized everything again and deleted the messages.

I don't how this happens the o9nly thing that I have suspicions is :

1) I have downloaded some riskier files but again, malwarebytes detected nothing
2) some days after my steam account got hacked, google detected some 'suspicious activities' but google says nothing about this activity so I just assumed it was my computer and I changed password the discord hack happened after that
3) I have lended my steam account to an irl friend (I know it's not him) for some steam family so maybe it's on his computer ? But he didn't have any problems
4) again a few days after the steam hack someone commented on my steam profile and said he 'nedeed to talk to me' so I put my profile on private and then sent him a friend request (idk I thought it was funny). He didn't accept it nothing happened

I don't know if these could be linked and I just hope it's not my mail
最后由 Cylinder 编辑于; 2024 年 11 月 8 日 下午 1:21
< >
正在显示第 1 - 5 条,共 5 条留言
magicISO Sweden 2024 年 11 月 8 日 下午 1:19 
Accounts are phished not hacked.

You gave away all your account details.

The account name, the password and the KEY to the door, the Steam Guard Mobile code giving them access to the account.

How? by either logging into a known scam site or sites, tailored malware on your PC, the vote for my team scam, you have a pending ban scam on Discord, free knife click the link etc.

How does Steam (a program) know it is not you when all the account details are correct? It doesn't, therefore any action taken on your account is seen as you doing said actions.

The alternative is not plausible:

1) Someone would have to "GUESS" your account name from "millions of possible combinations".

2) Next they would have to "GUESS" your password from "millions of possible combinations" and then match it to your account name with "millions of possible combinations".

3) And finally they would have to "GUESS" the Steam Guard Mobile code "which changes every 30 seconds" to match both your account name and password to then have access your account.
Cylinder 2024 年 11 月 8 日 下午 1:45 
引用自 magicISO Sweden
Accounts are phished not hacked.

You gave away all your account details.

The account name, the password and the KEY to the door, the Steam Guard Mobile code giving them access to the account.

How? by either logging into a known scam site or sites, tailored malware on your PC, the vote for my team scam, you have a pending ban scam on Discord, free knife click the link etc.

How does Steam (a program) know it is not you when all the account details are correct? It doesn't, therefore any action taken on your account is seen as you doing said actions.

The alternative is not plausible:

1) Someone would have to "GUESS" your account name from "millions of possible combinations".

2) Next they would have to "GUESS" your password from "millions of possible combinations" and then match it to your account name with "millions of possible combinations".

3) And finally they would have to "GUESS" the Steam Guard Mobile code "which changes every 30 seconds" to match both your account name and password to then have access your account.
Is there any way to check the potentially dangerous links that you clicked in the past ? Because I know how dangerous clicking an unknown link is and I just don't remember doing it.
alphahunter234 2024 年 11 月 8 日 下午 4:52 
change your password
Maria 2024 年 11 月 8 日 下午 5:04 
引用自 Cylinder
Is there any way to check the potentially dangerous links that you clicked in the past ? Because I know how dangerous clicking an unknown link is and I just don't remember doing it.
easiest to check is browser history.. other than that idk.

It is also possible that there is keylogger in your friend's PC.

That stranger commenting on your profile is probably the same hijacker trying to rope you back with some 'I accidentally reported you' bullsht.

Make sure to do ALL the steps provided here (you have probably done some or all of it but I just want to confirm it):

1. Scan for malware.
https://www.malwarebytes.com/

2. Check that the email and phone number on the Steam account are still yours.

3. Deauthorize all other devices.
https://store.steampowered.com/twofactor/manage

4. Change passwords from a clean computer.

5. Generate new backup codes for your Mobile App. https://store.steampowered.com/twofactor/manage

6. Revoke the API key (there should be no key).
https://steamcommunity.com/dev/apikey
Connie 2024 年 11 月 8 日 下午 6:58 
If you need help with Account Security or Recovery, please contact Steam Support.
< >
正在显示第 1 - 5 条,共 5 条留言
每页显示数: 1530 50

发帖日期: 2024 年 11 月 8 日 下午 1:15
回复数: 5