Toate discuțiile > Forumuri Steam > Steam Discussions > Detaliile subiectului
Steam Guard hacked
Hi, so today I woke up to a 30+ emails saying I sold an item which I didn’t put on market.
When I went into my Steam app on my phone to see what was going on there was new device from Hong Kong authorised on my Steam Guard. There ware no email that says there was new login or that there was new device authorised. There ware no 2FA code that I received to my phone. There was really nothing saying anything.
Did someone else had similar thing happened to him/her?

Also I’m waiting 24h to pass to see if there was new login.

UPDATE
Today 13. 9. 2024, they access my discord. Not directly to account but I believe they had my token and they send everyone same message with link.
I've also got email from DISCORD that some website was "hacked"....
- SkinsMonkey
- farm skin
- hell case
one of does or all of them....
Editat ultima dată de Tali; 13 sept. 2024 la 5:11
Postat inițial de Dr.Shadowds 🐉:
Postat inițial de ljubavi:
Postat inițial de Dr.Shadowds 🐉:
Correct as LONG as you DON'T provide the 2FA people will not be able to BRUTE force login to your account so easily compare to NOT having 2FA enable.

Removing login devices does not require code, you can use revoke simple as that when LOGIN.

Also I already explain how they got into your account, either you provided it to them, or you approve it that it, not hard to figure out...

Is there some sort of token? Like discord has token, if they get it they can access your account only with that token. Does steam using something similar?
If they have access to your device such as virus / backdoor they can collect your token using that as away to try access your account, now if this was for browser token that more doable than client token, but depends how said client works. That why security matters a lot when comes to downloading stuff from others, or random sites, and using a good anti virus is 9/10 will save you from an attack then without it.

Anyways just note for them to take token from your device they need access to your device to begin with such as virus attack using "hey try my demo.exe" or "♥♥♥♥♥♥♥♥♥♥ download and run this .exe" basically.
< >
Se afișează 1-15 din 61 comentarii
Pscht 11 sept. 2024 la 1:49 
Always hilarious when someone who actively advertises a phishing site in his name complains about getting phished.

Scan for malware https://www.malwarebytes.com/
Deauthorize all other devices https://store.steampowered.com/twofactor/manage
Change passwords from a clean computer
Generate new backup codes https://store.steampowered.com/twofactor/manage
Revoke the API key https://steamcommunity.com/dev/apikey
Stop using shady third party trade sites or clicking suspicious links.

And maybe leave that group with the monkey logo.
Hop on over to this site: https://steamcommunity.com/dev/apikey

Most likely you'll find an API key there, remove it. In addition...

https://store.steampowered.com/twofactor/manage

^ De-authorize all other devices, and also consider chaning your password.


SteamGuard didn't get hacked, some time ago you accessed a scam site and while thinking that you logged onto Steam you actually gave the attacker your full account details. Which they then immediately used to log into your account and plant that API key, thus giving them near to full control over your account.

(edit)

So, I just checked that website in your username.... it allows you to log onto their site using a Steam account and that is exactly the cause of your problems. Not every website is legit, and many will even swap out a legit logon option for a fake one, thus making it impossible to fully pinpoint where things went wrong.

Fact of the matter is... if you use your Steam account outside of Steam, then you're taking big risks.
Editat ultima dată de ShelLuser; 11 sept. 2024 la 3:45
Tali 11 sept. 2024 la 2:09 
Postat inițial de Pscht:
Always hilarious when someone who actively advertises a phishing site in his name complains about getting phished.

Scan for malware https://www.malwarebytes.com/
Deauthorize all other devices https://store.steampowered.com/twofactor/manage
Change passwords from a clean computer
Generate new backup codes https://store.steampowered.com/twofactor/manage
Revoke the API key https://steamcommunity.com/dev/apikey
Stop using shady third party trade sites or clicking suspicious links.

And maybe leave that group with the monkey logo.

If you are referring to a bloody.com I’m using the website for quite some time, I’ve also had trades with them and received everything I got there.
Im not getting the part where they authorised new device without 2FA confirmation. And did very little damage.
Tali 11 sept. 2024 la 2:28 
Postat inițial de ShelLuser:
Hop on over to this site: https://steamcommunity.com/dev/apikey

Most likely you'll find an API key there, remove it. In addition...

https://store.steampowered.com/twofactor/manage

^ De-authorize all other devices, and also consider chaning your password.


SteamGuard didn't get hacked, some time ago you accessed a scam site and while thinking that you logged onto Steam you actually gave the attacker your full account details. Which they then immediately used to log into your account and plant that API key, thus giving them near to full control over your account.

(edit)

So, I just checked that website in your username.... it allows you to log onto their site using a Steam account and that is exactly the cause of your problems. Not every website is legit, and many will even swap out a legit logon option for a fake one, thus making it impossible to fully pinpoint where things went wrong.

Fact of the matter is... if you use your Steam account outside of Steam, then you're taking risk.

There is no API key there.
I’ve also deauthorised all the devices and changed my password.
But my question is if they had access to my account why wouldn’t they change password, email,… and completely locked me out of my acc, why would they sell worthless skins, and leave does which are worth something?
Editat ultima dată de Tali; 11 sept. 2024 la 2:30
Postat inițial de ljubavi:
There is no API key there.
Then you need to check the state of your computer and other of its facilities. Maybe your e-mail got comrpomised, maybe a roommate is messing with you, maybe you left a login session open in an internet cafe?

One way or the other... somewhere along the line your account got compromised. You might want to prioritize finding the real cause here because... this could easily escalate beyond Steam.
Here how phishing works.
1. Scammer contact victim via DM/email, or victim watch scammer videos, or saw ad scam. Maybe gamble, or trading promotion by scammer in search results victim looking for something.

2. victim visit scam site with no idea it was a scam site.

3. Victim click login entering the login information, AND entering in code which is sent to scammer device they login, and have your login token, or victim scan QR code then click approved for login that on scammer device to getting access.

So now you figure out most common day to day problem, how do you solve it, simple tell victim stop smashing buttons, and use brain pay attention then stop logging into scam sites.


Yes the moment scammers get on your account, they run to spam your friends in their DM with links, with message to trick them to fall for it, or try to sell every time you have in your inventory, or trade it.

Now you wonder why isn't there a 2nd code for login, well when have you ever had to enter a 2nd code to login, answer is you never did, you put username, password, plus code that it, there no 2nd code, scammers got in because you handed the code for them to use hence login process.
Postat inițial de ljubavi:
Postat inițial de Pscht:
Always hilarious when someone who actively advertises a phishing site in his name complains about getting phished.

Scan for malware https://www.malwarebytes.com/
Deauthorize all other devices https://store.steampowered.com/twofactor/manage
Change passwords from a clean computer
Generate new backup codes https://store.steampowered.com/twofactor/manage
Revoke the API key https://steamcommunity.com/dev/apikey
Stop using shady third party trade sites or clicking suspicious links.

And maybe leave that group with the monkey logo.

If you are referring to a bloody.com I’m using the website for quite some time, I’ve also had trades with them and received everything I got there.
Im not getting the part where they authorised new device without 2FA confirmation. And did very little damage.
All 3rd party websites are suspect. Sometimes because they're ran by scammers, other times because they get targeted by phishers.

Plus scammers aren't stupid enough to use every account that logs in. They need to appear legit enough so people call them "trusted", you know.

You need to read up on phishing. Then you'll understand how you accidentally confirmed their login device.
Tali 11 sept. 2024 la 4:26 
Postat inițial de ShelLuser:
Postat inițial de ljubavi:
There is no API key there.
Then you need to check the state of your computer and other of its facilities. Maybe your e-mail got comrpomised, maybe a roommate is messing with you, maybe you left a login session open in an internet cafe?

One way or the other... somewhere along the line your account got compromised. You might want to prioritize finding the real cause here because... this could easily escalate beyond Steam.


I’ve checked the email, and its not been compromised. Also it is really hard to get into google email, even i cant login from every computer because it doesn let me, i also have 2FA on my google email.

I don’t use internet cafe and also the are none in my country.
Tali 11 sept. 2024 la 4:29 
Postat inițial de Dr.Shadowds 🐉:
Here how phishing works.
1. Scammer contact victim via DM/email, or victim watch scammer videos, or saw ad scam. Maybe gamble, or trading promotion by scammer in search results victim looking for something.

2. victim visit scam site with no idea it was a scam site.

3. Victim click login entering the login information, AND entering in code which is sent to scammer device they login, and have your login token, or victim scan QR code then click approved for login that on scammer device to getting access.

So now you figure out most common day to day problem, how do you solve it, simple tell victim stop smashing buttons, and use brain pay attention then stop logging into scam sites.


Yes the moment scammers get on your account, they run to spam your friends in their DM with links, with message to trick them to fall for it, or try to sell every time you have in your inventory, or trade it.

Now you wonder why isn't there a 2nd code for login, well when have you ever had to enter a 2nd code to login, answer is you never did, you put username, password, plus code that it, there no 2nd code, scammers got in because you handed the code for them to use hence login process.

No contact via email as I really dont receive lot of emails.
There are no messages to my friends also I’ve never clicked on any when i got them from any other friend.

Every time u login into your Steam acc and have 2FA enabled u have to accept it on Steam Guard. Also if you want to change anything on steam (security stuff) u have confirm it with 2 security codes (steam guard/phone and email)
Tali 11 sept. 2024 la 4:31 
Postat inițial de Thiesen:
https://en.wikipedia.org/wiki/Phishing

https://en.wikipedia.org/wiki/Phishing

https://en.wikipedia.org/wiki/Phishing

https://en.wikipedia.org/wiki/Phishing

https://en.wikipedia.org/wiki/Phishing

https://en.wikipedia.org/wiki/Phishing

PLEASE READ C A R E F U L L Y!!!

One more time for good measure:

https://en.wikipedia.org/wiki/Phishing

Sorry but I wouldn’t agree even if u would to give password to everyone in the world you need 2FA code which u get on Steam Guard or phone number and there wasn’t any code, any requests for login anything.
Tali 11 sept. 2024 la 4:33 
Postat inițial de Crazy Tiger:
Postat inițial de ljubavi:

If you are referring to a bloody.com I’m using the website for quite some time, I’ve also had trades with them and received everything I got there.
Im not getting the part where they authorised new device without 2FA confirmation. And did very little damage.
All 3rd party websites are suspect. Sometimes because they're ran by scammers, other times because they get targeted by phishers.

Plus scammers aren't stupid enough to use every account that logs in. They need to appear legit enough so people call them "trusted", you know.

You need to read up on phishing. Then you'll understand how you accidentally confirmed their login device.

Really hard to believe I would confirm login if I knew i wasn’t logging in.
Postat inițial de ljubavi:
Postat inițial de Dr.Shadowds 🐉:
Here how phishing works.
1. Scammer contact victim via DM/email, or victim watch scammer videos, or saw ad scam. Maybe gamble, or trading promotion by scammer in search results victim looking for something.

2. victim visit scam site with no idea it was a scam site.

3. Victim click login entering the login information, AND entering in code which is sent to scammer device they login, and have your login token, or victim scan QR code then click approved for login that on scammer device to getting access.

So now you figure out most common day to day problem, how do you solve it, simple tell victim stop smashing buttons, and use brain pay attention then stop logging into scam sites.


Yes the moment scammers get on your account, they run to spam your friends in their DM with links, with message to trick them to fall for it, or try to sell every time you have in your inventory, or trade it.

Now you wonder why isn't there a 2nd code for login, well when have you ever had to enter a 2nd code to login, answer is you never did, you put username, password, plus code that it, there no 2nd code, scammers got in because you handed the code for them to use hence login process.

No contact via email as I really dont receive lot of emails.
There are no messages to my friends also I’ve never clicked on any when i got them from any other friend.

Every time u login into your Steam acc and have 2FA enabled u have to accept it on Steam Guard. Also if you want to change anything on steam (security stuff) u have confirm it with 2 security codes (steam guard/phone and email)
The fact you enter login info via scam site is the problem.

Adding more steps doesn't prevent, nor fixed the problem as long go out the way to logging into scam site. That why just don't login scam site that simple.
Postat inițial de ljubavi:
Postat inițial de Thiesen:
https://en.wikipedia.org/wiki/Phishing

https://en.wikipedia.org/wiki/Phishing

https://en.wikipedia.org/wiki/Phishing

https://en.wikipedia.org/wiki/Phishing

https://en.wikipedia.org/wiki/Phishing

https://en.wikipedia.org/wiki/Phishing

PLEASE READ C A R E F U L L Y!!!

One more time for good measure:

https://en.wikipedia.org/wiki/Phishing

Sorry but I wouldn’t agree even if u would to give password to everyone in the world you need 2FA code which u get on Steam Guard or phone number and there wasn’t any code, any requests for login anything.

You gave the code away when you logged in on that scam site that you, for whatever reason, protect.
Tali 11 sept. 2024 la 5:57 
Postat inițial de Unn4m3d (♥AUT♥):
Postat inițial de ljubavi:

Sorry but I wouldn’t agree even if u would to give password to everyone in the world you need 2FA code which u get on Steam Guard or phone number and there wasn’t any code, any requests for login anything.

You gave the code away when you logged in on that scam site that you, for whatever reason, protect.

The best way to determine if Bloody Case is legit or not is to take a closer look at what this platform offers. Despite it not being licensed or registered, the ownership is transparent and we can see that the company behind the site is Aghanim Group with headquarters in Lithuania.

Moreover, since all of the games are played against the house, we should also address the fairness features. At the time of writing, a dedicated provably fair system is put in place. Keep in mind that this system can be inspected and verified as soon as the game is finished which proves that this platform is legit.

https://csdb.gg/bloodycase/review/#:~:text=The%20best%20way%20to%20determine,Group%20with%20headquarters%20in%20Lithuania.
< >
Se afișează 1-15 din 61 comentarii
Per pagină: 1530 50

Toate discuțiile > Forumuri Steam > Steam Discussions > Detaliile subiectului
Data postării: 11 sept. 2024 la 1:25
Postări: 61