Всички дискусии > Steam форум > Steam Discussions > Подробности за темата
old steam account got hacked, steam guard email is disabled suddenly?? just curious how its happened
hello, i will explain some background to make this more clear before. i have 2 steam account(this one and the old one). i made the old one around more than 10 years ago to play dota2 beta key at that time if i recall correctly and the password probably kinda weak at that time
so the last time i login on that old steam account also should be around more than 10 years ago

so the email for the old steam account, i still login into the email regularly, changing the password and activate 2fa long time ago, so i only login to make sure no email deleted and i dont use the email anymore for anything

today i login as usual every year around the same month, but decided to checking the inbox this time. and i found out that there is 1 email from steam support saying my steam account email is changed recently on september 2024. after that i decide to check more if i receive any other email and i dont see any email from steam guard for the 2FA on that month

im pretty sure the steam guard is activated, because i check the older email that i received and i saw there are multiple email from steam support about steam guard codes so i can login

my question is how they disabled the steam guard email codes? i had some email for steam guard codes means the guy know my email and password but cant access it because they cant access my email, so suddenly my steam guard codes disabled?

what are the chances of support disabling it because the hacker know my email and password only?

is it still possible to recover my account after 5 months? and can someone let me know how to recover my account, at this point i dont even want to click the link on that email if possible

all my other account and email are fine btw, even tho they all login on same device and day

p.s the sequence is : old steam account last login is 10 years ago >>> i only login emails once a year to avoid them to be deleted without checking inbox >> on 2024 i decided to check inbox, i found steam guard codes email from 2-3 years ago, this year no steam guard codes email, only a mail from steam saying my email for old steam account changed recently on september 2024

why suddenly there is no steam guard codes email?
Последно редактиран от Ashvain; 24 февр. в 10:19
< >
Показване на 1-15 от 23 коментара
Your account wasn't hacked. It was phished. At some point in the past year, or potentially earlier, you gave away your credentials.

Do these:

1. Scan for malware https://www.malwarebytes.com/
2. Deauthorize all other devices https://store.steampowered.com/twofactor/manage
3. Change passwords from a clean computer
4. Generate new backup codes for your Mobile App https://store.steampowered.com/twofactor/manage
5. Revoke the API key https://steamcommunity.com/dev/apikey (there should be nothing in the APIKEY)

If you need to recover the account, read this:

https://steamcommunity.com/sharedfiles/filedetails/?id=1126288560
Първоначално публикувано от Chika Ogiue:
Your account wasn't hacked. It was phished. At some point in the past year, or potentially earlier, you gave away your credentials.

i dont know how they got my credentials, its probably from data breach or whatever, but like i said the last time i login with that old account is more than 10 years ago, and recently like 1 year ago theres still some email of steam guard codes, means the guy trying to login and knowing my password right?( this is not me login with that steam account)

i never login with that old account anymore, so all the steam guard codes email are from the guy login attempts, not me

so why suddenly no more email of steam guard code when they changing my steam email? i will take some screenshot later
Първоначално публикувано от Ashvain:
i dont know how they got my credentials, its probably from data breach or whatever,

The only way that would be the case is if you used the exact same account name, email, and password combination as somewhere else. Don't do that.
Hey there, sorry to hear that you got hacked too.

I can report something similar in my experience with Steam Guard - and my first question is:

Did you peered your smartphone with Steam guard with your windows?

But let me tell you my story:

My discord and my Reddit got hacked - that's where I realized some weird data steal was going on.

I instantly wiped my whole win 11 and setted all passwords and logins I could remember new and added 2 factor authentication. (Most with google authenticator).

Steam should be safe because I setted steam guard when it came out and used also the steam guard app on my smartphone.

On 21.02. someone purchased with my steam account a ♥♥♥♥♥♥ Dota 2 headgear item (~sold for 90€ - for the exact amount of my steam wallet ( a bit more than twice of 90).

1 day later the hijackers tried to "cover their traces" by buying a 100, a 50 and a 25 € wallet charge.

Steam was connected to my PayPal. A big mistake as I believe now.

I recognized that activities 2 days after that dota 2 Item BS - and contacted the support immediately.

Also I changed my steam account password.

Now I don't understand:

How could someone log into my steam without my Steam guard is popping up a new log in attempt?

Did they "mirror" any sessions?

Isn't that - a clear marker - that the guard is not working 100%?

For now the support cancelled the 175 € wallet purchases done by the hackers, but my old wallet of honest gained ~189 is actually gone.

I still sit on that ♥♥♥♥♥♥ Dota 2 crown item for ~90€.

I responded to Louise from the support, that I don't get - how this could be possible?

And in addition asked for the log in protocol for that Dota 2 transaction and the wallet charges.

Man I can feel your frustration.

And the point with smart link thru windows:

What if they could trespass over that link into my steam guard?

I don't know if this is technically possible.

It's just shocking, exhausting and I'm sad.
Have you EVER been going to "trading" sites?
Accounts on Steam are PHISHED because the end user gave away all their account details, giving them access to their account.

The account name, the password and the KEY to the door, the Steam Guard Mobile code, or scanning the QR code or authorising via fingerprint giving them access to the account.

How? by either logging into a known scam site or sites, tailored malware on your PC, the vote for my team scam, you have a pending ban scam on Discord, free knife click the link, signing in through a fake login window, the fake Valve employee scam etc.

How does Steam (a program) know it is not you when all the account details are correct? It doesn't, therefore any action taken on your account is seen as you doing said actions.

The alternative is not plausible:

1) Someone would have to "GUESS" your account name from "millions of possible combinations".

2) Next they would have to "GUESS" your password from "millions of possible combinations" and then match it to your account name with "millions of possible combinations".

3) And finally they would have to "GUESS" the Steam Guard Mobile code "which changes every 30 seconds" to match both your account name and password to then have access your account.

The weakest link is the end user, not the security offered.
Първоначално публикувано от Nx Machina:
Accounts on Steam are PHISHED because the end user gave away all their account details, giving them access to their account.

The account name, the password and the KEY to the door, the Steam Guard Mobile code, or scanning the QR code or authorising via fingerprint giving them access to the account.

How? by either logging into a known scam site or sites, tailored malware on your PC, the vote for my team scam, you have a pending ban scam on Discord, free knife click the link, signing in through a fake login window, the fake Valve employee scam etc.

How does Steam (a program) know it is not you when all the account details are correct? It doesn't, therefore any action taken on your account is seen as you doing said actions.

The alternative is not plausible:

1) Someone would have to "GUESS" your account name from "millions of possible combinations".

2) Next they would have to "GUESS" your password from "millions of possible combinations" and then match it to your account name with "millions of possible combinations".

3) And finally they would have to "GUESS" the Steam Guard Mobile code "which changes every 30 seconds" to match both your account name and password to then have access your account.

The weakest link is the end user, not the security offered.


I definitely got your point. But if my Win 11 was compromitted and they got my data.

They should not be able to get my authenticatoraccess too, or do you think they came into a fake login they showed up on my windows 11 - and I authorised that?

Ok, if we take that case: How could they login on a complete different day - even if I was logged in in my account? Shouldn't promp up a new authentication for that other log in?
Първоначално публикувано от Ashvain:
Първоначално публикувано от Chika Ogiue:
Your account wasn't hacked. It was phished. At some point in the past year, or potentially earlier, you gave away your credentials.

i dont know how they got my credentials, its probably from data breach or whatever, but like i said the last time i login with that old account is more than 10 years ago, and recently like 1 year ago theres still some email of steam guard codes, means the guy trying to login and knowing my password right?( this is not me login with that steam account)

i never login with that old account anymore, so all the steam guard codes email are from the guy login attempts, not me

so why suddenly no more email of steam guard code when they changing my steam email? i will take some screenshot later
They got the credentials because you leaked them somewhere. It's the only way this happens.
Also, the word is hijacked. Steam accounts are not hacked.


https://help.steampowered.com/en/faqs/view/0A94-F308-34A5-1988

Notice that Valve uses the word hijacked and not hacked?
Първоначално публикувано от C²C^Guyver |NZB|:
Also, the word is hijacked. Steam accounts are not hacked.


https://help.steampowered.com/en/faqs/view/0A94-F308-34A5-1988

Notice that Valve uses the word hijacked and not hacked?


Ok - I got you Guyver.

Check that profile out:

https://steamcommunity.com/id/gustavmarkin909

Thats the guy who has NOTHING at all on his profile - but that 1 Dota 2 Crown for a char ?

:gordon::meatytears:
Първоначално публикувано от Chika Ogiue:
Първоначално публикувано от Ashvain:
i dont know how they got my credentials, its probably from data breach or whatever,

The only way that would be the case is if you used the exact same account name, email, and password combination as somewhere else. Don't do that.

yea but this is still not answering how theres no steam guard email right before the email change notification
all my account have different password and email, there are previous steam guard email before from 2-3 years ago and i never notice it since i never check inbox
so this old account last login should be around 10 years ago
Последно редактиран от Ashvain; 24 февр. в 9:42
Първоначално публикувано от C²C^Guyver |NZB|:
Първоначално публикувано от Ashvain:

i dont know how they got my credentials, its probably from data breach or whatever, but like i said the last time i login with that old account is more than 10 years ago, and recently like 1 year ago theres still some email of steam guard codes, means the guy trying to login and knowing my password right?( this is not me login with that steam account)

i never login with that old account anymore, so all the steam guard codes email are from the guy login attempts, not me

so why suddenly no more email of steam guard code when they changing my steam email? i will take some screenshot later
They got the credentials because you leaked them somewhere. It's the only way this happens.

yea but what im curios about now is how there is no steam guard email right before the email change mail from steam

basically the sequence like this : old steam acc last login 10 years ago(probably acc name and password leaked somewhere) >>>> multiple steam code email since 2 3 years ago until now which is not by me >> 2024 i decide to check inbox, and in 2024 no steam code email but there is email change notification, this is also the first time i saw all that previous steam code email LOL

this is the 1st time i decide to check the inbox so yea i never notice the steam code email before until now. i only login all my email on same secure device once a year and have all 2fa activated, this is including email for this steam acc that i use now, but this steam account is fine
Последно редактиран от Ashvain; 24 февр. в 9:40
Първоначално публикувано от Nx Machina:
Accounts on Steam are PHISHED because the end user gave away all their account details, giving them access to their account.

The account name, the password and the KEY to the door, the Steam Guard Mobile code, or scanning the QR code or authorising via fingerprint giving them access to the account.

How? by either logging into a known scam site or sites, tailored malware on your PC, the vote for my team scam, you have a pending ban scam on Discord, free knife click the link, signing in through a fake login window, the fake Valve employee scam etc.

How does Steam (a program) know it is not you when all the account details are correct? It doesn't, therefore any action taken on your account is seen as you doing said actions.

The alternative is not plausible:

1) Someone would have to "GUESS" your account name from "millions of possible combinations".

2) Next they would have to "GUESS" your password from "millions of possible combinations" and then match it to your account name with "millions of possible combinations".

3) And finally they would have to "GUESS" the Steam Guard Mobile code "which changes every 30 seconds" to match both your account name and password to then have access your account.

The weakest link is the end user, not the security offered.


my old account last login is around 10 years ago >>> i only login all my emails once a year so they dont get deleted, i dont check inbox>> on 2024 i decide to check email inbox, i found steam guard code email from 2-3 years ago, this year on 2024 there is no steam guard code email, theres only 1 email change mail from steam

how its suddenly change my steam account email? and there is not steam guard code email like previous years is what makes me curious, like how?
Последно редактиран от Ashvain; 24 февр. в 10:03
NX Machina is running out of his clever explanations I guess.
Първоначално публикувано от C²C^Guyver |NZB|:
...Notice that Valve uses the word hijacked and not hacked?
Not to say it is one way or another, but being as how embarrassing it would be to Valve in the advent word of a hack gets out, accurate or not, it may be in their perceived best interest to play things down; I don't think it has added value coming from just Valve.
< >
Показване на 1-15 от 23 коментара
На страница: 1530 50

Всички дискусии > Steam форум > Steam Discussions > Подробности за темата
Дата на публикуване: 23 февр. в 9:33
Публикации: 23