RedEzzio 1 FEB 2020 a las 11:22
My son was scammed yesterday on steam - warning and ask for help
Greets Fellow Steamers,

Please forgive me the language errors as english is not my native language.

This is a warning for those of You who did not hear about this scam. And also I am asking You for some explanation if You know why it worked.

Thank You in advance.

Yesterday happened the unfortunate thing

1. My son came to me and aked not to accept an offer with all his items (dozens of CS go skins) he just send me.

2. I asked him why he did it

3. My son told me that there is a give away only for people with inventory value below 2$ (or something like that). As he got skins with value circa about 50$ (very hardly earned) he temporarily transfered all his skin to my steam account

4. That sounded very suspicious so I handedn him my phone and asked to open steam app (we both have steam guard) and look for the unaccepted offer

5. As he check my phone he got pale and said - there is no offer from me

6. He run to his computer and shouted that his was scammed. All items has been treaded to the scammer whos account looked as mine

7. I really had no time and hat to go to job but today I looked at this trade and this scammer account look different (different miniature and name) but my sons item are still (strange...) on this scammer account along with many other items.

8. My son told me that this scammer inventory increaded more than 100 items since yeasterday

Me and my son really do not understand how this scam was made. My son had me in friends but not this scammer. He believes that he has chosen my avatar composed an offer, then somehow the offer was rejected then my son started to confirm all the pop-ups along with the information from steam that that the trading partner is not his steam friend.
My son admits that he just confirmed trade despite this warning as he says thay sometimes steam issues wrong warnings - I know that this was the correct warning

I do not know if this scam is a new thing to You - if Yes treat it as warning. If you know this scamming scheme please explain it to me - how it is done

I want to learn myself and my son to protect against future scams.

My son reported the scammer and the steam group user who invited him to the give-away.

I understand that there is no chance to get items back - despite the fact that we see them on scammer account?

RedEzzio
Publicado originalmente por nullable:
Steps to take NOW:
1. Scan for malware https://www.malwarebytes.com/
2. Deauthorize all other devices https://store.steampowered.com/twofactor/manage
3. Change passwords from a clean computer
4. Generate new backup codes for your Mobile App https://store.steampowered.com/twofactor/manage
5. Revoke the API key https://steamcommunity.com/dev/apikey (there should be nothing in the APIKEY)



Publicado originalmente por RedEzzio:

I do not know if this scam is a new thing to You - if Yes treat it as warning. If you know this scamming scheme please explain it to me - how it is done

It's not new. It happens all the time. Your son in all his skin trading and likely participating on 3rd party (non-steam) trading sites has figured out a way to compromise his account. Perhaps providing his credentials into a login form that looks like a legitimate Steam login. Regardless of the exact details, the root cause is usually the user being reckless with their account security. Users tend to be the weakest link when it comes to account security.

And greed is a powerful motivator and is often used to get people to act against their own best interests. Your story highlights this. A scenario was concocted for him to get him to trade his valuable items so he would be "eligible" for something valuable to be given to an account with virtually no items.

Whenever greed is driving your decisions, it's a big red flag. Stop and take an inventory of what you're doing.

Publicado originalmente por RedEzzio:
I understand that there is no chance to get items back - despite the fact that we see them on scammer account?

The Steam policies are pretty clear about this. Trades are not reversed, items aren't duplicated or returned.
< >
Mostrando 1-15 de 16 comentarios
El autor de este hilo ha indicado que este mensaje responde al tema original.
nullable 1 FEB 2020 a las 11:26 
Steps to take NOW:
1. Scan for malware https://www.malwarebytes.com/
2. Deauthorize all other devices https://store.steampowered.com/twofactor/manage
3. Change passwords from a clean computer
4. Generate new backup codes for your Mobile App https://store.steampowered.com/twofactor/manage
5. Revoke the API key https://steamcommunity.com/dev/apikey (there should be nothing in the APIKEY)



Publicado originalmente por RedEzzio:

I do not know if this scam is a new thing to You - if Yes treat it as warning. If you know this scamming scheme please explain it to me - how it is done

It's not new. It happens all the time. Your son in all his skin trading and likely participating on 3rd party (non-steam) trading sites has figured out a way to compromise his account. Perhaps providing his credentials into a login form that looks like a legitimate Steam login. Regardless of the exact details, the root cause is usually the user being reckless with their account security. Users tend to be the weakest link when it comes to account security.

And greed is a powerful motivator and is often used to get people to act against their own best interests. Your story highlights this. A scenario was concocted for him to get him to trade his valuable items so he would be "eligible" for something valuable to be given to an account with virtually no items.

Whenever greed is driving your decisions, it's a big red flag. Stop and take an inventory of what you're doing.

Publicado originalmente por RedEzzio:
I understand that there is no chance to get items back - despite the fact that we see them on scammer account?

The Steam policies are pretty clear about this. Trades are not reversed, items aren't duplicated or returned.
Última edición por nullable; 1 FEB 2020 a las 11:37
J4MESOX4D 1 FEB 2020 a las 11:33 
Your son gave his credentials away to a phishing/fake Steam site and these were then stolen and login-botted into a real Steam Client where his account was compromised. The hijackers then gained control of the API key which is used to control trades so when your son next traded items away, the trade would be cancelled and then re-directed to the hijacker's account and the items stolen. This scam relies on the victim confirming the contaminated trades themselves via the authenticator.

You must do the steps given above in order to secure the account but any items lost this way aren't returned.
RedEzzio 1 FEB 2020 a las 11:36 
Dear Brockenstain.
Thank You for quick answer. This is crucial for me to know that my son steam account was compromised - that means he is still in danger

Worse thing is that You suggest that also his computer could be compromised and also steam guard on mobile phone?

I wonder why newest and actual Bitdefender 2020 did not reported anything.

I will do exactly as You told.

If you have any link describing what exactly those scammers do - I would appreciate that. If You do not want to promo scammers techniques - I respect that also.

Great thanks anyway!
Teksura 1 FEB 2020 a las 11:46 
Scan for malware https://www.malwarebytes.com/
Deauthorize all other devices https://store.steampowered.com/twofactor/manage
Change passwords from a clean computer
Generate new backup codes https://store.steampowered.com/twofactor/manage
Revoke the API key https://steamcommunity.com/dev/apikey
Stop using shady third party trade sites or clicking suspicious links.


Do each of the steps.



What happened is your account became compromised, most likely through a third party site. This well known scam then requires you to authorize the trade giving your items away after you allow them access to your account through either malware, or giving away your details through a phishing fake login page or other trick used by those shady third party sites.

The way it does this is after it gains access to your account, a bot waits until you send out a trade offer, and then using the access you gave to them, their bot cancels the trade, changes a bot account to match the name and profile picture of the person you wanted to trade with, and then sends a trade giving your stuff away for free.

The scam depends on you ignoring all the warnings, such as "this user is not on your friends list", "this user has a similar name to someone on your friends list", their items missing from the offer, the big "you will receive nothing" text, the fact that they have the wrong level, wrong "has been on Steam since" date (usually obviously too recent to make sense), and a few other obvious warnings. It only works if you're not even looking at what you're doing. Sadly, an awful lot of people don't care enough to verify the trade is what they are expecting, so this scam continues to work.

Valve will not return items you gifted away to the scammer as a result of ignoring all the warnings. https://support.steampowered.com/kb_article.php?ref=9958-MJDG-3003
Kietan 1 FEB 2020 a las 11:46 
It's very likely that there isn't malicious software involved in the scam, which is why BitDefender wouldn't report anything suspicious. It still makes sense to protect your computer and to scan with Malware Bytes though.

Unfortunately most of these scams require people with a trusting nature to be tricked into willingly moving their inventory once their account has been compromised.
76561198407601200 1 FEB 2020 a las 11:49 
Publicado originalmente por RedEzzio:
Greets Fellow Steamers,

Please forgive me the language errors as english is not my native language.

This is a warning for those of You who did not hear about this scam. And also I am asking You for some explanation if You know why it worked.

Thank You in advance.

Yesterday happened the unfortunate thing

1. My son came to me and aked not to accept an offer with all his items (dozens of CS go skins) he just send me.

2. I asked him why he did it

3. My son told me that there is a give away only for people with inventory value below 2$ (or something like that). As he got skins with value circa about 50$ (very hardly earned) he temporarily transfered all his skin to my steam account

4. That sounded very suspicious so I handedn him my phone and asked to open steam app (we both have steam guard) and look for the unaccepted offer

5. As he check my phone he got pale and said - there is no offer from me

6. He run to his computer and shouted that his was scammed. All items has been treaded to the scammer whos account looked as mine

7. I really had no time and hat to go to job but today I looked at this trade and this scammer account look different (different miniature and name) but my sons item are still (strange...) on this scammer account along with many other items.

8. My son told me that this scammer inventory increaded more than 100 items since yeasterday

Me and my son really do not understand how this scam was made. My son had me in friends but not this scammer. He believes that he has chosen my avatar composed an offer, then somehow the offer was rejected then my son started to confirm all the pop-ups along with the information from steam that that the trading partner is not his steam friend.
My son admits that he just confirmed trade despite this warning as he says thay sometimes steam issues wrong warnings - I know that this was the correct warning

I do not know if this scam is a new thing to You - if Yes treat it as warning. If you know this scamming scheme please explain it to me - how it is done

I want to learn myself and my son to protect against future scams.

My son reported the scammer and the steam group user who invited him to the give-away.

I understand that there is no chance to get items back - despite the fact that we see them on scammer account?

RedEzzio


https://steamcommunity.com/discussions/forum/7/1747893804397849536/#c1747893804398016279

I don't understand how it was possible for your son to become scammed, surely he read all of the other warning topics such as this one, correct?
RedEzzio 1 FEB 2020 a las 11:51 
Dear J4MESSOX4D - Thank You!
Now I also understand how it could be done.

I just have been talking with my son - I told him that experts on steam (You dear fellows) insist that he had to give at some point access to his account along with steam guard code.

And he admitted that on some page - lured with greed - he simply entered steam creditentials along with steam guard code.

Now I undeerstand this "mystic scam"

I am starting the porocedure provided by Brockenstain.

Great respect to both of You!
J4MESOX4D 1 FEB 2020 a las 11:52 
Publicado originalmente por RedEzzio:
Dear J4MESSOX4D - Thank You!
Now I also understand how it could be done.

I just have been talking with my son - I told him that experts on steam (You dear fellows) insist that he had to give at some point access to his account along with steam guard code.

And he admitted that on some page - lured with greed - he simply entered steam creditentials along with steam guard code.

Now I undeerstand this "mystic scam"

I am starting the porocedure provided by Brockenstain.

Great respect to both of You!
Good stuff and at least he has come clean. Just finish the steps in full and tell him to avoid such sites in future and never give away his Steam credentials to anywhere else that isn't 100% safe.
nullable 1 FEB 2020 a las 12:17 
Publicado originalmente por RedEzzio:
Dear J4MESSOX4D - Thank You!
Now I also understand how it could be done.

I just have been talking with my son - I told him that experts on steam (You dear fellows) insist that he had to give at some point access to his account along with steam guard code.

And he admitted that on some page - lured with greed - he simply entered steam creditentials along with steam guard code.

Now I undeerstand this "mystic scam"

I am starting the porocedure provided by Brockenstain.

Great respect to both of You!

Well good for your son. It's not an easy thing to admit, and a lot of people want to argue or shift the blame because protecting their own egos ends up being more important to them.

The only other thing I can say is for him not to take it too hard, thousands and thousands, perhaps millions of Steam users have fallen into the same trap. All this really proves is he's just a regular human being like the rest of us. But if he can learn from his mistakes on the first go around he'll be better off than many.
RedEzzio 1 FEB 2020 a las 12:20 
Thank You once again all You good people of Steam Community

Borockenstein, J4MESSOX4D, The Living Tribunal, Obey, Teksura

This is my first post for help ever and I am astonished with the speed and quality of your help.

I hope I can repey it somewhere in the future to other steam users.

The case is closed. We are processing the steps provided

Computer is not likely to be infected (screening is running now)
My sons admited to go to page provided him on steam group (a person who provided it has been reported) which rules user to login with his steam creditentiald and steam guard code
The rest is exactly as You described:

He willingly created and offer directed to real me with all his items in order to temporarily have "poor" acount in order to take a part in free give away <- THIS IS HOW THEY RULED HIM

The offer for proper me was "somehow" rejected
The an offer appeared somehow (it was a scammer diguised as me)
My son just confirmed it
Steam warned him that this person is not his steam friend
My son IGNORED that and confirmed it

This is a hard lesson for him. He has been earning this 50$ for skins for a few months by making dozens of english self learning english lessons. We allow him to buy digital goods only if he invest an "earning" time into his education. Those skins are equivalent of dozens of hours of making translations from english to polish - in order to improve his skills

So some money has been lost, expierience has been gained, case has been understood - thanks to You!. Some english have been improved on my sons side

It is important to male such a mistake once. That what I want him to learn


Best regards
Mariusz / Red Ezzio
Silicon Vampire 1 FEB 2020 a las 12:38 
And kudos to you for raising a son that doesn't try to obfuscate and shift the responsibility. That seems to be a rare quality these days, especially for a young person.
Zekiran 1 FEB 2020 a las 13:48 
Publicado originalmente por Silicon Vampire:
And kudos to you for raising a son that doesn't try to obfuscate and shift the responsibility. That seems to be a rare quality these days, especially for a young person.


^^^ Indeed.

Now both of you know to be a little bit more wary. Enjoy your gaming, but be careful what you do online!
RedEzzio 1 FEB 2020 a las 13:51 
Thank You.
Last thing to say which 100% confirms that mechanism described by all of You was exactly what happened - > at last step of cleaning instructions we have found the filled field API key - never generated by us.

Of course reseted immidietely

My son asked me to thank to all of You on his behalf - this account is precious for him as he earned GOLD in CS:GO for the first time in his life this morning.

Who knows for what else this account could be used for by scammers - resulting for example in ban.

I wish all of You the very best!
Dear fellow Steam Friends!
DC-GS 1 FEB 2020 a las 14:08 
Sorry for hijacking your thread RedEzzio, just wanted to ask a quick question.

Publicado originalmente por Brockenstein:
5. Revoke the API key https://steamcommunity.com/dev/apikey (there should be nothing in the APIKEY)

In my case I dont see a list. Only an input field and a checkbox to register a new key. Is it what it should look like?
RedEzzio 1 FEB 2020 a las 14:34 
Hi DC-GS
My account which I believe has not been compromised has exactly looking APIkey page as You described (empty imput field and checkbox)
My son's account which was hijacked had an API key field fully filled with somethin like this
zaCELgL!0imfnc8mCDFwsAawjYr4Rx-Af50YYqtlx <- just a fake API key here

As my son has no clue what an API key is <- it was a proof that his account had been compromised.
I went through all the steps described by those helpful colegues in order to regain this account.

I hope that answers Your question
regards!
< >
Mostrando 1-15 de 16 comentarios
Por página: 1530 50

Publicado el: 1 FEB 2020 a las 11:22
Mensajes: 16