Összes téma > Steam fórumok > Help and Tips > Téma részletei
Curious Hijacking
--- The Story ---
So I went on vacation about a week and a half ago into an area where I had no service and when I returned, I couldn't access my account. After this, I tried a password reset email, and I didn't get the email! After looking back a couple days, it turned out the password was changed the day before I got back (July 28), by someone in China, while I live in Canada and have never been to or know anyone in China. After looking back in my Account History for my email, it turns out the player also logged into my email on the same day! After that, I went through the link to lock my account, but it says it had already been locked!

---Key Points---
  • Account locked by Hijacker
  • No Items Missing from Inventory
  • Friends list untouched
  • Account displays as offline since about time of hijacking

---Questions---
  1. How did he know what my email was?
  2. How did he manage to get into my email?
  3. What does anyone think he might have done?
  4. How can I prevent this in the future?

---Additional Points---
  • It goes without saying I changed all my passwords
  • I have SteamGuard enabled
  • I haven't visited any phishing sites, because I religiously check all the links after people started asking me to add their friends
  • Email Provider - Hotmail
Legutóbb szerkesztette: Skad2; 2014. júl. 30., 9:30
< >
110/10 megjegyzés mutatása
Just to be sure what is your email provider?
Black Blade eredeti hozzászólása:
Just to be sure what is your email provider?
Just using Hotmail
Did you have the same password on your steam account as your email?
Ericrct eredeti hozzászólása:
Did you have the same password on your steam account as your email?
Unfortunately yes, but I don't see why this matters, as they wouldn't have had my password in the first place... right?
Skad2 eredeti hozzászólása:
Ericrct eredeti hozzászólása:
Did you have the same password on your steam account as your email?
Unfortunately yes, but I don't see why this matters, as they wouldn't have had my password in the first place... right?
I think if they had access to your email first then they could see any emails Steam has sent you to get your account name. Then they could have your password reset to that email and then change your Steam password then change your Steam contact email.
Legutóbb szerkesztette: HLCinSC; 2014. júl. 30., 10:38
Skad2 eredeti hozzászólása:
Ericrct eredeti hozzászólása:
Did you have the same password on your steam account as your email?
Unfortunately yes, but I don't see why this matters, as they wouldn't have had my password in the first place... right?

Depends how strong your password was. Any word that's easy to remember is often also easy for someone to guess or break with the appropriate tools - even if you substitute characters and wind up with s0m3th1ng l1ke th15. Someone with the right tools can crack passwords like those in a matter of minutes.

Once they've got access to your email they'll try to use it to do access a whole load of sites - Steam, MMO's, online banking and gambling, etc. - to see if there's anything there that they can liquidate to make a profit before you find out what's happened.

Get everything sorted and sweep your PC for malware just to be on the safe side... then you might want to consider investing in a password manager to generate (and remember) some unbreakable passwords for you.
Just to be safe i think you be best to run a scan:
https://www.malwarebytes.org/
Skad2 eredeti hozzászólása:
Black Blade eredeti hozzászólása:
Just to be sure what is your email provider?
Just using Hotmail
I've had to recover several hotmail accounts retrieved by phishers and exploiters. If possible, enable two factor authentication on your email account, so any future login attempt will require a SMS code sent to your mobile.
Black Blade eredeti hozzászólása:
Just to be safe i think you be best to run a scan:
{HIVATKOZÁS TÖRÖLVE}
Already done.
Tito Shivan eredeti hozzászólása:
Skad2 eredeti hozzászólása:
Just using Hotmail
I've had to recover several hotmail accounts retrieved by phishers and exploiters. If possible, enable two factor authentication on your email account, so any future login attempt will require a SMS code sent to your mobile.
Conveniently did this a couple hours before your message.
< >
110/10 megjegyzés mutatása
Laponként: 1530 50

Összes téma > Steam fórumok > Help and Tips > Téma részletei
Közzétéve: 2014. júl. 30., 9:23
Hozzászólások: 10