Winter Trabex 2016 年 6 月 28 日 下午 1:08
(K----- Limited) Steam/Paypal Scam
Hello friends, I had rather an unusual shock today when I went to pay for an 89 cents gallon of water and found my card (which was supposed to have 260 dollars on it) wouldn't get approved at the register. The debit card I was using was registered to my paypal account.

I found 23 anamalous transactions for digital steam items, each from 10 to 20 dollars. About half of them were in Euros, not dollars. During the course of investigating this matter together with the Paypal security representatives, I uncovered the following information:

-My Steam purchase history did not record any of the digital items (some of which did not even appear to be sold at Steam anyway).
-I had SteamGuard on, but never received an email (or 23) asking me to confirm my login with a special code.
-The hacker was able to provide records of the transaction, which caused Paypal to find in their favor the first time around. However...
-As soon as I got emails from Paypal notifying me about the open case, I also received emails from (K------) Limited with a record of the purchase (two days after the purchase was credited to my account)
-These emails had the pseudonym that I use on Paypal to prevent identity theft. They also had me a street address that doesn't exist in a city I don't live in.
-All of this information combined has since caused Paypal to credit my money. I may have lost a few dollars in the Euro conversion, but I'm happy that the situation was resolved.

Now I'm not entirely sure where the breach occurred or how- whether it was from Paypal or Steam or something else. However, I thougth I would outline the steps that I took so that anyone else who runs into a similar problem.

Be careful out there friends.
最后由 Winter Trabex 编辑于; 2016 年 6 月 28 日 下午 1:09
< >
正在显示第 1 - 6 条,共 6 条留言
Cathulhu 2016 年 6 月 28 日 下午 1:13 
So, somehow someone got your card details, not from Steam, as Valve does not save credit card details. And if you used PayPal on Steam Valve never knew about that card in the first place.
Winter Trabex 2016 年 6 月 28 日 下午 1:20 
I looked into the third-party site in question. They do sell Steam items. They appear (on the surface) to be legitimate. However, the delay in order confirmation emails makes me seriously question them.

I do not know where the breach came from. Very likely, it's my own fault for not updating my password often enough or having a password that wasn't strong enough.
Cathulhu 2016 年 6 月 28 日 下午 1:24 
Again, did you use the credit card on Steam directly, or through a payment processor like PayPal?
Winter Trabex 2016 年 6 月 28 日 下午 1:29 
The transactions credited did not originate from my debit card. The transaction list can tell when a card is used.
Satoru 2016 年 6 月 28 日 下午 1:29 
note you shouldnt have lost any money in the conversion. the charges would be cancelled/refunded. In that situtaion you get exactly the same amount of money back as was put in.

the only time you'd lose money is if

a) you send 5 euros
b) i can't refund it properly
c) I send you 5 euros back instead

In that situation you lose money in the transaction beacuse of the exchange rate and fees. But if you just get the transaction cancelled/refunded the original amount of money is sent back to you because its considered one 'transaction' not 2 separate ones.

I've had to deal with this with a restaurant one time for my brother's wedding. Tons of headaches.
最后由 Satoru 编辑于; 2016 年 6 月 28 日 下午 1:29
Satoru 2016 年 6 月 28 日 下午 1:31 
引用自 floaty_79
I looked into the third-party site in question. They do sell Steam items. They appear (on the surface) to be legitimate. However, the delay in order confirmation emails makes me seriously question them.

I do not know where the breach came from. Very likely, it's my own fault for not updating my password often enough or having a password that wasn't strong enough.

I'm goin to guess it was a paypal account compromise given that your steam account has no record of the transactions.

Paypal has 2FA authentication available. Annoyingly its only for Symantec's token thing. But its something you might want to look into to increase your paypal security.
最后由 Satoru 编辑于; 2016 年 6 月 28 日 下午 1:31
< >
正在显示第 1 - 6 条,共 6 条留言
每页显示数: 1530 50

发帖日期: 2016 年 6 月 28 日 下午 1:08
回复数: 6