Всички дискусии > Steam форум > Help and Tips > Подробности за темата
Some Punt with a hard CUH at the start, hacked my Steam Account and was emptying my inventory
Account got hacked, or something of the sorts about 30 minutes ago.

Was reading some Manga on my phone when i got a notification through steam guard that something was listed, thought that was strange given i'm not even at my Computer. Clicked on the notification, got the "There is nothing you need to confirm" Strange, then emails just start spamming my phone as my inventory was being sold, by the time i got my password to finally change over 123 emails had been received (Although market history shows around 250 results for stuff listed today)

I have no idea how they got into my account to begin with, as far as i know i haven't given out account information to anyone, i have 2 fac set up so any attempt to login would tell me anyway (Which typically leads to a password change) i haven't been "phished" or anything (Had been once like 2 years ago? Where i clicked the link that was sent by a friend and immediately had 2 fac disabled, password changed, friends deleted etc etc) I don't know how they bypassed the 2 fac either with Market stuff, as normally you have to manually approve each listing (I'm assuming they just have a bot do it).

Question is, will support be able to help recover anything? Or am i stuck using the disgustingly low value wallet funds i got from it to attempt buying back my stuff item by item?
< >
Показване на 1-15 от 30 коментара
Secure your account. All steps...

Scan for malware. https://www.malwarebytes.com/

Deauthorize all devices https://store.steampowered.com/twofactor/manage

Change your password on a secure device.

Generate new back up codes. https://store.steampowered.com/twofactor/manage

Revoke the api key (this should be empty) https://steamcommunity.com/dev/apikey

Read the Steam Item Restoration Policy.

Report your friends account for being compromised to help prevent more hijackings.

:qr:
Последно редактиран от cSg|mc-Hotsauce; 21 май 2023 в 18:32
Yes I know it says in whatever support section its under that "Securing your account is your problem" but i had their 2 fac stuff and this STILL happened. I did what i was meant to keep it secure as best i could. I'm presuming i'm just ♥♥♥♥♥♥ and on my own but figured its at least worth asking so i know what i'm wasting my time doing next
Първоначално публикувано от cSg|mc-Hotsauce:
Secure your account. All steps...

Scan for malware. https://www.malwarebytes.com/

Deauthorize all devices https://store.steampowered.com/twofactor/manage

Change your password on a secure device.

Generate new back up codes. https://store.steampowered.com/twofactor/manage

Revoke the api key (this should be empty) https://steamcommunity.com/dev/apikey

Read the Steam Item Restoration Policy.

Report your friends account for being compromised to help prevent more hijackings.

:qr:

Don't have malware,

Only authorised device is my phone and PC,

Password has been changed on a secure device,

Back up codes get re-gen'd every few months. Have Re-genned now

Afaik my apikey is empty. Have confirmed its empty? It asks me if i want to make one so i presume its empty

None of my friends have been compromised.

Edit: Plus y'know, none of this stuff helps post account recovered.

Edit 2: Good advice to help prevent future cases and i do appreciate that.
Последно редактиран от ♡ Chaotic ♡; 22 май 2023 в 0:02
Your name history is riddled with 3rd party sites advertisements. Those are all use at own risk, and known to be linked to phishing. That's likely how someone got past your 2FA, given just how many are in your history...

Stop using those sites, and take your account security more seriously to prevent this from happening again.
Първоначално публикувано от ♡ Chaotic ♡:
Edit: Plus y'know, none of this stuff helps post account recovered.

No need to be salty.

Stop using those scam sites and this would not happen.
Първоначално публикувано от Mr. Smiles:
Your name history is riddled with 3rd party sites advertisements. Those are all use at own risk, and known to be linked to phishing. That's likely how someone got past your 2FA, given just how many are in your history...

Stop using those sites, and take your account security more seriously to prevent this from happening again.


Name history i haven't used in literally 6 years lmao. Haven't used that since i was 14-15 in highschool so yeah no. I've been taking my account security seriously for the past year or 2 since the phishing hack
Първоначално публикувано от Shaggy:
Първоначално публикувано от ♡ Chaotic ♡:
Edit: Plus y'know, none of this stuff helps post account recovered.

No need to be salty.

Stop using those scam sites and this would not happen.

Don't use scam sites. only things i have steam connected to atm is DIM/D2 Armor picker and Light.gg. All of which are safe and are used for Destiny 2.

Edit: For the record, pointing out that the advice is kinda useless and doesn't help post account recovery isn't "salty" but also, get hacked and lose over 100+ items for cents of what they're worth before telling someone not to be annoyed about losing all of that stuff.
Последно редактиран от ♡ Chaotic ♡; 21 май 2023 в 18:52
You used third party scam sites. So no surprise you got scammed. I hope you learned your lesson.
Първоначално публикувано от Callahan420:
You used third party scam sites. So no surprise you got scammed. I hope you learned your lesson.

Except i haven't? That's my problem. 3rd time someone has mentioned it and its been wrong each time. Don't know what 3rd party scam sites ya'll are on about given the only 3rd party stuff i've used is the apps mentioned above for Destiny 2 (Being DIM, Light.gg and D2armorpicker)
The only way someone gets into your account is if they have your credentials. Steam accounts are not hacked, they are hijacked. If you login to steam through ANY 3rd party sites, you are at risk.

It's up to you to figure out where you leaked your credentials, and plug the security hole.
Първоначално публикувано от Mr. Smiles:
The only way someone gets into your account is if they have your credentials. Steam accounts are not hacked, they are hijacked. If you login to steam through ANY 3rd party sites, you are at risk.

It's up to you to figure out where you leaked your credentials, and plug the security hole.

I mean Hacked or Hijacked, the technicality is irrelevant, People aren't actually hacking in Rainbow Six matches they're just clicking buttons on cheat menus but people still saying "They're hacking" its just sentimantics at that point.

If it was from some 3rd party ♥♥♥♥ (Not that i know how given the only 3 i use are safe) that doesn't really explain how tf they entirely bypass Steams 2 fac?? That ♥♥♥♥ is meant to go off the instant someone logs in as they need that code to get in no? Ignoring the whole "Selling all your ♥♥♥♥ on the Marketplace" afterwards which also, normally needs to be approved 1 by 1 via the 2 fac app (And somehow steam doesn't auto flag 100+ listings in a few minutes as suspicious activity astounds me) i don't get not only how they'd even log into my account without my knowledge but then also be able to list stuff near instantly and just spam that process (Until presumably they buy the most expensive thing your account can afford before selling / trading that to one of their accounts) without ever triggering anything 2 fac related (While its still enabled at that?)
Same thing just happened to me and I went searching to see if it was happening to other people, someone emptied about 40 items out of my inventory before I was able to change my password. The hell is going on dude.
Първоначално публикувано от T0LK13N:
The hell is going on dude.

People giving their information away..
I haven't logged into a 3rd party website ever. And I was away at my cabin all weekend. The fact this is happening to many people at the same exact time means something else is going on, I know of at least 5 other people in my friend group who had the same thing happened within the past 2 hours.

This just happened to me about 45 minutes ago FYI. And my discord server blew up with people saying the same thing.
Tried to remove all authorized devices and my phone is saying "this cannot be reached at the moment please try again later".
Последно редактиран от T0LK13N; 21 май 2023 в 20:12
Първоначално публикувано от T0LK13N:
I haven't logged into a 3rd party website ever. And I was away at my cabin all weekend. The fact this is happening to many people at the same exact time means something else is going on, I know of at least 5 other people in my friend group who had the same thing happened within the past 2 hours.

This just happened to me about 45 minutes ago FYI. And my discord server blew up with people saying the same thing.
Tried to remove all authorized devices and my phone is saying "this cannot be reached at the moment please try again later".

Yeah had the same message the entire time it was happening and i was attempting to use the app. Lost about half my items just because of that specific message from the app. Caught it around 40-50 items sold but wouldn't let me change my password unless i did it via the app. Which ofc spat out that error message so wouldn't let me change the password for a few attempts. By the time the password change went through, yeah 123 items gone and yeah same boat with not using 3rd party ♥♥♥♥, only i use the 3 main ones for Destiny 2 which unless the other 90 thousand people got hit as well. Is unlikely to be the source of it
Последно редактиран от ♡ Chaotic ♡; 21 май 2023 в 20:29
< >
Показване на 1-15 от 30 коментара
На страница: 1530 50

Всички дискусии > Steam форум > Help and Tips > Подробности за темата
Дата на публикуване: 21 май 2023 в 18:29
Публикации: 30