Összes téma > Steam fórumok > Help and Tips > Téma részletei
Account Hacked - Be Careful
*EDIT*
---------
So after everything is done - this is the finalized update. A little TLDR - but if you want to get the full story including some trolling - you can go ahead.

Original post is at the end of this.

TLDR
--------
My STEAM account was compromised through a phishing link. I found the account/s that were involved in the hack, and made a list of all items (200+) that were transferred out, but STEAM said they're not going to give me back the items (more details below). Phishing link came through two accounts of friends I know personally, so guard was down - lesson learned - first time this has happened to me - was usually more careful.

STEPS TO TAKE
------------------------
Some users in this thread provided some good info.

Muppet among Puppets eredeti hozzászólása:
could access everything you can.

You could do these things to make sure every other "user" is gone.
Check that the email and phone number on the steam account are still yours.

Deauthorize all devices https://store.steampowered.com/twofactor/manage

Change your password on a secure device.

Generate new back up codes. https://store.steampowered.com/twofactor/manage

Revoke the api key https://steamcommunity.com/dev/apikey

GenX-Gamore eredeti hozzászólása:
As I have said, I take security very seriously, we have had money stolen from our bank accounts, and even my wife had her Debit card stolen the day it was replaced due to a lost card. I have learned over the years to never click e-mail links for login or "we noticed bank account is _____" Well unless it's a link to say Newegg to find new or better stuff for ya PC.

And I have followed the PC security channel for a long time.
https://www.youtube.com/@pcsecuritychannel
The two top Security software programs are Bitdefender even when disabled and Kaspersky do not, believe me, do your own research from a DESKTOP, NOT MOBILE. Here is a quick search I just did have a look see https://www.youtube.com/results?search_query=how+easy+is+it+to+hack+a+cell

https://steamcommunity.com/sharedfiles/filedetails/?id=3059904438


STEAM provided some information.

These are their "Account Security Recommendations".
https://support.steampowered.com/kb_article.php?ref=1266-OAFV-8478


SLIGHTLY LONGER
-----------------------------
Well - I think the details above cover most of what you need to do. But basically - if your account is hacked then STEAM will not restore your items.

Steam Item Restoration Policy
https://support.steampowered.com/kb_article.php?ref=9958-MJDG-3003

Apparently there's no recourse for items sent from your account because account security is the responsibility of the end user. The reasoning is kinda like this...apologies to the users that helped as I'm using you as examples.

Useless is the hacker and hacks into Muppet's account.
Useless then gives items to GenX.
Muppet contacts STEAM and identifies Useless as the thief.
Because items are now in GenX's account, STEAM says it's unfair to GenX to take the items from him. STEAM also says they won't duplicate the items to give back to Muppet as it will reduce the rarity of the items and also reduce their value in the store.

I was thinking that the hackers somehow broke into the account for one (or both) of my friends, but after discussing I'm settled on my friends accidentally letting the hackers in by providing their authenticator codes somehow. I've still not released the accounts, but I'll say there were two (2) specifically that did the trading out of my items and two (2) others that received items. Logins came from Russia.

MY MISTAKE
-------------------
There were two primary mistakes made in my case. One was skimming the message (was driving/working) and didn't see the last part of the URL with spelling errors. Two was the fact that multiple friends sent similar links about coupons - which lowered my guard related to the links. Regardless of who it comes from, should have used my usual due diligence.

Normally I only open stuff on my PC or laptop where I can see the full URL and inspect what's going on, but I opened the links on my phone. This resulted in the entire URL not being seen and I got caught. I thought something was up, but work had me REALLY busy until the weekend - which was too late. My items were already transferred out by then.

CLOSING
--------------
That's it for now. I think this can be closed out - I'll update if anything else happens - but I'm hoping the thread will help others to be more aware of what could happen and ensure the security of their accounts. Keep safe all.

*ORIGINAL POST*
--------------------------
I posted the same info on my profile - need to ensure that others are aware.

Apparently a friend of mine had their account hacked and had sent out a link saying they got some gift card from STEAM. Using my mobile I wasn’t able to fully view the details in the URL, but because it’s someone I know personally and trusted I opened the link. Came to a STEAM page that required sign in - a bit odd but it did have the authenticator (STEAM Guard) code stuff and all that so I went along. This was done while I was at work (driving and all) - I should have been more diligent.

Reinstalled stuff on my PC today and realized my STEAM password didn’t work. Went through and realized it may have been some Russians. Please be careful with links you get - they’re using all kinds of methods to get into your stuff now.

The problem here? I’ve lost ALL of my contacts. Going take time to get back everyone.

Again - be careful.
Legutóbb szerkesztette: Useless (死); 2023. okt. 24., 19:40
< >
115/38 megjegyzés mutatása
There's 2 lessons to be learned here and only one of them has to do with clicking on links.
Never log into given links or buttons.

I lately saw an url that i would have not recognized as fake. In a search result. And in the url bar there would be a tiny dot below a letter.
Thats why you need to stick to recommendations like "never".

Even using a searchengine can be dangerous, so never just do things.
Agreed with both replies so far. Just putting it out there so others can be aware. I have to give props to the phishing method though. It involved the use of the STEAM Guard code and then cutting off the user once they got logged in. It's elaborate and well done.

What I need to find out - which I've already asked STEAM support - is what data was accessed and such.

Accessing from desktop would have shown some more info. I checked my browser history on my phone - all of the links from "https://steamcommumutiy.com/" - which has two letters out of place. Well - wrong spelling overall. So it was missed because I was driving.

The site is no longer up - seems to have been taken down. Either by reports made or because they've gotten into enough accounts.

There may be others like that in future - so please be careful.
Legutóbb szerkesztette: Useless (死); 2023. okt. 21., 12:03
Useless (死) eredeti hozzászólása:
Agreed with both replies so far. Just putting it out there so others can be aware. I have to give props to the phishing method though. It involved the use of the STEAM Guard code and then cutting off the user once they got logged in. It's elaborate and well done.

What I need to find out - which I've already asked STEAM support - is what data was accessed and such.
You were not on steam. You just handed over the guard code, or scanned the scammers QR code for their login.

The hijacker could access everything you can.

You could do these things to make sure every other "user" is gone.
Check that the email and phone number on the steam account are still yours.

Deauthorize all devices https://store.steampowered.com/twofactor/manage

Change your password on a secure device.

Generate new back up codes. https://store.steampowered.com/twofactor/manage

Revoke the api key https://steamcommunity.com/dev/apikey
Useless (死) eredeti hozzászólása:
Just putting it out there so others can be aware.

Classic. And that's why there are hundreds if not thousands such threads on here. NOBODY reads these things BEFORE they need it. And then they make yet another thread nobody (who needs it) reads.
Muppet among Puppets eredeti hozzászólása:
Useless (死) eredeti hozzászólása:
Agreed with both replies so far. Just putting it out there so others can be aware. I have to give props to the phishing method though. It involved the use of the STEAM Guard code and then cutting off the user once they got logged in. It's elaborate and well done.

What I need to find out - which I've already asked STEAM support - is what data was accessed and such.
You were not on steam. You just handed over the guard code, or scanned the scammers QR code for their login.

The hijacker could access everything you can.

You could do these things to make sure every other "user" is gone.
Check that the email and phone number on the steam account are still yours.

Deauthorize all devices https://store.steampowered.com/twofactor/manage

Change your password on a secure device.

Generate new back up codes. https://store.steampowered.com/twofactor/manage

Revoke the api key https://steamcommunity.com/dev/apikey

No API keys. Already logged out all devices. Just didn't generate the new backup keys. Thanks for that. Will do shortly.

Understood I wasn't on a STEAM page or site. What I find interesting is how it was handled. Theory is, it seems to have used a front end to mimic the STEAM site layout and then once the STEAM Guard code is entered, it kept the session information and passed it on to the hackers. You get a generic failure message that makes you think it's genuine.

From the dates and timestamps, the problem was - initially - that I used the link. Next that I opened it while driving and couldn't validate properly. Next that I realized a problem but delayed in doing checks. Had I not been busy with work, I'd have checked it when I got home. Only now on the weekend did I have some time to check.

Point made that nobody checks these until after the fact. We are more reactive than proactive. Just hopeful that the info will find someone beforehand, and with the info and links provided I'm hoping it'll help someone.

Pscht eredeti hozzászólása:
Useless (死) eredeti hozzászólása:
Just putting it out there so others can be aware.

Classic. And that's why there are hundreds if not thousands such threads on here. NOBODY reads these things BEFORE they need it. And then they make yet another thread nobody (who needs it) reads.

What I'm doing is sharing the thread and info with those I know. Once it's passed on at least some persons will be aware.
Legutóbb szerkesztette: Useless (死); 2023. okt. 21., 14:54
Double posting for multiple reasons. More info.

Items in my inventory were transferred out to other accounts. I found the accounts that my items were sent to - and I raised the concern with STEAM. They pointed me to these.

Steam Item Restoration Policy
https://support.steampowered.com/kb_article.php?ref=9958-MJDG-3003

Apparently there's no recourse for items sent from your account because account security is the responsibility of the end user.

These are their "Account Security Recommendations".
https://support.steampowered.com/kb_article.php?ref=1266-OAFV-8478

They also said "In addition, we are unable to recover any friends or Community groups that have been lost or deleted."

I have quite a lot of items lost now. I'll be making a note of it and seeing how things go.

*EDIT*
So after taking a tally - it's 12+ games and 200+ tradable items. These were amassed over years since I've been with STEAM from.....forever. Was introduced to HL1 and CS way back before competitive online gaming was a thing - back when you had to go to venues to have any kind of competition - back when we had dial-up. While it doesn't harm me personally, the part I'm most upset about is the contacts. The items I can probably buy if I REALLY wanted them out the market. The games I had in my inventory for friends - old or new. Not sure if you're aware, but STEAM had a policy where you can't add friends unless you have one paid game in your list. Not sure what it is like now, but that was the purpose of the extra games in my list.

Games lost include:
The Last Remnant™
Terraria
Skullgirls 2nd Encore
Prince of Persia®
PAYDAY™ The Heist
Onikira - Demon Killer
Machinarium
Far Cry® 2
ComiPo! Highschool Starter Pack
Broken Sword Trilogy
Alien Breed™ Trilogy
Age of Empires II (2013)

These were held in storage for trading as I said. Items? Well now...

-Torchlight II, Chivalry: Medieval Warfare, Reus, Dead Island Riptide, Aiai, Eggman, Shadow, Witch, Smoker, Hacker Concept, 「Shen Woo」, 「Clark Still」, 「K'」, 「Ash Crimson」, 「Kim Kaphwan」, 「Ralf Jones」, Beach, Outlander, Dark Knight Detective, King of the Seven Seas, Emerald Knight, Amazon Princess, Night's Edge, Mr. Crow, Xan, Through the Flames, Explosive, Pool Repair, Need a Doctor, 「NESTS-style Kyo」, 「Robert Garcia」, 「Mr. KARATE」, Frost King Spotting, Pink Knight vs. Painter Boss, Beefy Sandwich, White Pawn (Foil), White Pawn, Black King, Black Knight, Black Pawn, ASHIGARU, VANGUARD (Trading Card), JIRO (Trading Card), Skaarj, Behemoth Concept, Berserker, Embermage, The Arsenal, The Wilds, Walrut Head, Kit Ballard, Allied Assault, Allied Sniper, Axis Panzerschreck, Hooning Is Not A Crime, Sno* Problem, DC Compound, Evil Goat, Three Horned Goat Jesus, Wistful, Chloe, Waka, Mikoto (Trading Card), Purna (Trading Card), Sam B (Trading Card), Zombie, Glowing Mushrooms, Living Wood, The Underworld, Night's Edge, The Skulk, TSF Marine, Special Ops Marine, The Fade, Gary Coleman, The Champ, X Dude, The Gang, Nyte Blayde, The Herald of the Walking Apocalypse, Oleg Kirrlov the Brute, Nyte Blayde, Witch-Bride of Achriman (Trading Card), Bio-Mechanoid, Antaresian Spider, Gnaar, Scarlet Pilot, Amber Pilot, Emerald Coalition Mecha, Nordic Ruins, Daedric Warrior, Daedric Warrior, Nordic Ruins, Fleshpound, Husk, Clot, Scrake, Vlad, Troll, Swarm Baron, Wizards, OSTRICH SLUG, Gal DONALD MORDEN, MARCO ROSSI, FIO GERMI, Monster in the shadows, US Sniper, US Sniper, HEAVY (Trading Card), ENGINEER (Trading Card), PYRO (Trading Card), MEDIC (Trading Card), MEDIC (Trading Card), Squigly, Cerebella, Filia, Valentine, Double, Wilson, Willow, Life Element, Shield Element, Lightning Element, Shinobi, Shogun, Shepherd, Hoarice, Shepherd, The Knight Rider, Castle Blood, Silence, Marked, We've Always Been Together, Combat, Masked, Battle vs Chess Booster Pack, No Transparency, The Magician's Joy, Mercy of the Saint, Vengeful Spirit (Trading Card), Tiny (Trading Card), Tiny (Trading Card), Riki (Trading Card), Dust: An Elysian Tail Booster Pack, Injustice: Gods Among Us Ultimate Edition Booster Pack, Tusk (Trading Card), Phantom Lancer (Trading Card), Vengeful Spirit (Trading Card), Vengeful Spirit (Trading Card), Stardust Vanguards Booster Pack, Gogeta, Frieza, Cell, T-Bone (Trading Card), Home Base, Everything is Under Control, F.A.N.G (Trading Card), Ryu/Ken, Necalli, F.A.N.G (Trading Card), Zangief, F.A.N.G (Trading Card), Dhalsim, Ryu/Ken, IDF, Arumat (Trading Card), Arumat (Trading Card), Myuria (Trading Card), Lymle, Lymle, Green, Ghost Android, Nakamura, Jacker (Trading Card), Blue, Red, Quirrel, Dung Defender, Hollow Knight (Trading Card), Broken Shell, Broken Shell, Battle vs Chess Booster Pack, INTERNATIONAL ROUNDHOUSE, CLASS A4 "MALLARD", SOUTHEASTERN CLASS 395, DiRT 3 Complete Edition Booster Pack, STAR OCEAN™ - THE LAST HOPE™ - 4K & Full HD Remaster Booster Pack, Schneider, Circuit To Success, The Comfort You Deserve, The Comfort You Deserve, The Duelist, Dactyl Riders, Centaur Man, Vile MK-2, MMXLC: Axl, Vile MK-2, The Duelist, PTOLEMY, AYA, JULIUS CAESAR, Cooked Meat, Guts, Trisha?, Ham Fisted, Grey Mother, Sorrow Pass, Kit Cat, Muscle Governor, Drakoth (Trading Card), Emilienator, Kit Cat, Governor, Kit Cat, Gilda Ire, Vladyn The 100 Demon Arm, Wyatt Goibniu, Battle vs Chess Booster Pack, Left 4 Dead 2 Booster Pack, Charlotte (Trading Card), Riesz (Trading Card), Shizuka, Magicka 2 Booster Pack, Dragon form, Dragon form, Frog form, [GGI] Sol Badguy, Eddie (Trading Card), Faust (Trading Card), Randi (Trading Card), Luka, Gemma (Trading Card), Randi (Trading Card), [GGI] Potemkin, Pip Holy Beast Form, It Was You!, End of the Line, Knife Way to Make Friends, Kwolok, Twillen (Foil Trading Card), Twillen (Trading Card), New Family Member, Opher, Ambush, Breach, Range Rover SVR, BMWI8, VW, Mammoth Tank, Masks On, Happy Forest, Happy Forest

And that's not everything. But these include items I spent time to acquire. Some I may not get back. So again - let's see how things go.
Legutóbb szerkesztette: Useless (死); 2023. okt. 22., 6:29
Useless eredeti hozzászólása:
Just putting it out there so others can be aware.

Here is a better awarness post:
Stop driving and texting, FFS.
Losing a few cheap items is way too low of a price you had to pay.
DC-GS eredeti hozzászólása:
Useless eredeti hozzászólása:
Just putting it out there so others can be aware.

Here is a better awarness post:
Stop driving and texting, FFS.
Losing a few cheap items is way too low of a price you had to pay.

♥♥♥♥♥♥♥ word!

I despise people that don’t give their driving complete attention. That is exactly how accidents happen.
Silicon Vampire eredeti hozzászólása:

♥♥♥♥♥♥♥ word!

I despise people that don’t give their driving complete attention. That is exactly how accidents happen.

LoL. Love the turn. Lemme be the troll. I text with both hands while driving. Been doing so for years. Not everyone has the dexterity. Should I mention I was also on calls with my office at the time? Attention divided. Fully concentrated on the road.

Let's see.....30 years of doing so with no accidents.

DC-GS eredeti hozzászólása:
Useless eredeti hozzászólása:
Just putting it out there so others can be aware.

Here is a better awarness post:
Stop driving and texting, FFS.
Losing a few cheap items is way too low of a price you had to pay.

Agreed. Texting and driving is not recommended.


As I've said repeatedly, but let me make it more clear. I'm not looking for sympathy. Everything can be bought back. I'm putting the info out so people can be aware and realize that there's no recourse from STEAM.

Cheers.
Legutóbb szerkesztette: Useless (死); 2023. okt. 22., 16:56
next time be careful
emr eredeti hozzászólása:
next time be careful

Yeah. The advice is typical cyber security stuff. Validate the link etc... If I were at my PC or laptop then I'd have seen the mistake in the spelling. URL didn't fully display in the phone browser. Work has also been hectic. To the point that a business partner is thinking of sending help from overseas. So looking at STEAM was last on my list before the weekend.

Got back a few friends and ran some CS Source off my VPS. So that's a plus. Now to plan a link up to wash away the issue.
Legutóbb szerkesztette: Useless (死); 2023. okt. 22., 17:28
Thank you very much for the warning but I have trust issues and sorta cannot be scammed - easily. :sadistpolite:
Wynters eredeti hozzászólása:
Thank you very much for the warning but I have trust issues and sorta cannot be scammed - easily. :sadistpolite:

Good stuff. And with the evolving methods in use it's best to be like that. Had two friends - persons I know personally - send similar links. That's what lowered my guard. Plus was driving between locations for work.

Won't be a second time for me. But hoping the lesson will be taken to prevent a first time for others.
I hope you are able to get everything back, the best of luck to ya.
But this is what I tell my family, wife, and daughters stop trying to do everything on ya cell.
There are only Three things I do on my phone, check my bank account log in with my fingerprint, through the Apple-provided app, I text, and make calls. I stay logged out of all web browsers. And will be installing Bitdefender on all cell phones, It has saved my rear many times on my PC.
< >
115/38 megjegyzés mutatása
Laponként: 1530 50

Összes téma > Steam fórumok > Help and Tips > Téma részletei
Közzétéve: 2023. okt. 21., 10:45
Hozzászólások: 38