LOST ALMOST 180$... help
so last day i downloaded something from github and its didnt worked and then after i left my pc open after fiew hours i found out that everything in my inventory got sold on market with a cheap price to not detect the confermation with steam guard ... and then they bought a realy cheap skin with all my wallet to get all that wallet
after seeing this all i did is clean install for my windows and forget to change password
then after a 20 hours this happen again now tho i did an anti virus and scannedd everything and now i changed my password and log off all the other devices from steam ...
whati want to know is how they even can do this without steam guard how they logged in to my account without steam guard or even reciving an email that a login attempt from other region
please someone expert in this tell me if there is anything else i need to do im so scared ...
< >
Beiträge 18 von 8
Hijacked. Through phishing or malware. Either way, it requires active input by the account holder.

If you still have access to the account:
Ursprünglich geschrieben von Crazy Tiger:
Phishing is the most likely cause, OP. When people get phished, they give out the account name, password and then active guard code. A bot quickly enters it and hijackers have access then. Ultimately 2FA is "just another code" that can be given away when getting phished. It's not a magical defense layer.

Have you secured your account? If not:
- Scan for malware. https://www.malwarebytes.com/
- Deauthorize all devices https://store.steampowered.com/twofactor/manage
- Change your password on a secure device.
- Generate new back up codes. https://store.steampowered.com/twofactor/manage
- Revoke the api key https://steamcommunity.com/dev/apikey

Find out how you leaked your credentials. Phishing and malware are the two ways it happens, phishing is the most likely one. Either way, find out how you leaked your credentials.

Items are gone, they do not get returned nor will you get money back for them. The item restoration policy: https://support.steampowered.com/kb_article.php?ref=9958-MJDG-3003

Not all items require confirmation. https://steamcommunity.com/groups/community_market/announcements/detail/1705067494681435160

If you don't have access to the account:
Ursprünglich geschrieben von Crazy Tiger:
Recover the account, use the guide: https://steamcommunity.com/sharedfiles/filedetails/?id=1126288560

Start here and don't be logged in on any Steam account: https://help.steampowered.com/en/wizard/HelpWithLogin
If Step 1 is not possible, proceed from Step 2. Along the way you can mention you don't have access to the email, phone, etc. Might need to enter a bogus one a few times to get that option.
At the end of the guide you'll make your ticket to Support. They'll tell you what proofs they want, often they ask first things (first email, first key activated on account, first payment method used, etc).

Do read up on phishing, as that's the most likely way to get an account hijacked. Malware is a second.
Ursprünglich geschrieben von Crazy Tiger:
Hijacked. Through phishing or malware. Either way, it requires active input by the account holder.

If you still have access to the account:
Ursprünglich geschrieben von Crazy Tiger:
Phishing is the most likely cause, OP. When people get phished, they give out the account name, password and then active guard code. A bot quickly enters it and hijackers have access then. Ultimately 2FA is "just another code" that can be given away when getting phished. It's not a magical defense layer.

Have you secured your account? If not:
- Scan for malware. https://www.malwarebytes.com/
- Deauthorize all devices https://store.steampowered.com/twofactor/manage
- Change your password on a secure device.
- Generate new back up codes. https://store.steampowered.com/twofactor/manage
- Revoke the api key https://steamcommunity.com/dev/apikey

Find out how you leaked your credentials. Phishing and malware are the two ways it happens, phishing is the most likely one. Either way, find out how you leaked your credentials.

Items are gone, they do not get returned nor will you get money back for them. The item restoration policy: https://support.steampowered.com/kb_article.php?ref=9958-MJDG-3003

Not all items require confirmation. https://steamcommunity.com/groups/community_market/announcements/detail/1705067494681435160

If you don't have access to the account:
Ursprünglich geschrieben von Crazy Tiger:
Recover the account, use the guide: https://steamcommunity.com/sharedfiles/filedetails/?id=1126288560

Start here and don't be logged in on any Steam account: https://help.steampowered.com/en/wizard/HelpWithLogin
If Step 1 is not possible, proceed from Step 2. Along the way you can mention you don't have access to the email, phone, etc. Might need to enter a bogus one a few times to get that option.
At the end of the guide you'll make your ticket to Support. They'll tell you what proofs they want, often they ask first things (first email, first key activated on account, first payment method used, etc).

Do read up on phishing, as that's the most likely way to get an account hijacked. Malware is a second.

all i did is formating my pc and scanned for malware its didnt detect anything and also i deauthorized all devices and changed the password but didnt generated a new back up codes scared they can get the guard i get in phone by typing it ...
The backup codes are on pc only. The phone does not get them.

On the other hand, if they created backup codes they can keep them until you create new ones. So better do that.

Also revoke the api key
Zuletzt bearbeitet von Muppet among Puppets; 30. Jan. 2024 um 8:45
Ursprünglich geschrieben von Muppet among Puppets:
The backup codes are on pc only. The phone does not get them.

On the other hand, if they created backup codes they can keep them until you create new ones. So better do that.

Also revoke the api key
i mean when i tried to generate the codes steam asked me to put a code i recive in my phone number and i recived it
Good. Then you know what the code was for
ShinsoX 30. Jan. 2024 um 11:17 
Ursprünglich geschrieben von Muppet among Puppets:
Good. Then you know what the code was for
so now since i did everything there is noway he can enter to my acc again ?
nullable 30. Jan. 2024 um 11:18 
Ursprünglich geschrieben von ShinsoX:
Ursprünglich geschrieben von Muppet among Puppets:
Good. Then you know what the code was for
so now since i did everything there is noway he can enter to my acc again ?

Well ultimately that depends on your ability to learn from your mistakes and keep your account secure in the future. Can you guarantee yourself that?
ShinsoX 30. Jan. 2024 um 11:19 
Ursprünglich geschrieben von nullable:
Ursprünglich geschrieben von ShinsoX:
so now since i did everything there is noway he can enter to my acc again ?

Well ultimately that depends on your ability to learn from your mistakes and keep your account secure in the future. Can you guarantee yourself that?
ofc i never tought i get a virus from github ! that why i downloaded from there blindly ! otherwise i wont !
< >
Beiträge 18 von 8
Pro Seite: 1530 50

Geschrieben am: 30. Jan. 2024 um 7:57
Beiträge: 8