Install Steam
login
|
language
简体中文 (Simplified Chinese)
繁體中文 (Traditional Chinese)
日本語 (Japanese)
한국어 (Korean)
ไทย (Thai)
Български (Bulgarian)
Čeština (Czech)
Dansk (Danish)
Deutsch (German)
Español - España (Spanish - Spain)
Español - Latinoamérica (Spanish - Latin America)
Ελληνικά (Greek)
Français (French)
Italiano (Italian)
Bahasa Indonesia (Indonesian)
Magyar (Hungarian)
Nederlands (Dutch)
Norsk (Norwegian)
Polski (Polish)
Português (Portuguese - Portugal)
Português - Brasil (Portuguese - Brazil)
Română (Romanian)
Русский (Russian)
Suomi (Finnish)
Svenska (Swedish)
Türkçe (Turkish)
Tiếng Việt (Vietnamese)
Українська (Ukrainian)
Report a translation problem
Do NOT trade any of your item to anyone and do not attempt to trade anywhere as yet.
You need to follow all of these steps in this exact order...
1) Scan for malware. https://www.malwarebytes.com/
2) Deauthorize all devices https://store.steampowered.com/twofactor/manage
3) Change your password on a secure device.
4) Generate new back up codes. https://store.steampowered.com/twofactor/manage
5) Revoke the api key https://steamcommunity.com/dev/apikey
Most common reason people get accounts hijack for any service really are as followed.
- Sharing account infomation with others.
- Logging in on phishing sites.
- Downloading / Installing Virus / Keylogger on your system.
- Using public devices that has keyloggers, such as cyber cafe, school computers, and etc...
- Storing your login credentials on a unsecured service that others has access to view.
- Using same login credentials for all your things, or using same login credentials on another service that had a data leak. Yes it does matter because even if it not related to Steam, if using same login credentials, hijackers will try to use those credentials to see what services you use with those credentials. https://haveibeenpwned.com/
We're getting a lot posts about it in our Discord server and on the subreddit of r/Steam.
On the main forums here, a lot of other users are giving away their account details as well.
¯\_(ツ)_/¯
Yes please ensure to follow the steps that Robin3ak provided above, and read my post below his steps which explains the most common reasons why people get their account hijacked.
They usually get it when you log in via the page and supply it right there.
2FA is really moot when you give away your auth code.
It does its job when someone just has your account name and password.
^Exactly.
if you had 2fa for Steam on email, then it was phishing/malware or compromised email account.
if you had 2fa for Steam on mobile, then it was phishing/malware.
it really is mostly that simple
you had mobile authenticator? then you gave your credentials away, including the guard code. from that point there are many different attacks and scams that can be done.
they can overtake your account,
they can pressure you into doing trades via various methods (one you encountered),
or they use the silent variant and just wait for you to do a trade yourself.
all in dozens of variants.