AFKin May 22, 2024 @ 8:12am
CS skins sold not by me, Info needed
So some how some one managed to start selling my CS2 skins without logging into my account
I have ♥♥♥♥♥♥♥♥♥♥ and free crates you get from playing they managed to sell £3 worth before stopping. Trying to looking into this and the the people i found with the same problem have all used skin sites or what and have given out their info, i have never used a a site or logged in anywhere other than steam on PC and the app on my phone. What i find strange is where you can look and see where your account has been logged in from its just me, also the last time i traded on steam I had to use the app to confirm it, how have they got around this? i know what is sold is lost and i don't care about that what i care about is the future of my account and if anything i buy is at risk of being stolen. i have changed password done a malwarebytes scan. anything else i need to do?
< >
Showing 1-5 of 5 comments
magicISO Sweden May 22, 2024 @ 8:14am 
this what happens whne you use your steam login on third party sites say cs skin site
Nx Machina May 22, 2024 @ 8:16am 
Accounts are PHISHED because the end user gave away all their account details. The account name, the password and the KEY to the door, the Steam Guard Mobile code giving them access to the account.

How? by either logging into a known scam site or sites, tailored malware on your PC, the vote for my team scam, you have a pending ban scam on Discord, free knife click the link etc.

How does Steam (a program) know it is not you when all the account details are correct? It doesn't, therefore any action taken on your account is seen as you doing said actions.

The alternative is not plausible:

1) Someone would have to "GUESS" your account name from "millions of possible combinations".

2) Next they would have to "GUESS" your password from "millions of possible combinations" and then match it to your account name with "millions of possible combinations".

3) And finally they would have to "GUESS" the Steam Guard Mobile code "which changes every 30 seconds" to match both your account name and password to then have access your account.

Note:

1) Only you and Steam Support know your account name until you give it away.

2) Steam passwords are hashed, not stored therefore only you can give it away.

3) They physically need to have your mobile for the code, or you need to enter the code.


TRADE ONLY on Steam.


Do all the following NOW to secure your account.

1. Scan for malware https://www.malwarebytes.com/

2. Deauthorize all other devices https://store.steampowered.com/twofactor/manage

3. Change passwords from a clean computer

4. Generate new backup codes for your Mobile App https://store.steampowered.com/twofactor/manage

5. Revoke the API key at https://steamcommunity.com/dev/apikey (there should be NOTHING in the APIKEY)
Last edited by Nx Machina; May 22, 2024 @ 8:20am
AFKin May 22, 2024 @ 8:22am 
Originally posted by Nx Machina:
Accounts are PHISHED because the end user gave away all their account details. The account name, the password and the KEY to the door, the Steam Guard Mobile code giving them access to the account.

How? by either logging into a known scam site or sites, tailored malware on your PC, the vote for my team scam, you have a pending ban scam on discord, free knife click the link etc.

How does Steam (a program) know it is not you when all the account details are correct? It doesn't, therefore any action taken on your account is seen as you doing said actions.

The alternative is not plausible:

1) Someone would have to "GUESS" your account name from "millions of possible combinations".

2) Next they would have to "GUESS" your password from "millions of possible combinations" and then match it to your account name with "millions of possible combinations".

3) And finally they would have to "GUESS" the Steam Guard Mobile code "which changes every 30 seconds" to match both your account name and password to then have access your account.

Note:

1) Only you and Steam Support know your account name until you give it away.

2) Steam passwords are hashed, not stored therefore only you can give it away.

3) They physically need to have your mobile for the code, or you need to enter the code.


Do all the following NOW to secure your account and stop using 3rd party skin sites. TRADE ONLY on Steam.

1. Scan for malware https://www.malwarebytes.com/

2. Deauthorize all other devices https://store.steampowered.com/twofactor/manage

3. Change passwords from a clean computer

4. Generate new backup codes for your Mobile App https://store.steampowered.com/twofactor/manage

5. Revoke the API key at https://steamcommunity.com/dev/apikey (there should be NOTHING in the APIKEY)


Ok thanks for the reply i have done all the above to secure the account, i know i have not put my info anywhere i know you will not believe this because if the most common way but can you explain why there is no record of someone logging into my account other than me?
Nx Machina May 22, 2024 @ 8:43am 
Originally posted by AFKin:
Ok thanks for the reply i have done all the above to secure the account, i know i have not put my info anywhere i know you will not believe this because if the most common way but can you explain why there is no record of someone logging into my account other than me?

Your account details were captured hence why they could access the account.

All Steam a program does check if all the boxes are ticked and allows access.

Account name: :steamthumbsup:

Password: :steamthumbsup:

Steam Guard Mobile code: :steamthumbsup:

The scammer sits on your account and waits then strikes when they deem it worthwhile.
AFKin May 22, 2024 @ 8:51am 
Originally posted by Nx Machina:
Originally posted by AFKin:
Ok thanks for the reply i have done all the above to secure the account, i know i have not put my info anywhere i know you will not believe this because if the most common way but can you explain why there is no record of someone logging into my account other than me?

Your account details were captured hence why they could access the account.

All Steam a program does check if all the boxes are ticked and allows access.

Account name: :steamthumbsup:

Password: :steamthumbsup:

Steam Guard Mobile code: :steamthumbsup:

The scammer sits on your account and waits then strikes when they deem it worthwhile.

Oh well i hope they enjoy the £1.50 they made. as long as my account is now secure im happy
< >
Showing 1-5 of 5 comments
Per page: 1530 50

Date Posted: May 22, 2024 @ 8:12am
Posts: 5