Bonez Feb 20, 2024 @ 8:52pm
Friends account hacked
Hey this is super weird, but my friends account has been hacked, and they're messaging for me and my buddies to vote on a team logo that they supposedly made.. if you click the logo, it takes you to a website that essentially lets the hacker in to your steam account (looks like they're from moscow).

When i called him on it, he deleted me as a friend.. I'm worried my friends account is going to be tampered with even more (maybe deleted account or fraud purchases).

What can he do to mitigate damage here?? Is there anything I can do, like submit a ticket for him or something??

Any help would be greatly appreciated.

Thanks
< >
Showing 1-5 of 5 comments
JPMcMillen Feb 20, 2024 @ 8:57pm 
Report the account in question for theft/fraud/scamming. Support will get it sorted out and if the account was hijacked, they will lock it down till the real owner can recover it.
no154370 Feb 20, 2024 @ 9:07pm 
Hijacked, not hacked. You leaked your account credentials somehow.

Do not trade until your account is secured.

Take the following steps to secure your account:

1. Scan for malware. https://www.malwarebytes.com/
2. Check that the email and phone number on the Steam account are still yours.
3. Deauthorize all other devices. https://store.steampowered.com/twofactor/manage
4. Change passwords from a clean computer.
5. Generate new backup codes for your Mobile App. https://store.steampowered.com/twofactor/manage
6. Revoke the API key (there should be no key). https://steamcommunity.com/dev/apikey

Steam does not return inventory items or wallet funds: https://help.steampowered.com/faqs/view/3B6E-B322-2400-8D24

If you no longer have access to your account, read this:

How To Recover Your Account
A Guide for Steam
By: ▲ Ara ▽
This is a step-by-step guide on how to navigate the Steam Support Help page to recover an account that you no longer have access to.

p.s OP should do this as it is clearly shown that OP's Steam Account is also compromised as well.
Bonez Feb 20, 2024 @ 10:35pm 
thank you both for the help... happy to report, 2FA did its job this time.. his email was unable to be changed without it, and with his email still on the account, he was able to restore his account control by changing his password.

Glad this wasn't worse, cause it definitely could have been much so... Thank you Gaben.
JPMcMillen Feb 20, 2024 @ 11:03pm 
Originally posted by Bonez:
thank you both for the help... happy to report, 2FA did its job this time.. his email was unable to be changed without it, and with his email still on the account, he was able to restore his account control by changing his password.

Glad this wasn't worse, cause it definitely could have been much so... Thank you Gaben.
Tell him to do ALL the steps. Changing the password doesn't help if you don't deauthorize all devices first as a bot could still be logged in. And not removing API keys means someone could still be monitoring account activity.
Bonez Feb 20, 2024 @ 11:04pm 
Originally posted by JPMcMillen:
Originally posted by Bonez:
thank you both for the help... happy to report, 2FA did its job this time.. his email was unable to be changed without it, and with his email still on the account, he was able to restore his account control by changing his password.

Glad this wasn't worse, cause it definitely could have been much so... Thank you Gaben.
Tell him to do ALL the steps. Changing the password doesn't help if you don't deauthorize all devices first as a bot could still be logged in. And not removing API keys means someone could still be monitoring account activity.
good point, I will definitely let him know.
< >
Showing 1-5 of 5 comments
Per page: 1530 50

Date Posted: Feb 20, 2024 @ 8:52pm
Posts: 5