Összes téma > Steam fórumok > Help and Tips > Téma részletei
Ez a téma zárolásra került
Am I Stupid: Steam Guard NOT Leaked but Account Hacked
Hey, friends. I'm new to the forum and would appreciate some discussion/healthy criticism.

My account got hacked one week ago, with the hacker clearing all my Steam Wallet balance and trying (but failing) to wipe out all my CS2 inventory. I logged in while he was listing my inventory items on the community market, so I reset everything before it was way too late.

Upon reflection, the most likely source of the security breach was that I downloaded malware from an unreliable website.

In my previous deleted post, the below statement received multiple doubts, but I stand by my words:

I never gave away my Steam Guard code or clicked any "confirm" before the account compromise, but the hacker had:

1. My Steam account;
2. Steam password;
3. My linked email account;
4. Email password; and
5. Control over my computer's C drive.

The key question: How did he manage to do all the filthy stealing without directly accessing my Steam Guard?

I am not able to prove myself of not doing certain things. Those "burden of proof" stuff, you know. Still, it was NOT a "vote for some team" incident - one key thing to note is that he did not trade all my valuable skins, but only bought and sold from the community market. For trading, confirmation is a must; for the community market, I'm not so sure.

Also, there was no change of credentials. My Steam was still linked to my email, and the password was not changed. That is not what a phishing scammer would allow unless he felt particularly merciful that day.

FYI, he first logged into my Gmail, my PayPal, then LinkedIn, Reddit...illegal transaction, harassing my friends, you name it. I had to call my bank and change passwords for 300+ different accounts. He made me reincarnate my stupid self after this. It was way bigger than some vote-for-team phishing scam.

The thing is, many other companies identified suspicious activity and helped me freeze my accounts there, including Amazon and Reddit, but not PayPal and, unfortunately, not Steam. I was not even by my phone when it all started, and when I checked my Steam Guard App, it appeared that over 100 more unrecognized devices were approved to access my account. I felt like a ♥♥♥♥♥.

How could he have done all those login approvals, let alone community market sales, if I had yet to give away my Steam guard information?

Also, could Steam's confirmation mechanism in the Community Market be improved? Sometimes, I need confirmation for a 0.5-dollar item, but a 10-dollar item is confirmation-free.

Moreover, selling a $0.04 skin for $200 is suspicious, at least, and should receive an automatic ban, stopping further transactions. That could save lives. Seriously.
Legutóbb szerkesztette: Mufaa; 2024. jún. 19., 19:12
< >
12/2 megjegyzés mutatása
Accounts are PHISHED not hacked because the end user gave away all their account details. The account name, the password and the KEY to the door, the Steam Guard Mobile code giving them access to the account.

How? by either logging into a known scam site or sites, tailored malware on your PC, the vote for my team scam, you have a pending ban scam on Discord, free knife click the link etc.

How does Steam (a program) know it is not you when all the account details are correct? It doesn't, therefore any action taken on your account is seen as you doing said actions.

The alternative is not plausible:

1) Someone would have to "GUESS" your account name from "millions of possible combinations".

2) Next they would have to "GUESS" your password from "millions of possible combinations" and then match it to your account name with "millions of possible combinations".

3) And finally they would have to "GUESS" the Steam Guard Mobile code "which changes every 30 seconds" to match both your account name and password to then have access your account.

Or please explain how in 19+ years i have never lost access to my Steam account and that includes before Steam Guard Email and Steam Guard Mobile existed.


Do all the following NOW to secure your account.

1. Scan for malware https://www.malwarebytes.com/

2. Deauthorize all other devices https://store.steampowered.com/twofactor/manage

3. Change passwords from a clean computer

4. Generate new backup codes for your Mobile App https://store.steampowered.com/twofactor/manage

5. Revoke the API key at https://steamcommunity.com/dev/apikey (there should be NOTHING in the APIKEY)
If you need help with Account Security or Recovery, please contact Steam Support.
< >
12/2 megjegyzés mutatása
Laponként: 1530 50

Összes téma > Steam fórumok > Help and Tips > Téma részletei
Közzétéve: 2024. jún. 19., 19:06
Hozzászólások: 2