Este tema ha sido cerrado
【= ◈ ︿ ◈ =】 21 SEP 2024 a las 5:08 a. m.
Repeated account hijacking attempts.
A week ago, I got a notification in my messages (Screenshot[imgur.com]) that someone had attempted to break into my account. I got Steam Guard codes on my phone (which is bound to my account) which are in Russian. (I am also not Russian.) I was really confused as to how they broke into my account, but I didn't give it much thought and just changed my password.

(The one in English is me resetting my password on my new phone)

A few days after that, it happened again. This time, I was sure there was something more as the password I used was a randomly generated one. I changed it again, and tried to see whether anyone else reported something like this but I only found an old 2015 password exploit and nothing else.

Then it happened again today, while I was out shopping. I changed it again, and got even more notifications even though I JUST changed it. Every single time it was a randomly generated password.


I was wondering if there's a way to report this to Steam directly or somehow stop this person from trying to access my account because it's driving me nuts.
Also, whether anyone else knows anything about this, please do tell me. None of my friends have had this happen to them recently, so I am completely clueless.

(I also apologize if this is the wrong place to post it in. If so, please tell me where I should drop this.)
< >
Mostrando 1-15 de 30 comentarios
peppermint hollows 21 SEP 2024 a las 5:41 a. m. 
Follow ALL of these steps:

1. Scan for malware. https://www.malwarebytes.com/
2. Check that the email and phone number on the Steam account are still yours.
3. Deauthorize all other devices. https://store.steampowered.com/twofactor/manage
4. Change passwords from a clean computer.
5. Generate new backup codes for your Mobile App. https://store.steampowered.com/twofactor/manage
6. Revoke the API key (there should be no key). https://steamcommunity.com/dev/apikey

In the future, avoid third party websites that ask for your Steam login as well as common scam vectors - such as "free 50$ gift card" or "Please vote for my team" "please vote for my workshop submission" and "I accidentally reported you." Even if these messages come from people who are on your friends list.
【= ◈ ︿ ◈ =】 21 SEP 2024 a las 5:59 a. m. 
Well, I already did all this the first time this had happened, and clearly it didn't help...
Also I'm not one to click on random links.

I scanned both my PC and phone already too.
Thank you though.
Dr.Shadowds 🐉 21 SEP 2024 a las 7:04 a. m. 
Are you using any add-ons for your browser? Or running weird things that interact with browser, or apps on your system.

Are you keeping things up to date?

Are you logging on other devices beside your own devices like schools, cafes, or etc?

Did you ensure you change password for your email?

When you said you did all the steps are you sure you didn't skip any? If you skip any then not really helping yourself.

There are endless scam sites online, they go out of their way to copy any site to try look real as them to the smallest detail to try trick you.

Discord has a problem where they allow people send spoof hyperlinks where people fall for scams easier. As well can easily send viruses if download & run them as they can lie to you what the file about.

There lots of scam trading/gambling sites claiming to be legit, as well fake ones of them as well via search results, there also scams on trading/gambling sites where they be legit, but do a switch on you when get used to them to trick you into logging into fake Steam page.



Lastly ensure the stesm app if using steam chat app too also ensure, isn't having issues for language for settings either local side, and account side both are separate just incase if it was a setting, and you got a notification for something else. Scammers can change language settings if they got on the account, and then sync to local app settings afterwards which why check both settings.



If you share your account with others then there good chance that someone screwing up. If someone using your browser to login to sites using your Steam account that also be a problem such as those auto fillers.
【= ◈ ︿ ◈ =】 21 SEP 2024 a las 9:28 a. m. 
The addons I use for my browser are uBlock Origin, Privacy Badger, a Youtube video downloader and Return Youtube Dislike.

I am keeping things up to date.

I log in from work sometimes, on my phone, but the router has a password.

I changed my e-mail password when this first happened, just to be sure, as it was the same as my steam account. My Google account didn't report any connection attempts.

I was really anxious when this first happened, I just redid everything on that list, one by one, again... It might've been the backup codes maybe.

I didn't access any sites out of the ordinary in a while. The only sites I accessed lately are Youtube, Google Keep, Gmail, Scrap.tf, backpack.tf and 3 wiki sites for Arknights, Limbus Company and Minecraft respectively, all of which are bookmarked in my browser.

I didn't click on any weird discord links either (in fact I only use discord to talk with 3 friends and I have non-friend DMs closed)


Whoever tried to hijack my account managed to enter in my password shortly after I changed it, on my phone, which is what I find weird
I'll let you guys know if it'll show up again btw. Thank you for help.
【= ◈ ︿ ◈ =】 22 SEP 2024 a las 1:04 a. m. 
(Screenshot[imgur.com])

It is still happening, even though I changed my password again.
I woke up today and saw these messages. At this point I believe there's multiple people who have seen some video posted by a Russian youtuber or something of the sort.

Are you guys sure this isn't some password breaking exploit? Again, if anyone would know where I could ask someone at Steam directly, or maybe an e-mail address, it'd be greatly appreciated.
StickyPawz 22 SEP 2024 a las 2:51 a. m. 
Publicado originalmente por 【= ◈ ︿ ◈ =】:
(Screenshot[imgur.com])

It is still happening, even though I changed my password again.
I woke up today and saw these messages. At this point I believe there's multiple people who have seen some video posted by a Russian youtuber or something of the sort.

Are you guys sure this isn't some password breaking exploit? Again, if anyone would know where I could ask someone at Steam directly, or maybe an e-mail address, it'd be greatly appreciated.

You were given six steps to follow in post#1 ... Yet you *only* mention changing your password.

Did you deauthorize all other devices?!

Did you generate new backup codes?!

Did you revoke any API key?!
【= ◈ ︿ ◈ =】 22 SEP 2024 a las 2:58 a. m. 
Publicado originalmente por StickyPawz:
Publicado originalmente por 【= ◈ ︿ ◈ =】:
(Screenshot[imgur.com])

It is still happening, even though I changed my password again.
I woke up today and saw these messages. At this point I believe there's multiple people who have seen some video posted by a Russian youtuber or something of the sort.

Are you guys sure this isn't some password breaking exploit? Again, if anyone would know where I could ask someone at Steam directly, or maybe an e-mail address, it'd be greatly appreciated.

You were given six steps to follow in post#1 ... Yet you *only* mention changing your password.

Did you deauthorize all other devices?!

Did you generate new backup codes?!

Did you revoke any API key?!

I did all those both the first and second times, yeah.
Which is what I find weird.

The only devices I have authorized are my PC and phone
I generated new codes already
And there wasn't any API key.
https://imgur.com/a/wgbqMmQ

Normally I try to solve problems like these on my own by looking things up but I had no clue what else to try, that's why I made this post.


edit: There was yet another attempt an hour ago.
Última edición por 【= ◈ ︿ ◈ =】; 22 SEP 2024 a las 3:00 a. m.
Aluvard 22 SEP 2024 a las 3:05 a. m. 
Publicado originalmente por 【= ◈ ︿ ◈ =】:

I did all those both the first and second times, yeah.
Which is what I find weird.

The only devices I have authorized are my PC and phone
I generated new codes already
And there wasn't any API key.
https://imgur.com/a/wgbqMmQ

Normally I try to solve problems like these on my own by looking things up but I had no clue what else to try, that's why I made this post.


edit: There was yet another attempt an hour ago.

Run some anti-vir software on your phone, then do steps 1-6 from another PC. Don't turn on your original PC or allow it to connect to the network.

If hacking attempts will cease, it means that there is deep-rooted malware on your PC and you need to do a factory reset.
【= ◈ ︿ ◈ =】 22 SEP 2024 a las 3:11 a. m. 
Alright, I'll run MalwareBytes on my phone.
I'll ask my girlfriend for her laptop tomorrow. And I'll send an update whether it keeps happening or not.

Thank you.
Home Appliance 22 SEP 2024 a las 5:14 a. m. 
Publicado originalmente por 【= ◈ ︿ ◈ =】:
a Youtube video downloader and Return Youtube Dislike

I'd uninstall those if i were you
Muppet among Puppets 22 SEP 2024 a las 6:34 p. m. 
What are the codes for? Translate each "reason".
You only get such sms in the situation you describe? Or other things too?
Was the one to create backup codes for you doing that?
Delete the images.
Jessy 23 SEP 2024 a las 12:40 a. m. 
Publicado originalmente por Muppet among Puppets:
What are the codes for? Translate each "reason".
You only get such sms in the situation you describe? Or other things too?
Was the one to create backup codes for you doing that?
Delete the images.
All the sms codes he gets (aside for backup) stand for "your confirmation code: ----", general Steam ones that are sent when try to login or purchase something through browser.
【= ◈ ︿ ◈ =】 23 SEP 2024 a las 1:02 a. m. 
Publicado originalmente por Home Appliance:
Publicado originalmente por 【= ◈ ︿ ◈ =】:
a Youtube video downloader and Return Youtube Dislike

I'd uninstall those if i were you

I just did this. Thank you.



Publicado originalmente por Muppet among Puppets:
What are the codes for? Translate each "reason".
You only get such sms in the situation you describe? Or other things too?
Was the one to create backup codes for you doing that?
Delete the images.

A russian friend of mine translated them, they are confirmation codes, pretty much Steam Guard.
Everything in English is me, everything not in English is not me.



Also I haven't tried doing anything else on my account and I haven't had any attempts for almost 24 hours.

I remember changing my password on my phone when I was out shopping, and then I got another notification (Saturday, 13:10 and then 14:41). I was on mobile data when this happened.

I changed my password entirely without the use of my computer, but I don't remember whether the 14:41 attempt happened before I got back home and logged back in, or after.


Do you guys suggest I should factory reset both my phone and computer, after I try doing that list of steps from the first message?


edit: It just happened again, at 12:29 and 12:30
Última edición por 【= ◈ ︿ ◈ =】; 23 SEP 2024 a las 2:31 a. m.
【= ◈ ︿ ◈ =】 23 SEP 2024 a las 2:51 a. m. 
Alright, I did those 6 steps from a work laptop in the end. I think I am either getting paranoid or maybe my phone is at fault. I noticed it slowed down massively at some point, which shouldn't happen because it's brand new, I have it for a month now...


edit: I should add this here perhaps. When I did this, I tried using the backup codes I generated last time, in place of Steam guard. I tried the first 3 and also the last one and neither worked. So I just logged in like normal with Steam Guard. Maybe this helps.
Última edición por 【= ◈ ︿ ◈ =】; 23 SEP 2024 a las 6:37 a. m.
Muppet among Puppets 23 SEP 2024 a las 2:32 p. m. 
Publicado originalmente por Jessy:
Publicado originalmente por Muppet among Puppets:
What are the codes for? Translate each "reason".
You only get such sms in the situation you describe? Or other things too?
Was the one to create backup codes for you doing that?
Delete the images.
All the sms codes he gets (aside for backup) stand for "your confirmation code: ----", general Steam ones that are sent when try to login or purchase something through browser.
No,
sms codes are only for things like changing phone number, changing steam guard, generating backup codes. Or other similar reasons.

Sms codes are not send if someone logs in with the password or for purchases.




Publicado originalmente por 【= ◈ ︿ ◈ =】:
edit: I should add this here perhaps. When I did this, I tried using the backup codes I generated last time, in place of Steam guard. I tried the first 3 and also the last one and neither worked. So I just logged in like normal with Steam Guard. Maybe this helps.
Backup codes are only valid as long as there were no changes to steam guard or new codes were created.
They are so to say a backup for one instance of steam guard app<--(!).
< >
Mostrando 1-15 de 30 comentarios
Por página: 1530 50

Publicado el: 21 SEP 2024 a las 5:08 a. m.
Mensajes: 30