My steam and discord got hacked
I saw today that i had bought dota 2 items at the middle of the night, this wasn't me obviously as i don't have dota and i've never played it.

I did all the things you should do when something like this happens, i checked my pc for malware, reset my password, deleted my API key and all that.

Later that day when i was playing with my friends, one of them asked me "Bro, why did you just send me a steam giftcard scam link". I checked and saw that my account was being used like a fleshlight to send "____@ Steam gift 50$" scam links to all my discord friends.

I reset my password, took my pc offline, reset my emails' password (which i was using for both steam and discord). I've ran multiple scans of my system with none of them finding anything. I'm going to backup some stuff like images and videos on a usb stick, but after that i'm clearing my whole ssd just in case.

I didn't see anyone online who had both their steam and discord be the target of something like this, especially only hours a part so i wanted to post this incase anyone else has had a similar attack happen to them.
< >
Mostrando 16-30 de 36 comentarios
RPG Gamer Man 13 NOV 2024 a las 14:52 
Publicado originalmente por alphara:
my discord and steam got hacked, all items were sold and around 40 EUR of steam credit is gone. All the money was used to buy 3 cent dota2 items for 2-15 EUR each from 2 users.

1. Why didnt I get any emails about market activity? I always get an email even when I have bought/sold a 3 cent item. This time there was nothing.
2. How did they access my discord and steam account when I havent logged in anywhere with these 2 accounts nor have I clicked any suspicious links?

1. The people who hijacked your account probably changed the email to their own, so that way you get no emails on your email address.

2. There are several ways. They could of asked you to vote or click on a link, which you may have done and not remember. Or you went to a place to trade csgo skins where they got your information when you entered it.

Considering you play CS2 i imagine you went to a fake trading site. Always only trade on steam or learn the consequences the hard way.
Última edición por RPG Gamer Man; 13 NOV 2024 a las 14:53
Aluvard 13 NOV 2024 a las 14:57 
Publicado originalmente por RPG Gamer Man:

Can you explain exactly what happens in a session hijack? I would like to know more information about this.
If you want to dig into this topic, read this one and all associated articles.
https://owasp.org/www-community/attacks/Session_hijacking_attack
RPG Gamer Man 13 NOV 2024 a las 14:58 
Publicado originalmente por Aluvard:
Publicado originalmente por RPG Gamer Man:

Can you explain exactly what happens in a session hijack? I would like to know more information about this.
If you want to dig into this topic, read this one and all associated articles.
https://owasp.org/www-community/attacks/Session_hijacking_attack

Thank you. I like to learn about how they are done so i can avoid them.
alphara 13 NOV 2024 a las 15:05 
Publicado originalmente por RPG Gamer Man:
Publicado originalmente por alphara:
my discord and steam got hacked, all items were sold and around 40 EUR of steam credit is gone. All the money was used to buy 3 cent dota2 items for 2-15 EUR each from 2 users.

1. Why didnt I get any emails about market activity? I always get an email even when I have bought/sold a 3 cent item. This time there was nothing.
2. How did they access my discord and steam account when I havent logged in anywhere with these 2 accounts nor have I clicked any suspicious links?

1. The people who hijacked your account probably changed the email to their own, so that way you get no emails on your email address.

2. There are several ways. They could of asked you to vote or click on a link, which you may have done and not remember. Or you went to a place to trade csgo skins where they got your information when you entered it.

Considering you play CS2 i imagine you went to a fake trading site. Always only trade on steam or learn the consequences the hard way.


1. Ok now I remember that I went to a fake trading site through twitch stream a long time ago (at least 6 months ago) took a few seconds to realize my mistake and changed my steam password back then. Could this still be the same thing that now finally got me?

2. Then I didnt get hacked through discord but through steam? and then somehow discord started sending some 50 dollar gift links to people? My discord and steam are not connected by the way.

3. Could anything else be compromised? Should I be worried that the hacker could also access my bank account or any other account that I access through my browser?
Muppet among Puppets 13 NOV 2024 a las 18:37 
If several accounts with different passwords are accessed,
your computer might be infected.
Azel 17 NOV 2024 a las 7:26 
i had same issue today, i was hacked, however you dont get any notification if your friend gets a message from "You" until some of my friends replied to me why i send a message about gift activation link which was obviously a scam and according to the date this message was already one hour old when i saw it by myself.
i hope changing ps works.
Última edición por Azel; 17 NOV 2024 a las 7:29
alphara 18 NOV 2024 a las 11:20 
Publicado originalmente por Azel:
i had same issue today, i was hacked, however you dont get any notification if your friend gets a message from "You" until some of my friends replied to me why i send a message about gift activation link which was obviously a scam and according to the date this message was already one hour old when i saw it by myself.
i hope changing ps works.
I formatted all drives just in case as well, because I think I had some malware on my PC that used my browser to do all the unwanted things
Sora 16 DIC 2024 a las 9:32 
My account was getting hacked too, same as you discord and steam
Sora 16 DIC 2024 a las 9:32 
Did your problem solved? What should I do for now
alphara 17 DIC 2024 a las 12:38 
Publicado originalmente por Sora:
Did your problem solved? What should I do for now
I formatted all of my drives and then reset all passwords, stolen money and items are unfortunately gone forever :(
Eccentric 9 ENE a las 16:20 
My friend was emailed saying he was going to be exposed and have his info sold unless he sent him $1100 and was sent a picture of his desktop and files
HE❌EN 9 ENE a las 16:45 
Publicado originalmente por Eccentric:
My friend was emailed saying he was going to be exposed and have his info sold unless he sent him $1100 and was sent a picture of his desktop and files
And... does "your friend" think that this is true?
Publicado originalmente por Eccentric:
My friend was emailed saying he was going to be exposed and have his info sold unless he sent him $1100 and was sent a picture of his desktop and files
Let us humor this and say this is real, that someone was sent pictures by someone else of their desktop and files. The first thing you do is find a topic from last year on Steam forum to post on for your first time regarding something that is unrelated to steam? I feel it isn't your friend who was sent this as much as it was you.
Rocksuperstar 20 MAR a las 11:37 
This has happened to me a couple of days ago, exactly the same, reported the account it had awarded gifts to when my bud clicked on the link, but I have LITERALLY no idea how some pikey scrote would've got into it. I haven't downloaded freaky midget pr0n in weeks... okay, days... but my point stands.

Scrubbed all devices, changed passwords on Steam, Discord, Email account associated to both, already had 2FA enabled - properly stumped, I really haven't a clue.
KalGimpa 20 MAR a las 11:49 
Publicado originalmente por Rocksuperstar:
This has happened to me a couple of days ago, exactly the same, reported the account it had awarded gifts to when my bud clicked on the link, but I have LITERALLY no idea how some pikey scrote would've got into it. I haven't downloaded freaky midget pr0n in weeks... okay, days... but my point stands.

Scrubbed all devices, changed passwords on Steam, Discord, Email account associated to both, already had 2FA enabled - properly stumped, I really haven't a clue.

first

sorry it happened, partner

second

make sure to follow everything in the second response

as to the how

phishing is the number one way people are losing their accounts

and not just here at steam

people get tricked through giveaways or threats into giving their info away

it could be a virus or keylogger or the like

but phishing is the big thing
Última edición por KalGimpa; 20 MAR a las 11:50
< >
Mostrando 16-30 de 36 comentarios
Por página: 1530 50

Publicado el: 14 SEP 2024 a las 13:46
Mensajes: 36