Install Steam
login
|
language
简体中文 (Simplified Chinese)
繁體中文 (Traditional Chinese)
日本語 (Japanese)
한국어 (Korean)
ไทย (Thai)
Български (Bulgarian)
Čeština (Czech)
Dansk (Danish)
Deutsch (German)
Español - España (Spanish - Spain)
Español - Latinoamérica (Spanish - Latin America)
Ελληνικά (Greek)
Français (French)
Italiano (Italian)
Bahasa Indonesia (Indonesian)
Magyar (Hungarian)
Nederlands (Dutch)
Norsk (Norwegian)
Polski (Polish)
Português (Portuguese - Portugal)
Português - Brasil (Portuguese - Brazil)
Română (Romanian)
Русский (Russian)
Suomi (Finnish)
Svenska (Swedish)
Türkçe (Turkish)
Tiếng Việt (Vietnamese)
Українська (Ukrainian)
Report a translation problem
1) you give me your account+password+2fa
2) I can now log into your acccount on steam
3) Immediately log in
4) THis immediately kick you out of your session
5) I launch Rocket League
6) I trade your items away in game
Note this doesn't require me to change anything on your end. I don't need to change the password, email, phone # etc. Since apparently all I have to do is log in to Rocket Leauge once I have your username/password+2FA, I can obliterate your inventory in 5 minutes it akes to log in and trade to my alt. At no point do I need ot change your credentials because its unnecessary for the goal.
Regardless they dont need to change the password to do the scam. Once you gave them your password and 2FA you were scrweed. I can add a friend launch RL and trade items within the time it take syou to figure out what the hell happened
Which I can do by my phishing sie taking your credentials and triggering the 2FA on it, then my fake site 'pretends' to trigger the 2FA window as well. YOu input the 2FA code, which passes it to my actual login, and presto I've logged in.
2FA is not designed to protect against phising attacks
Note this basically means they just send your SteamID64 to the site. It does not mean "you" should send them your 2FA code. You will never be prompted to enter that except to login to Steam.
Also note if you are logged into Steam there is no need to login again via a website (you get a button to say that you are logged in correctly from the cookie information Steam already has). Likely the website merely pretended to be a Steam login page.