I fell for a Phishing Scam. Not sure if I changed my password in time.
Man, after all these years of looking down on other people who fall for phishing scams, I fall for one myself. Luckily, I was able to detect something was off & I quickly changed my password before any damage was done, but still... now I feel like a hypocrite for dismissing phishing victims as computer illiterate newbies.

Anyways, THIS is the phishing site:
https:// steam communitcy. com/ redem wallet code/ 6 1 0 4 4 3 6 3
Looks legit at a quick glance, unless you REALLY pay attention to the URL.
I was caught off guard because the link came from someone who I trust & him giving me a $50 gift wouldn't be out of character for him.

At first I was like "Why the **** is this $50 gift card not going into my account?" & I kept trying to log in to the phishing site & it continued to give me error messages. I also recently got a new smart phone, but have not yet transferred ALL of the accounts for all of my apps over to the new phone yet, so naturally, I assume that the problem was just because the Steam Guard app was on my old phone. I then moved the app over & logged in on my new phone, but I still couldn't log into the phishing site.

At this point I was getting impatient & assume Steam was just being overly protective with their cumbersome authentication process, so I disabled receiving the Steam Guard code from the Steam app & opted to get the code by e-mail instead. I still had no luck logging into the phishing site. I then tried the URL on different web browsers & it wasn't until I finally tried the Microsoft Edge browser, did I get a phishing warning. I took another quick glance at the URL & wondered why it was setting off the warning by MS. It wasn't until I compared the URL of the phishing site with the URL in the Steam web browser did I finally notice the spelling error that my brain kept ignoring.

As soon as I was aware that it was a fake site, I quickly changed my password, & from what I can tell, nothing else in my account was changed, but I am getting a paranoid "what if" feeling now. Even if that scammer had been unable to make any changes to my account, is there any info that he could have copied & then use against me later?

Now I am trying to re-able getting the Steam Guard codes from the Steam app, but the new setting will not save. Currently it is stuck on "Get Steam Guard codes by email". Do you guys think this is the hacker's doing? I already hit the "DeAuthorize all devices" button after changing my password.

What do you guys think would be the worst case scenario here? :o
Last edited by United Healthcare; Sep 6, 2023 @ 9:20pm

Something went wrong while displaying this content. Refresh

Error Reference: Community_9734361_
Loading CSS chunk 7561 failed.
(error: https://community.fastly.steamstatic.com/public/css/applications/community/communityawardsapp.css?contenthash=789dd1fbdb6c6b5c773d)
< 1 2 >
Showing 1-15 of 20 comments
cSg|mc-Hotsauce Sep 6, 2023 @ 8:58pm 
You should really hold back posting the malicious link, even if you broke it up.

All steps, in order...

Scan for malware. https://www.malwarebytes.com/ (or with whatever)

Deauthorize all devices https://store.steampowered.com/twofactor/manage

Change your password on a secure device.

Generate new back up codes. https://store.steampowered.com/twofactor/manage

Revoke the api key (this should be empty) https://steamcommunity.com/dev/apikey

:summercat2023:
Last edited by cSg|mc-Hotsauce; Sep 6, 2023 @ 9:00pm
✨Saint✨ Sep 6, 2023 @ 8:58pm 
I think you should remove the link so other people do not fall for it, and honestly, after you have been 14 years on Steam, you should have known better.

:saint:
Some dude just messaged me offering help:

Originally posted by Funga Alafia:
[8:58 PM] Funga Alafia:
you got API scam bro?

[8:59 PM] Elon Musk:
what's API?

[8:59 PM] Funga Alafia:
api scam is like phishing scam bro
the scammer can still able to control your account

[9:04 PM] Elon Musk:
even after i changed teh pw & hit "de-authorize all devices" ?

[9:04 PM] Funga Alafia:
ya

[9:14 PM] Funga Alafia:
hey can i ask u

[9:19 PM] Elon Musk:
sure, ask away

[9:28 PM] Funga Alafia:
how did u get involved in phishing scam? or let say API scam?

[9:29 PM] Elon Musk:
got the link from a friend on steam

[9:29 PM] Funga Alafia:
and then?
can u explain everything to me what happen?

[9:30 PM] Elon Musk:
it went pretty much like what i typed out on the forum

[9:31 PM] Funga Alafia:
i cant find it already. like tell me what happen in the first place. like whos that friend? is that ur close friend in steam or what?
and why did u click the link? and after what happen the time u click the link?

[9:31 PM] Elon Musk:
I fell for a Phishing Scam. Not sure if I changed my password in time. :: Steam Community
https://steamcommunity.com/discussions/forum/7/3815166994146847110/

he's more a friend of a friend, but i've known him for like years already
i've been business with him too

[9:32 PM] Funga Alafia:
did he knew that the link he send is a scam?

[9:32 PM] Elon Musk:
like he sends me money & then i ship him asian food
i'm not even sure if it was really him. maybe his acct got hacked too
i know his FB acct has gotten hacked before

[9:33 PM] Funga Alafia:
did u fix ur account already?

[9:33 PM] Elon Musk:
i changed the pw & de-authorize all devices. IDK if that's enough

[9:34 PM] Funga Alafia:
still they can able to control ur account. and u know what? as of now that we are talking they can able to read all of our conversation
ur account needs to validate by a steam moderator bro. so it will be clean and also they can able to secure your account.

[9:36 PM] Elon Musk:
u got a guide handy?

[9:36 PM] Funga Alafia:
what do you mean?
i dont understand what u mean

[9:36 PM] Elon Musk:
step by step directions

[9:36 PM] Funga Alafia:
ohhh okay

[9:36 PM] Elon Musk:
i'm sure there's a guide somewhere on steam

[9:37 PM] Funga Alafia:
wait a sec. i know someone who can help you.
he is the one who help me also the time i got api scam
add this steam moderator for sure he can help you
Steam Community :: Solo
https://steamcommunity.com/id/anster/

and this is his discord
Solo Valve#5809
hope that would help brother

His profile:
https://steamcommunity.com/profiles/76561199177955521/

Last edited by United Healthcare; Sep 7, 2023 @ 12:43pm
Bloody Moon Sep 6, 2023 @ 9:55pm 
both are scammer, you have to follow only the guide above and stop. don't share anything with anyone.
Last edited by Bloody Moon; Sep 7, 2023 @ 1:47am
Bloody Moon Sep 6, 2023 @ 9:56pm 
in the last message he is directing you to another account but it is still the same scammer.
Bloody Moon Sep 6, 2023 @ 9:58pm 
do you really trust anyone too much? the guide above is the official links of your profile functions, nothing more!
Bloody Moon Sep 6, 2023 @ 9:59pm 
and this is a Steam moderator in your opinion?
https://steamcommunity.com/id/anster/
Bloody Moon Sep 6, 2023 @ 10:00pm 
this is a real steam moderator Valve employee
https://steamcommunity.com/profiles/76561199433024922

Report both of those accounts and send the chat screen to Valve while reporting and avoid third party sites, Valve will not be responsible for anything and you may even get a VAC if your account is stolen and cheated after stole all your inventory.
Last edited by Bloody Moon; Sep 6, 2023 @ 10:02pm
Do not log into given links or buttons.

Do not interact with random people claiming they do things with your account.
United Healthcare Sep 6, 2023 @ 10:09pm 
Originally posted by Candy Moon:
and this is a Steam moderator in your opinion?
https://steamcommunity.com/id/anster/

That's why I stop trusting him, but just in case he tris to guilt trip or gas light me, I would like to have a 2nd supporting opinion. I assumed a moderator would have some kind of badge or or icon next to his name or something.

I also thought he was gonna provide an official link, not just pass me off to another guy who's probably using a throw-away account.
Last edited by United Healthcare; Sep 6, 2023 @ 10:16pm
Bloody Moon Sep 6, 2023 @ 10:12pm 
However, you are responsible for account security, Valve will not refund any items stolen from inventory. You have the protection tools included steam guard, accessing third-party sites by entering your steam login outside Steam could compromise your account.
14 years on Steam and you know none of this? I've only been here for two weeks.
Bloody Moon Sep 6, 2023 @ 10:13pm 
Just report both, send chat screen to steam during report and block all 2 accounts because are scammers.
The "why" you should contact a random person was the red flag already.
Others were, discord, random person, etc
Bloody Moon Sep 6, 2023 @ 10:15pm 
follow the guide above and you will be calm, there must be no API key in the link, the box must remain empty because the API on external sites is used to steal your inventory via bots.
Bloody Moon Sep 6, 2023 @ 10:16pm 
this is a Real Valve employee https://steamcommunity.com/profiles/76561199433024922

and Valve have nothing to do with any esternal site nor discord.
< 1 2 >
Showing 1-15 of 20 comments
Per page: 1530 50

Date Posted: Sep 6, 2023 @ 8:52pm
Posts: 20