Install Steam
login
|
language
简体中文 (Simplified Chinese)
繁體中文 (Traditional Chinese)
日本語 (Japanese)
한국어 (Korean)
ไทย (Thai)
Български (Bulgarian)
Čeština (Czech)
Dansk (Danish)
Deutsch (German)
Español - España (Spanish - Spain)
Español - Latinoamérica (Spanish - Latin America)
Ελληνικά (Greek)
Français (French)
Italiano (Italian)
Bahasa Indonesia (Indonesian)
Magyar (Hungarian)
Nederlands (Dutch)
Norsk (Norwegian)
Polski (Polish)
Português (Portuguese - Portugal)
Português - Brasil (Portuguese - Brazil)
Română (Romanian)
Русский (Russian)
Suomi (Finnish)
Svenska (Swedish)
Türkçe (Turkish)
Tiếng Việt (Vietnamese)
Українська (Ukrainian)
Report a translation problem
https://support.steampowered.com/kb_article.php?ref=1266-OAFV-8478&l=
People fall for phishing sites all the time, click links and enter their steam account details plus email information. Valve have many safe guards in places to protect users but some users choose too ignore the warning and end up being phished, hijacked and have infor stolen. End of the day, the end user is the weakest link in the chain.
That is just 1 method I saw being used.
1) Have the victim enter their login details (including Steam Guard code) on a fake login website
2) Log in on the real Steam website using these details (and before Steam Guard code expires)
3) Change their avatar and profile description to something threatening, usually something like: you are vac banned. then leave a note saying "you have 1 hour to trade your items" or something along those lines.
4) Now obviously no one wants a VAC ban so they send the trade over to another account (such as their alt)
5) The original trade gets cancelled and then a bot disguises himself as the exact name and picture as the receiver and sends another trade.
6) The user confirms the trade through their Steam Guard app and the trade is complete. The person doesn't even know what hit them.
Why is this so smart? Because it allows to bypass Steam Guard completely, of course. If they see some dodgy trade being made from the account, they are not going to confirm it at all. Instead, threaten the user and hi-jack the trade.
Honestly one of the most elaborate and smart scams I've seen
Right. They can't verify the trade without access to the user's phone, but they can scare the user enough to get them to trade their own items out and verify it for them.
But couldn't the same thing be accomplished by infecting the user's computer by tricking them into downloading something and then grabbing their login + steam guard? How do we know for sure which one is being done?
Because people put so much trust into these gambling sites and a lot of them also confirmed that they entered their details.
I started a game of Arma 3 and a few mins later I was contacted by an account named 'VAC BOT #9854', telling me my account will be banned or some stupid crap like that. https://prnt.sc/lbzffg
I realised this person must be on my friends list if he sent me a message so I checked his profile and noticed my avatar in the top right corner was gone.. so I went into my profile and saw that my name was changed to VAC BANNED.
I never log into any sites, share my passoword with or do any stupid things. I also use Mobile Authenticator so even if someone managed to get a hold of my password then they would have needed the code from my phone to access my account.
DO NOT TRADE YOUR ITEMS!
Your account was compromised.
Scan for malware. https://www.malwarebytes.com/
Deauthorize all devices https://store.steampowered.com/twofactor/manage
Change your password on a secure device.
Generate new back up codes.
Revoke the api key https://steamcommunity.com/dev/apikey
Password is changed. I have MalwareBytes and the scan didn't show any threats. I have also deauthorized all devices.