Accounts hacked, bug or what?
I was watching tv with my wife when i got an email saying i've just managed to order 50€ as credits to my account. And of course i haven't done anything like that.

When i checked my acco, there was message telling something like "donations not possible since card used is old" or something like that. Looks like someone tried to gift theirself something.

Without telling my whole life story here i must say, that there's no real possibility that anyone knows my passwords etc. Also the kids have transformed as old gamers ages ago so no spanking for them peskies coming either. Also no active subscriptions in years. No old computers sold with account information. Practically no other way to do this than raw power (12 digit pw) or worker gone bad.

Any ideas of what's going on? Anyone else experiencing this kinda oddity?
< >
Showing 1-9 of 9 comments
Somehow your account login details were leaked out. You need to re-secure your account and then determine what if anything you or someone else with access to the account gave the login details away.
Accounts are phished not hacked.

You gave away all your account details.

The account name, the password and the KEY to the door, the Steam Guard Mobile code giving them access to the account.

How? by either logging into a known scam site or any off steam item sell sites, fake steam log-in websites, or by tailored malware on your PC, the vote for my team scam, you have a pending ban scam on Discord, free knife click the link etc.

How does Steam (a program) know it is not you when all the account details are correct? It doesn't, therefore any action taken on your account is seen as you doing said actions.

The alternative is not plausible:

1) Someone would have to "GUESS" your account name from "millions of possible combinations".

2) Next they would have to "GUESS" your password from "millions of possible combinations" and then match it to your account name with "millions of possible combinations".

3) And finally they would have to "GUESS" the Steam Guard Mobile code "which changes every 30 seconds" to match both your account name and password to then have access your account.

--------------------------------------------------------------------------------------------------------------------
Your account was phished / hijacked. Follow steps 1- 8 to secure your account:

1. Scan for malware https://www.malwarebytes.com/

2. Check that the email and phone number on the Steam account are still yours.

3. Deauthorize all other devices https://store.steampowered.com/twofactor/manage

4. Change passwords from a trusted/clean device.

5. Generate new backup codes for your Mobile App https://store.steampowered.com/twofactor/manage

6. Revoke the API key https://gtm.steamproxy.vip/dev/apikey (there should be nothing in the APIKEY)

7. Make sure your steam recovery email account is secure and still accessible.

8. Do a PW reset to recover any steam points spent in last 14 days.

Steam will NOT return lost funds or Items.

If any lost items are from a Trade Protected game, you might be able to recover them. See:
https://help.steampowered.com/en/faqs/view/365F-4BEE-2AE2-7BDD

------------------------------------------------------------------------------------------------------------------------
Because you were phished on your computer. They grabbed the session token from that 30 second 2fa code, along with your login info. that is the only way. with all 3 parts of the key, they could use that at any time to log in as you, since they had the 2fa session token code, steam thinks it is you.

The only way to get all 3 parts of the key is from your computer, you were phished.

https://help.steampowered.com/en/wizard/HelpWithAccount

To begin a account recovery (Lost / Stolen) Follow these steps:

https://gtm.steamproxy.vip/discussions/forum/7/601905007519865294/?tscn=1747857836

-----------------------------------------------------------------------------------------------------------

Things to avoid

-----------------------------------------------------------------------------------------------------------

1. Steam Agent -- no such thing exists. Valve will not contact you outside of a yellow/red notification bar in your Steam client. The only exception is when they are emailing multiple people about a very specific issue. Valve will never contact you through Discord, Twitter, Facebook, Steam Chat, etc.

2. Steam needs to verify that I am the owner of my account. -- When Steam support needs to do that, it will be in direct response to a question you have sent them or as asked for via a red notification in your Steam client, and they will tell you specifically what they need to prove ownership.

3. I asked for a legit proof so I received e-mail with some issue number. -- Steam support will not email you when asking for proof of ownership. This is done entirely via the ticket system.

4. I was told that I need to accept all my cs2 items trade to a temporary account. -- Valve will never ask you to do this. This is a classic trading bot scam. These items are lost forever. Steam support will not return them.

5. I was told my items would return by Thursday, 05.06 -- Again, classic scam. You were given a date so they had more time to get away with it.

6. Yesterday I wrote to Steam support and I see now, that my Question was closed with no answer. -- This is an indicator that the person who scammed has direct access to your account.

7. Any offsite skin / item trade sites.. they are scammers. any non steam website that you use and login with your steam credentials is a bad place...
wau 19 hours ago 
Originally posted by rawWwRrr:
Somehow your account login details were leaked out. You need to re-secure your account and then determine what if anything you or someone else with access to the account gave the login details away.

I am absolutely only one knowing that user and pw. Residents in this house are 2 x dog and 1 wife. All old(ish) All three have absolutely no idea how, not to mention motive, to do this. Only neighbour in possible wifi range is a couple ovet their 70's.

I have no clue, how i could've leaked those out.

Changed pw of course and also took that card off from payment methods. What i need to know now, is from what i need to protect myself from. I wasn't born yesterday, so security basics are not strangers to me. But this is something else. Something weird is going on.
wau 19 hours ago 
Originally posted by pckirk:
Accounts are phished not hacked.

You gave away all your account details..

Thank you for your long answer. However...

I'm not going to take that apart and answer "no" to all parts of the message. Just telling, that i have never used any services of trading anything, all account-related links are to other game services and i am way too old to even take part in trading these useless-to-me game cards 'n' stuff.

That's - btw - why i can't tell, if something is stolen. All i know, that someone/-thing transfered 50€ to credits account while i wasn't even near this puter. Why and how, no clue. I think it is related to the possibility to gift people.

And i do know that unless chinese marketing places (like Aliexpress etc) are capable to do phishing like that, there's no possibility whatsoever for me to manage giving account info away. And if they do, why bother to steal just 50€? That's not the limit of my bank account.

_____________________________

(i just had to come and edit this message. Just look how i fail later in this thread ;D )
_________________

No Steam app in my phone either. One steam, one puter, one user.


It can be a hiccup in Steam's systems. If more people experience this, we'll know. I've contacted support but nobody is awake.
Last edited by wau; 16 hours ago
The ONLY way to get into your account is for you to give away your log in info.... Malware or Phished.
wau 18 hours ago 
Oh crap!! There is one possibility...

For giving it away i mean. Appears i am, or at least may be, a simpleton after all. 3-4 weeks ago ...

>be me
>notice Starfield crashing (again)
>search internet
>find some answers
>among those link to real steam forums
>click
<due naugtynaughty content log in
>done'd
<lost the game

If this was enough for phishing (usually i don't click links on reddit and stuff at all), i'm to blame. Believeable looking link going to official steam forum and 30 years internet history on completely zero mistakes so far letting me to believe that of course i am safe.

Ah well.

Btw why Steam acts like i have Steam app in my phone? I don't.

I really, really need an update to my routines and perhaps relearn online security.
wau 18 hours ago 
...or a virus found in recently downloaded chinese microscope app called wiewplaycap.

Funny. Scanned that with Microsoft's own, but nothing. Now with Malwarebytes 5 bingo's related. Guess i'll just have to pay them...

I really, REALLY need to update my behaviour in internet. Seems that i've been arrogant. Seems it is nothing like it used to be...
Last edited by wau; 18 hours ago
the worker do be going bad oh lord yes, but, in this case it's probably just your phone or your computer be going bad in 2018 or so. and not long for to be gone bad if not already ever since.
wau 16 hours ago 
Originally posted by Realigo Actual:
the worker do be going bad oh lord yes, but, in this case it's probably just your phone or your computer be going bad in 2018 or so. and not long for to be gone bad if not already ever since.

Nah. Appears that it was just me gone bad. Old that is. By reading whole thread it'll come obvious.

I could save myself from further embarrasment and make this thread disappear. But in case someone else fails, i'll keep it here.

For some reason new thread about stolen account just appeared. Maybe i'm not the only fool in here.

BTW: My tech is up to date.
< >
Showing 1-9 of 9 comments
Per page: 1530 50