Steam Scammers
Hello there, sorry if I asked questions 'bout thounsand times asked by another ppl.

So thru several yrs of my experience in this platform, there's 2 method of scammers when they try to hijack our acc:
1. Accidentally report our Steam acc then asked us to contact them via Discord
2. Vote CSGO

My questions:
1. Is there any other scam method beside these?
2. How do I resolved the problem if my acc has been hijaced? My friend recently told me their acc has been hijacked for 'bout 6 hrs. What should they do?

Thx very much.
Alkuperäinen julkaisija: Jerry:
About the second one, tell your friend to do all these steps (a malware scan can also be recommended):

Deauthorize all devices https://store.steampowered.com/twofactor/manage
Change your password on a secure device.
Generate new back up codes. https://store.steampowered.com/twofactor/manage
Revoke the api key https://gtm.steamproxy.vip/dev/apikey
Check that the email and phone number on the steam account is still yours.
< >
Näytetään 1-10 / 10 kommentista
Tämän ketjun aloittaja on ilmaissut julkaisun vastaavaan alkuperäiseen aiheeseen.
About the second one, tell your friend to do all these steps (a malware scan can also be recommended):

Deauthorize all devices https://store.steampowered.com/twofactor/manage
Change your password on a secure device.
Generate new back up codes. https://store.steampowered.com/twofactor/manage
Revoke the api key https://gtm.steamproxy.vip/dev/apikey
Check that the email and phone number on the steam account is still yours.
About the first, there are many ways, phishing sites can be spread. The "vote my team" strategy is one, you already know. Also a popular one are "giveaways" in group chats. Or asking you to give a like to a picture. Or to check an inventory item. Anything, where a false Steam link can be snuck in. And then there is the load of external trading sites, with three malicious ones for one clean one at best. Don't get overly focussed on a specific approach.

If a Steam subpage asks for your login, although you are logged into the main page in your browser, be alert.
Viimeisin muokkaaja on Jerry; 4.2.2023 klo 13.00
Jerry lähetti viestin:
About the second one, tell your friend to do all these steps (a malware scan can also be recommended):

Deauthorize all devices https://store.steampowered.com/twofactor/manage
Change your password on a secure device.
Generate new back up codes. https://store.steampowered.com/twofactor/manage
Revoke the api key https://gtm.steamproxy.vip/dev/apikey
Check that the email and phone number on the steam account is still yours.

Thx U, but how 'bout if we don't have Steam Mobile Authenticator on?
Yukana2710 lähetti viestin:
Thx U, but how 'bout if we don't have Steam Mobile Authenticator on?

In this case, skip the step about backup codes. The other ones are still relevant. An API infection (the usual form of hijackings in the last 5-6 years) can be as harmful with or without authenticator.
Jerry lähetti viestin:
About the second one, tell your friend to do all these steps (a malware scan can also be recommended):

Deauthorize all devices https://store.steampowered.com/twofactor/manage
Change your password on a secure device.
Generate new back up codes. https://store.steampowered.com/twofactor/manage
Revoke the api key https://gtm.steamproxy.vip/dev/apikey
Check that the email and phone number on the steam account is still yours.

Ah, yes. Regarding API Key, when I clicked the link it says registering my API key. We only need to register our API Key when our acc is hijacked or should I do it too now?
You are supposed to REVOKE it. Unless YOU put one there VOLUNTARILY and not because someone told you to, the field should be empty.
Viimeisin muokkaaja on Pscht; 4.2.2023 klo 13.47
If you have to ask any questions at all about an API key, you shouldn't have any of them active at all.
OK, TYSM for the help guys :happypengy:
< >
Näytetään 1-10 / 10 kommentista
Sivua kohden: 1530 50

Lähetetty: 4.2.2023 klo 12.46
Viestejä: 10