Team Fortress 2

Team Fortress 2

278 ratings
"Spear-" Phishing: How to avoid and help stop phishing
By @err0r.function
How to recover phished items, avoid phishing scams, and stop phishers who try to scam.
   
Award
Favorite
Favorited
Unfavorite
Welcome / Phishing Basics
HELLO ALL, Welcome to my first guide.
I didn't want to make a guide, but this is still a problem, you probably know what I'm talking about. Phishing.

So how does phishing work?
Phishing is when a user adds you, then provides a link to a FAKE steam website.
You enter in your information, thinking you're logging into Steam, then BLAM! They have your Steam username and password, they steal your account, your in-game items, and in certain cases, your credit card info and email. Usually they come from a trade you bumped on OP with high-tier items, saying that their friend wants you to add them, but can't contact you. (I've been phish attempted 6 times in the last 3 days.)

Scary right? Yeah, I know.
Here's how YOU can stop it.
Recovering Phished Items
STEAM ADMINS CAN BE YOUR FRIEND
STEAMREP ALONE CANNOT HELP YOU

EH-HEM! According to Steam Support, "Immediately Contact Steam Support about the lost account
Provide the following information:
Steam account name for hijacked account
The original contact e-mail for the account
Select “Account Questions” as the category and “Hijacked or Stolen Account” as the subcategory.
Proof of purchase for the account as outlined below:
If retail software is registered to the account, attach a digital photo or scan of the CD Key registered to the account. Write your Support Ticket Number on the quick reference card or CD Key sticker below the code in permanent ink."
More information about recovering accounts can be found here.

So essentially, 'Who you gonna call? CALL STEAM ADMINS!'
Technically, Steam can see all chat logs, and all trade logs, so you don't necessarily NEED proof, BUUUUTTT, it makes you look more professional and this could be going on.
How To Avoid Being Phished
IF YOU THINK YOU MAY HAVE BEEN PHISHED, CHANGE YOUR PASSWORD AND ENABLE STEAM GUARD IF YOU HAVEN'T!!!

The most simple way to stop from being phished is reading closely. Being attempted phishing many times, patterns emerge, such as:
  • Often items misspelled in speech
  • User's profile is private
  • God Forbid, If you click the link, a legit one will say "Valve Corporation [US]" at the top left.
  • And most importantly, STEAM COMMUNITY IS MISSPELLED
And for the fun of it, I'll show some examples of attempted phisher against me.
How To Stop Phishers [STEAM REPORTING]
I'll step-by-step it for you.
MOST IMPORTANTLY, DO NOT REPORT TO STEAMREP, THEY NO LONGER HANDLE IT.

1) Screenshot the scam [Snipping Tool for Windows 7, comes stock.]
2) Visit imgur and create an account.
3) Upload your screen shot to imgur, then find the image URL for it. [Keep clicking on the image until you find something like this "i.imgur.com/######"]
4) Find the user's Steam Profile, and report them. [More>Report A Violation>Attempted Hijacker or Phishing>And put the image URL in the details box. Other details can be put here as well.]



Your report should look like this.

5) OPTIONAL: Block the user, so they don't attempt on you again.
"THANKS, FOR RIDE!!!!!!" - Heavy
"Thanks, and have fun." - Gaben, The Chosen One
But seriously, thank you for reading, and I hope this helps stop phishers in the future.

LIST OF PEOPLE WHO HAVE ATTEMPTED TO PHISH ME [All reported, don't worry.]:
[unassigned]
Deymos
Detective Auschwitz
Mellerup
Buying Botkillers!
pilingCHINESE
HEAVY_USER
BURNING FLAMES :3
BlackGold
WinniCoot [Youtuber]
(There's a lot more who've tried. Read below.)

I will continue a running tally, hopefully.

UPDATE 3/9/14 And at this point, with the 11th attempted phisher This week alone, and all the phisher greater than the number of Sharkers, Scammers (Different than Sharkers or Phishers, I may make a guide someday), and Illiterates COMBINED, I am done keeping tally, instead, check my Imgur page, I will have all screenshots I have taken, am taking, and will take there: My Imgur[soviettoaster.imgur.com]

UPDATE 3/13/14 At this point, I am done accepting blind adds for this guide. Above all, I am a trader, So if you like the guide, please comment and rate, and only add me if your buying something. My Outpost[www.tf2outpost.com] (I know I sound like an ♥♥♥♥♥♥♥, but now quite literally, the only people adding me are phishers and anti-phishers.) On a lighter note, we are currently the most popular TF2 guide on Steam, breaking 6,000 views! Thank you guys, and God Bless!

UPDATE Iam now getting adds for people who looked my OP trades, and didn't read my notes. Please. Read. DON'T ADD ME FOR ANY REASON. You will be blocked.

Remember, these are not real people, these are phished accounts, now made solely for a bot to plant phishing links everywhere.
283 Comments
thug 3 Mar, 2016 @ 8:40pm 
If you have Kaspersky antivirus,well, it will not allow you to go on that website. Kaspersky saved my ass.
Señor SaaS 24 Jun, 2015 @ 8:33am 
I never accept random friend requests, ever.
Skin 9 Feb, 2015 @ 1:04pm 
sometimes they put a "v" instead of a "y" in the community so it looks like: communitv ( i did not read it right and fort it was a y and i was close to clicking lucky i reread it i was close to losing all my items:kill:)
DireFash 6 Feb, 2015 @ 7:30pm 
Why don't 99% of people realize that they are bots and not real people D: . When you talk to them it does nothing. Many of them are victims of phishing and their account is being used by a bot
DireFash 6 Feb, 2015 @ 7:27pm 
I think I overlaughed when I saw "I will continue a running tally, hopefully" crossed out XD so true.
geometry 21 Oct, 2014 @ 12:43pm 
I almost cried at how sad that attempt was. :boomer:
Better luck next time, kiddo!~
geometry 21 Oct, 2014 @ 12:39pm 
I've had one of these maggots before, it was too obvious. the old 'trade' trick. I checked his profile, he only has football manager 2014. His name is russelcraxford. (I reported him.)
Polis Ranger 31 Jul, 2014 @ 11:15am 
I hate Phishers~:spycon:
Lil'Chinga 24 Jul, 2014 @ 8:46am 
omg, that account [unassigned] just tried to phish me today. and if that wasnt enough, there was 2 of them that sent me an invite at the same time
Julio Valiente 18 Jul, 2014 @ 11:26am 
ok thanks :) maybe i should scan my pc for virus since I entered a malicious site and attempted to download the steamguard.exe phishing software I guess.