• Please make sure you are familiar with the forum rules. You can find them here: https://forums.tripwireinteractive.com/index.php?threads/forum-rules.2334636/

Account Hacking Warning

slavek

Grizzled Veteran
May 4, 2006
3,059
943
UnrealEd: Viewport #1
Today I received a steam chat message from a well known member of the RO/KF community, it asked if I wanted to join a new steam group, I answered yes send me an invite, what was sent was NOT a steam invite, but a link to a website.

Some of my ingame friends clicked on the link and their steam accounts were stolen, as well as access into their msn and other email accts.

The full website address will not be posted so no one will click on it.

The adress looks like this http:// steamcommunity<Insert dbl digit # here>.tk

DO NOT CLICK ONTO THIS LINK IF YOU GET THIS MESSAGE!


Again, watch out for your account's security and don't fall into possible account scams/hackings.
 
yes, i was stupid enough to fall for this over a week ago...upon realizing my mistake (and when steam logged me off) i immediately contacted steam via there support page and email claim. They had my account back within 20 hours...THIS IS DANGEROUS people. Please make sure your email and steam passwords are different. As when i realized this, i went to my email only to find a captcha (which i have never seen). Also, link another email to your steam account with a completely diff pass as well. :confused:

My message was from a well known friend, who's account was hijacked...i followed his message link (which said something like "free games on steam [link]")

I have never fallen for a phishing scam until then...also all of my friends were deleted, so if any one would like to add me on here feel free to do so.

Also why i was writing this (i have been on vacation for a week) i noticed 3 new friend requests...all from the hijacker...this is one of them

http://steamcommunity.com/id/blajeR

if you see any of the text like designs you see in this previous link...do not accept...this was on my profile page and seems to be something that this hijacker is doing to all of his hijacked profiles.

Also, he is hebrew or from the middle east (i can tell from the writing), and doesnt speak english...after recovering my account, all my friends were his hijacked accounts (like 10 of them, and none of them i recognized), i have deleted them, as he kept sending me messages. One other thing, after i was hijacked i could see that my steam ID was online, and i watched this MOFO change all of my info, including my profile and pic...it was rather bothersome.

One last note, after i recovered my account and went online i noticed the hijacker was in a scrim match, i guessed the password, scrim123. I proceeded to go into his CS game (his prefered game) and team kill and get a little bit of internet justice until i was banned from the server (i ruined there game though atleast 4 rounds :p), one more thing, a couple of friends told me, my steam account was using aimbot and cheats in cs and was whoring the servers. This could have resulted in a VAC ban, but i was lucky and i wasnt...be careful people!
 
Upvote 0
Funny story. I had someone send me a similar link, and i wasn't sure what it was at first. I showed it to a friend (at the time) and asked him what he thought of it. I told him not to put in his info, but i guess he did. When i found out he did i told him he needed to change his password to steam asap. He refused (for whatever reason) and i got more forceful and direct. I guess he thought i was being a jerk, told me to **** off and signed off. His account got jacked the next day.
 
Upvote 0
To bad that the mentioned site looks like the Steam Community site, including the log-in forms.

To avoid any problems, open the site manually and login only if you're absolutely sure that you're on steampowered.com or steamcommunity.com

I for myself never got phised or scammed, but no one wants my account. I guess it's because i don't own Counterstrike.
 
Last edited:
Upvote 0
slavek, this was scotty right? you know if his account was hacked the same way? i heard it was an invite to a group, but not through a chatbox, but that's pretty dirty if the invite was coming from somebody on you're friends list through chat

the last time i saw a scammer going, the steam name was like "Steam Admin" or something and he would tell people that they had to submit their password/username in order to keep their account.....that of course is a dead give away, too bad some people were really dumb! :D

but this...this sounds really bad.
 
Upvote 0
Last time I was attempted to scam that the so-called 'steam admin' was WRITEING IN CAPS IN RAGE.

Obviously he wasn't fond of the idea that I played along :p

Hehe, they usually can't even write properly. "Hai my name is Andrew from staem support, we will giv ur stem accoun sum free gamez but u haev to registr to steam community page. ok? Plz kthx" :p
 
Upvote 0
I dont think i would have ever fallen for it, except that it came from a good friend of mine on my friends list and i know him in person...we play had played many nights in a row. And had exchanged in many conversations before. He has given me advice before, and has helped me with some issues on my comp...except for his account was hijacked, and the hijacker sent me the message. So there was a bit of trust coming from the user...you can see how this happen now.

All the message said was. "steam has free games, check it out on steam"

with the steam being the link, i clicked and read the address bar, it said something very similar to steampowered.com and the page was identical to the steam login page. Which i have used at least 20 times in the last year.

So dumb not exactly...and i think since i contacted steam ASAP (within 2 minutes of signing into the false page). It helped me recover it. My friend also recovered his account, and sent many apologies to me.

I have avoided many phishing scams before, but this one is rather slick...the page looks exactly like the steam page. And for whoever said that a message comes up for a non steam page? i did not receive such a message then or ever when some one has linked me to a page through steam chat. I guess i can laugh about it now, but imagine a message coming from someone you know in person...there was more trust than the average random steam friend.
 
Upvote 0
First things first.

NEVER EVER give your account password to ANYBODY. Valve doesn't need it. At all. Not even to fix your account. I once ended up with a broken steam account that Valve needed to log into locally to reproduce the bug. They did NOT need my password to do that. They just reset it themselves and log in. So NEVER give out your password.

Also, make use of the warnings when you are linked to a "steam" website. If it isn't steampowered.com or steamcommunity.com Steam will warn you that you are going to a non steam site. DO NOT PUT YOUR INFO IN THERE.

On that note, Valve will probably NEVER contact you through the steam friends system. If there is a problem with the account they just close the account and wait for the owner to contact steam support to clarify any issues that come up. To prove ownership of the account they will require proof of purchase (original receipt/box with key code/steam email receipt) of a game associated with the account. On that note keep in mind that Valve does not accept third party key seller keys as valid proof of purchase.

So moral of the story is, if two people know your password, it isn't secret. Keep it secret, keep it safe!
 
Upvote 0