3rd Time Hacked (after "too many resquests" in Market and Inventory)
So
My account was hacked for the third time, and the money in my wallet was gone.

The hacker spent it on Dota items, for a large amount of money compared to their actual value..

I use antivirus software, I don't use third-party apps, I only log in through the Steam app, I don't log in through browsers, I use Steam Guard, I change my email and account passwords regularly, I always check everything, and I follow security recommendations to the letter. I don't know what else to do.

Interestingly, I was having trouble accessing the Marketplace and Inventory, with a "too many requests" warning for a few days. I tried to space out access, but it didn't work.

I contacted Support, and one of the recommendations (among others) was to try switching networks.

I did this, and as soon as I switched networks, it worked; I was able to access the Marketplace and my Inventory. However, at the same time, purchases were made automatically.

The other two times (1year since the last one) my account was hacked, most of my inventory items were sold at a rock-bottom price (I had a R$72/$13.28 item sell for R$0.08/~8 cents. All of this is irretrievable, of course) and then the valor used to also buy Dota itens (don't know if it's a coincidence or not).
This time, also, I saw the action in live. Was using my Steam app on celphone, and saw the trades/sales/purchase. Could stop it, but so many items and money was already gone....

Fortunately, currently, you need to confirm your purchase in the mobile app before making a sale, but the same doesn't apply to purchases on the Marketplace.

As I said, I follow the security recommendations to the letter (include, I regulary check my email security settings). I don't know what else to do to avoid being robbed.

I'm more and more frustrated with Steam security, don't know if I am the problem, and be more frustrated that can't refund these sales/purchases.
< >
Showing 1-3 of 3 comments
PS: Oh yeah, and I'm not able to see with who player/id/account those Dota items came from. In som cases, I'm not even can see who bought my Items.
pckirk 22 Aug @ 2:44pm 
Accounts are phished not hacked.

You gave away all your account details.

The account name, the password and the KEY to the door, the Steam Guard Mobile code giving them access to the account.

How? by either logging into a known scam site or any off steam item sell sites, fake steam log-in websites, or by tailored malware on your PC, the vote for my team scam, you have a pending ban scam on Discord, free knife click the link etc.

How does Steam (a program) know it is not you when all the account details are correct? It doesn't, therefore any action taken on your account is seen as you doing said actions.

The alternative is not plausible:

1) Someone would have to "GUESS" your account name from "millions of possible combinations".

2) Next they would have to "GUESS" your password from "millions of possible combinations" and then match it to your account name with "millions of possible combinations".

3) And finally they would have to "GUESS" the Steam Guard Mobile code "which changes every 30 seconds" to match both your account name and password to then have access your account.

--------------------------------------------------------------------------------------------------------------------
Your account was phished / hijacked. Follow steps 1- 8 to secure your account:

1. Scan for malware https://www.malwarebytes.com/

2. Check that the email and phone number on the Steam account are still yours.

3. Deauthorize all other devices https://steamhost.cn/twofactor/manage

4. Change passwords from a trusted/clean device.

5. Generate new backup codes for your Mobile App https://steamhost.cn/twofactor/manage

6. Revoke the API key https://steamhost.cn/steamcommunity_com/dev/apikey (there should be nothing in the APIKEY)

7. Make sure your steam recovery email account is secure and still accessible.

8. Do a PW reset to recover any steam points spent in last 14 days.

Steam will NOT return lost funds or Items.

If any lost items are from a Trade Protected game, you might be able to recover them. See:
https://steamhost.cn/help_steampowered_com/en/faqs/view/365F-4BEE-2AE2-7BDD

------------------------------------------------------------------------------------------------------------------------
Because you were phished on your computer. They grabbed the session token from that 30 second 2fa code, along with your login info. that is the only way. with all 3 parts of the key, they could use that at any time to log in as you, since they had the 2fa session token code, steam thinks it is you.

The only way to get all 3 parts of the key is from your computer, you were phished.
Originally posted by pckirk:
Accounts are phished not hacked.

You gave away all your account details.

The account name, the password and the KEY to the door, the Steam Guard Mobile code giving them access to the account.

How? by either logging into a known scam site or any off steam item sell sites, fake steam log-in websites, or by tailored malware on your PC, the vote for my team scam, you have a pending ban scam on Discord, free knife click the link etc.

How does Steam (a program) know it is not you when all the account details are correct? It doesn't, therefore any action taken on your account is seen as you doing said actions.

The alternative is not plausible:

1) Someone would have to "GUESS" your account name from "millions of possible combinations".

2) Next they would have to "GUESS" your password from "millions of possible combinations" and then match it to your account name with "millions of possible combinations".

3) And finally they would have to "GUESS" the Steam Guard Mobile code "which changes every 30 seconds" to match both your account name and password to then have access your account.

--------------------------------------------------------------------------------------------------------------------
Your account was phished / hijacked. Follow steps 1- 8 to secure your account:

1. Scan for malware https://www.malwarebytes.com/

2. Check that the email and phone number on the Steam account are still yours.

3. Deauthorize all other devices https://steamhost.cn/twofactor/manage

4. Change passwords from a trusted/clean device.

5. Generate new backup codes for your Mobile App https://steamhost.cn/twofactor/manage

6. Revoke the API key https://steamhost.cn/steamcommunity_com/dev/apikey (there should be nothing in the APIKEY)

7. Make sure your steam recovery email account is secure and still accessible.

8. Do a PW reset to recover any steam points spent in last 14 days.

Steam will NOT return lost funds or Items.

If any lost items are from a Trade Protected game, you might be able to recover them. See:
https://steamhost.cn/help_steampowered_com/en/faqs/view/365F-4BEE-2AE2-7BDD

------------------------------------------------------------------------------------------------------------------------
Because you were phished on your computer. They grabbed the session token from that 30 second 2fa code, along with your login info. that is the only way. with all 3 parts of the key, they could use that at any time to log in as you, since they had the 2fa session token code, steam thinks it is you.

The only way to get all 3 parts of the key is from your computer, you were phished.


Thanks
But I can sure that, from step 1 to 8, everything was already done. Also, I just checked for Virus and/or Malwares after this happened, and it's clean.
< >
Showing 1-3 of 3 comments
Per page: 1530 50