Hey there,

Just a fair warning and a heads up that my account was compromised on the 30-31.12.2022. It all started when I got a request to vote for a RUST server and had to log in via Steam. This request came from a person I was friends with and all the conversation as you can see below, seemed normal at first glance.

The whole hijack happened during that time until later on the 31st when I got a warning message from Steam about it. I wasn't aware that the scammer messaged over 20-30 people from my friend list, asking them to fall into the same trap. After sending them the message, the scammer has blocked all communications; in some cases, they even blocked the account. Because of that, some people got really upset about that and probably even reported my account for scamming.

I NEVER played RUST and I would NEVER do these kinds of things to anybody. So, despite not being the one directing all these messages to everybody, I feel responsible to reach out and message everybody about these scams that came through my account because it was my fault for not paying attention.

I know two people are extremely upset because of it and even if other Steamgifts or friends have contacted them, they don't believe it, so in hopes, they see this discussion maybe understand, and listen that it wasn't intentional and I would never do such a thing.

Update 1: I have recovered my account, but the scammer stole my entire Steam Cards inventory. Trying to see if I can get it back or at least the value of those cards.

Update 2: Found out who hijacked my account and stole my entire inventory. I pretty much lost my entire steam collection and I had over 500+ pcs. I do suspect his account is linked with another that has 1000+ hours on Steam of RUST, which is very suspicious. Reported both of them to be investigated, but I don't know if I'd ever recover the money from the steam cards and other items or the cards itself.

Thank you and stay safe out there and Happy New Year!

View attached image.
View attached image.
View attached image.
View attached image.
1 year ago*

Comment has been collapsed.

Deleted

This comment was deleted 1 year ago.

1 year ago
Permalink

Comment has been collapsed.

If you want to learn more about current scams, there’s a subreddit called r/scams where people talk about what scams they’re running into. I’m sorry this happened to you, and it’s not your fault. It’s sad to have to question yourself about a friend who sounds like they always do. Who wants to live in a constant state of mistrust?

I think I'm done hearing about scams to be honest. I don't wanna remind myself about it, but yeah, staying informed is important. I still don't mistrust the person, although I know their account got compromised. I'll be more careful in the future when stuff like this show up. It's a first timer for me, especially coming from friends I had in my list for a long time.

It was nice of you to follow up with everyone on your list. It probably saved several people.

I felt responsible and just downright bad if I wouldn't. It took my entire day to reach to all of them and explain. There were others who fell for it, but they said that didn't notice any sort of damage, so that's fine. They changed their account password and I believe e-mail. It's easy to fall for this coming from people you trust or have expectations of. My intention is to provide trustworthy stuff and if I am acting all sketchy and stuff all of the sudden that doesn't sit well with me. So, that's why I wrote to people one by one, send activity messages with updates and well... made a discussion here. I have a lot of friends from Steamgifts here that trusted me. I don't wanna break that trust.

1 year ago
Permalink

Comment has been collapsed.

Stick with the basics. Saw unknown link....unfriended account....safe

Sorry that you lost items.

1 year ago*
Permalink

Comment has been collapsed.

I wouldn't have unfriended him because we spoke for a while and he never tried to scam me. So it wasn't something that would put my guard up. It's so strange this happened.

1 year ago
Permalink

Comment has been collapsed.

That it came from you caused me to pause and think about it. I'm glad that I stuck with the basics above.

1 year ago
Permalink

Comment has been collapsed.

I saw I sent you a message as well. I appreciate not unfriending me despite suggesting it. Or you did and I can't remember. I've had a busy day reaching out to people and explaining my situation.

1 year ago
Permalink

Comment has been collapsed.

Steam FAQ telling:

You don`t get back stolen items/cards

Sorry
Source:
https://help.steampowered.com/en/faqs/view/3B6E-B322-2400-8D24

1 year ago
Permalink

Comment has been collapsed.

Yes. I saw that news... I don't even want the items... would be happy to get the value of the items back, even if they are sold at a minimum price.

1 year ago
Permalink

Comment has been collapsed.

wait, you just press that link? anything opened after using link?

also steam help says about trades/market transactions, not about scammed items, maybe theres chance

1 year ago
Permalink

Comment has been collapsed.

Opening the link isn't a problem. Logging in using your steam account is what causes the issue.

1 year ago
Permalink

Comment has been collapsed.

Any suggestions or experiences with NVIDIA GeForce NOW login to Steam? I knew about, log in to Steam first then go to page that asks for Steam credentials, but NVIDIA GeForce NOW seems to use some built in browser or something as it asks me to enter credentials on every game lunch. Any way to save credentials for Steam (actually to link to Steam) so that GeForce NOW does not ask me again? In setting of the app it says automatic sign-in is not supported for Steam. As it was app downloaded from NVIDIA directly I said what the hack hope I do not get scammed, but I see from this thread, that I could have been easily scammed if I got somehow to scammers version of "NVIDIA" web page (Phishing with Unicode Domains) and downloaded the app from there.

1 year ago
Permalink

Comment has been collapsed.

I don't think GeForce Now can use automatic login since what they're running is essentially a virtual machine with a standard Steam installation, if I'm remembering correctly you can even find it as one of your account's authorized PC's. So just as with any other PC you use the Steam client from it will need you to re-log if you haven't logged in in a while, but it shouldn't be each time, more like only if you haven't used it in more than a couple of weeks, at least in my experience.

1 year ago
Permalink

Comment has been collapsed.

Thanks for the info. Must have been something on my side of installation then. Will see how it goes with new version of the app.

1 year ago
Permalink

Comment has been collapsed.

I should point out that I've only ever used it from the android app, I have zero experience with their desktop app.

1 year ago
Permalink

Comment has been collapsed.

This is a good question, but using NVIDIA GeForce Now kinda uses a funnel so holding credentials is dangerous for them, therefore it doesn't trust. You connect via a server, so you're not really supposed to have your credentials stored in such a place because they are not secured and could be easily cracked opened if NVIDIA has a breach and the hackers steal all the credentials off of people.

1 year ago
Permalink

Comment has been collapsed.

Thanks, I guess I have misunderstood the meaning of that setting, I was thinking it was related to the token which is created when you login to Steam. New version of app supports automatic sign-in for Origin store.

1 year ago
Permalink

Comment has been collapsed.

No worries, I guess brainstorming and talking about it gets a better view of things. This is why I like this community. 😀

1 year ago
Permalink

Comment has been collapsed.

eh, seems like you've got enough lecturing already and the important stuff was said and you acknowledged it, so I won't add my two cents on the security side of things.
I'll just tell to not beat yourself about that too much since it can happen even to the best in case you don't know, that's Jim Browning - a cybersec genius and professional scambaiter
I'm glad you've regained control over your account even though you lost your cards you still have your library. and I'm gratefull you shared your story with us - maybe you'll save someone from falling for that scam themselves! I wish all the best in this unfortunate time. Stay strong!

1 year ago
Permalink

Comment has been collapsed.

eh, seems like you've got enough lecturing already and the important stuff was said and you acknowledged it, so I won't add my two cents on the security side of things.

Yes. I think the most lecturing I got was from myself.

I'll just tell to not beat yourself about that too much since it can happen even to the best in case you don't know, that's Jim Browning - a cybersec genius and professional scambaiter

I remember watching that video. I know it can happen to anybody really.

I'm glad you've regained control over your account even though you lost your cards you still have your library. and I'm gratefull you shared your story with us - maybe you'll save someone from falling for that scam themselves! I wish all the best in this unfortunate time. Stay strong!

Thank you for the kind words. It means a lot!

1 year ago
Permalink

Comment has been collapsed.

Oh, I got a very similar situation around the start of the sale, out of the blue one of my contacts asked me to vote for some SC GO thing on a site I've never heard about. Because I've seen reports of this type of scams I first googled the name of the site and very quickly found out that it was a spoof of another site, that set off my alarms so I started poking at whoever was currently in control of my friend's account, there were a few dead giveaways that something fishy was going on, like a very long stretch of time to get any response or clearly copy pasted responses, as if one person was holding a conversation with a bunch of people at the same time or using a bot to handle most messages. So in the end I politely declined.
You really have to treat any outside link shared through chat as if it was potentially dangerous, too many account hijackings going on at all times.

1 year ago
Permalink

Comment has been collapsed.

I've learned my lesson and for sure I'll be a lot more careful when I get this kind of links. I shouldn't have trusted it, but still, I did and I can only blame myself for this.

1 year ago
Permalink

Comment has been collapsed.

Don't beat yourself too much over this tho, it can happen to anyone, the only reason I didn't fall for it is thanks to all the people writing about their experiences with being hacked. So it's a good thing that you've made this thread, it will be a warning that at least some will find really useful, we have to keep up with the scammers' modus operandi after all.

1 year ago
Permalink

Comment has been collapsed.

You're very right about that. As time passes by I feel a lot better about things.

1 year ago
Permalink

Comment has been collapsed.

On that day, December 31st, I fell for it. Since this person was my friend for a long time, I did not expect that this would be a scam. https://imgur.com/a/lYE9wpb And followed the link without even paying attention to the fact that it was fake. I tried to log in and I received an SMS on my phone that my authenticator will be moved or deleted. I immediately began to change the password, all sorts of errors popped up, I started to panic, I thought I had lost my account. But, the password was changed. I understand that I did everything right, do I need to change the mail or phone number? So far, I have not noticed anything suspicious, but I did not turn off the computer all this time and did not exit Steam.

1 year ago
Permalink

Comment has been collapsed.

Kauil, I was trying to get a hold of you on Steam, but you've blocked me. I was trying to explain that I would never do such a thing to you or anybody and warn you that I had my account hijacked and all those messages sent were not made by me. I am really really sorry for what happened and for putting you through all that work. I would understand you're upset. There's a second person I was referring in this messages that I am also hoping would see the discussion.

I honestly didn't know this was happening under my account. I was informed mid-day about the account theft and only after the scammer already sent to 20-30 people and blocked them from communicating or completely blocking them back. I hope you'd accept my apology and if you don't wish to be friends, I can understand but know I'd never invite or try to scam someone.

I tried to log in and I received an SMS on my phone that my authenticator will be moved or deleted.

My app didn't warn me of such changes. So I wasn't aware it happened. I would have prevented it.

1 year ago
Permalink

Comment has been collapsed.

I'm not offended, because of this I had nerves and sugar jumped up, I removed the block

1 year ago
Permalink

Comment has been collapsed.

Thank you for understanding! I am left to get in touch with one person, but he doesn't appear to be from Steamgifts. It's a lot more difficult to explain to them.

1 year ago
Permalink

Comment has been collapsed.

this really sucks :c
i am glad you did recover your account tho, i wish you the best on getting back your collection of things <3

1 year ago
Permalink

Comment has been collapsed.

I actually found out that's not really possible. I have lost all that I've had forever. It would mean a lot of work for Valve and that was my fault for not being more careful and trusting so easily even when it came from a friend.

1 year ago
Permalink

Comment has been collapsed.

It all started when I got a request to vote for ___ and had to log in via Steam.

This should be in blinking red letters above the steam chat window.

1 year ago
Permalink

Comment has been collapsed.

Story of my life. 😅

1 year ago
Permalink

Comment has been collapsed.

What's the point of this warning, if you didn't see bazillion previous warnings of the same phishing scams?

1 year ago
Permalink

Comment has been collapsed.

Because if I never saw it coming, surely others didn't either. If I can save a few others from the same faith why not share? Most people keep quiet, and never speak about it and their friends or others don't know about it and more people fall for the same tricks.

1 year ago
Permalink

Comment has been collapsed.

Glad you got your account back.

I'm assuming 2FA will be enough to stop something like this?

1 year ago
Permalink

Comment has been collapsed.

2FA only helps in the case of a compromised password. If the victim types the 2FA code into a fake login form it does not do any good. Furthermore I think Steam's TOTP has a really long timeout -- not 30 seconds but instead several minutes, so the window for the scammer to use that code to steal your account is even longer.

Ideally Steam would implement FIDO2 which is resistant to phishing by design and could help to prevent this kind of stuff.

1 year ago
Permalink

Comment has been collapsed.

Yes, if you are not giving that access to them.

1 year ago
Permalink

Comment has been collapsed.

Some of us learn the lesson the hard way unfortunately. I fell into same phishing trap once with giving my login credentials through a fake Steam login page. Luckily there wasn't anything valuable to stole in my account back then. I never login to Steam outside of Steam's main page anymore.

I suggest everyone to read this guide: https://steamcommunity.com/sharedfiles/filedetails/?id=2569847731

1 year ago*
Permalink

Comment has been collapsed.

Yes, well I knew chances are rare to happen, but they still happen. It's harder to believe it would happen to you until it already did.

1 year ago
Permalink

Comment has been collapsed.

Oh wow, I'm pretty sure I'd gotten chat messages to vote for a CSGO team or something before, glad I was too paranoid to log in. Even if you can't recover your inventory, I hope you can stop these scammers.

1 year ago
Permalink

Comment has been collapsed.

I have a lead and the accounts got reported. But they are probably just a chain. If I was to do what they would, I'd likely disperse the items all over the place and get the whole thing confusing for the staff to identify. I doubt the dummy account has all my items and they are just sitting there.

1 year ago
Permalink

Comment has been collapsed.

A prime example of "no good deed goes unpunished", I guess. Sorry this happened, but I hope you won't be too hard on yourself and this doesn't sour your mood going into 2023 too much.

1 year ago
Permalink

Comment has been collapsed.

Surprisingly not enough. I think this was the wake-up call I needed. Even if it's upsetting to think I lost it because of a scam, I am optimistic that this year is gonna be a lot better than the last.

1 year ago
Permalink

Comment has been collapsed.

I'm sorry this happened. I'm glad you recovered your account. Hopefully you can get some or all of your inventory back. I recently got a message from someone like this as well so their account was hijacked. These type of scams must happen more often during the holidays. Happy new year to you as well Vasharal.

1 year ago
Permalink

Comment has been collapsed.

Happy New Year! I suspected it too, because when it's best to fill your pockets with awesome items from others but during these holidays. You'd expect people to be more kinder to one another during this season, so their guard is down.

1 year ago
Permalink

Comment has been collapsed.

Fuck (and I cannot stress this enough) them scammers.

1 year ago
Permalink

Comment has been collapsed.

You can even capitalize that one so the ones in the back can hear it too.

1 year ago
Permalink

Comment has been collapsed.

sorry, that really sucks man. i haven't read all the advice others have given you, but my number one piece of advice is to never log in via links someone has given you. if you need to log in to steam, do it by going to steampowered.com or steamcommunity.com. if you're already logged in there, you can log in to any other site through steam with one button click. this way you aren't entering any information and if it still asks you to log in then you know for sure it's a scam.

1 year ago
Permalink

Comment has been collapsed.

Yes, that was the advice most people gave here and it's a useful one to remember. Thank you for the kind words.

1 year ago
Permalink

Comment has been collapsed.

This even happened to me in the second half of 2022 and a lot of my friends got removed and blocked because of this

1 year ago
Permalink

Comment has been collapsed.

Sorry man... Did you lose items too?

1 year ago
Permalink

Comment has been collapsed.

Fortunately i didn't, but this game me a shock and a lot of trouble

1 year ago
Permalink

Comment has been collapsed.

That's good. I mean stress is not good, but still, at least you didn't lose anything monetary. You managed to recover from it?

1 year ago
Permalink

Comment has been collapsed.

Yeah, i was able to recover from it, but still is never good to get your own account hijacked

1 year ago
Permalink

Comment has been collapsed.

Oh yeah, 100%! 😕

1 year ago
Permalink

Comment has been collapsed.

I'm so happy you got your account back! That's the most important thing.
I don't have you as friend on Steam anymore but it's not important, maybe you wanted to clean your list!
Hope you find a way to get even you cards back!!

Good people always under attack. That's not fair!

1 year ago
Permalink

Comment has been collapsed.

I'm so happy you got your account back! That's the most important thing.

I can't be any happier knowing my account is safe and I am planning to keep it like that from now on.

I don't have you as friend on Steam anymore but it's not important, maybe you wanted to clean your list!

I don't remember unfriending you to be honest. 🤷🏻‍♂️ I don't unfriend people. Unless the scammer did it when I was not aware. I did try to track my friendlist and see who got unfriended here. I've re-added you back and I am sorry about it. People need to be real douche in order for me to unfriend them or block them. I have over 220+ people as friends, so I honestly struggle to keep track what happened but know you'll never get an unearned ban or unfriending unless it's not me or I don't announce it.

I like to befriend people, so that wouldn't be in my character. 😀

Hope you find a way to get even you cards back!!

I don't think I will, but I will appeal for it. I just hope to hear from Steam support about it at least to tell me "Sorry, we can't help you with recovering your items."

Good people always under attack. That's not fair!

Just have to learn to be more careful who I trust. That's all and learn from my mistakes. We're all evil in someone's story.

One of the person's that blocked me because they thought the real me wanted to scam them is the last remaining person I was trying to get to to explain myself, but I can't do it. So, I reached to his friends and wrote a kind message on their profile if they can please contact the guy for me and ask him to at least listen to me.

In response I got this from him:

View attached image.
View attached image.
1 year ago
Permalink

Comment has been collapsed.

Sorry this happened to you.

I've had a couple friends fall victim to a similar trick, where you get a message (from another victim usually) asking to vote for their Dota / CSGO team in some kind of contest. When you sign into the website, which looks very well done btw, it harvests your creds and sign-in token.

1 year ago
Permalink

Comment has been collapsed.

Yep, that's how it is. I wish I knew about it, but heck... it is what it is now. Thank you for your kind words. 🙏🏻

1 year ago
Permalink

Comment has been collapsed.

Closed 4 months ago by Vasharal.