so i got a message from someone
hey,m8!
get a free random game(gta v,pubg.....)............
so i log it in it because i thought he's trust worthy and he's youtuber has 326k subs and i thought it's like steamgifts
so yeah i logged and guess what i fuked up after few secondes i got email The Steam Guard Mobile Authenticator has been removed from your account
then another email A phone number (ending in ..) has been removed from your account.....
so wanted to let you know

5 years ago*

Comment has been collapsed.

Your account was cracked, contact steam support to recover it, there are plenty of threads about that

5 years ago
Permalink

Comment has been collapsed.

I still don't get how they manage to remove Steamguard Authentificator so easily... Having it is basically useless at this point.

edit: Ah, I guess the fake login also asks you for authentificator code. That makes it easy :/. Vale should add e-mail confirmation for removal of authntificator.

5 years ago*
Permalink

Comment has been collapsed.

+1
Steamguard Authentificator, password, email address or phone number should not be removed unless confirmed by email.
But some people do use the same password for Steam and their email. Doesnt take any cracking or hacking to assume the Steam account.

Just takes behavioral engineering of the attacker and lack of security on the victim. A script can change everything in a heartbeat.

Passwords dont have to be complicated, just unique and long for important sites.

5 years ago
Permalink

Comment has been collapsed.

Except you're giving them both your PASSWORD and Steam Guard code at the same time (op didn't mention this). You need both.

5 years ago
Permalink

Comment has been collapsed.

But doesn't the steam guard password change like every 30 seconds or so? These punks stealing accounts sure are quick.

5 years ago
Permalink

Comment has been collapsed.

Yeah... I doubt they manually do it.

Wonder how they do it though, just looking through deactivating mobile authenticator at a quick glance, you'd need either acces to the mobile authenticator somehow, or change the phone number, which also wants a confirmation from the mobile authenticator.

Unless I'm missing some options (obviously I'm not gonna go through the hassle of actually deactivating mine just to find out). Like e-mail would make sense.

But yeah, if people can get acces (as in, the ability to change it completely) to your account by just getting the guard code once, it kinda defeats the whole purpose of it.

5 years ago
Permalink

Comment has been collapsed.

I was thinking the exact same thing, I'm assuming they have a program to do it but still that's fast!

5 years ago
Permalink

Comment has been collapsed.

Please rename your topic; if someone doesn't open and read it, he might be tempted to visit it.

5 years ago
Permalink

Comment has been collapsed.

my account was stolen but i got it back, ashole deleted all my friends

5 years ago
Permalink

Comment has been collapsed.

Hello ahmedcabiste. I need you to please remove the website from thread title and do not include it anywhere in the thread. We don't want people trying the site just because they see the name. You may describe the details of what happened to help prevent others from making the same mistake you did.

For those that can see the site right now it would be a big help if you reported it to the sites linked below.

https://safebrowsing.google.com/safebrowsing/report_phish/?hl=en

https://www.microsoft.com/en-us/wdsi/support/report-unsafe-site

https://app.webinspector.com/

5 years ago*
Permalink

Comment has been collapsed.

Looks like your advice worked. Visiting the site now I get a Cloudflare warning "Suspected Phishing Site Ahead", and the site itself is now blank.

5 years ago
Permalink

Comment has been collapsed.

done

5 years ago
Permalink

Comment has been collapsed.

Closed 4 years ago by ahmedcabiste.