If someone sends you a message like this

"My friend cant add you(steam error), Add him for talk, he is interest for trade :http://lsteamncommunity.com/id/crab323/ "

then it is a scam attempt on your steam profile. I saw the thread on ST and quite a lot of people have been scammed already(hijacked, that is) I won't give the link to it because that will become calling out.

The scam attempt is such, when you go to the link(please dont click), it will tell you to log in to steam. When you do, will ask for steamguard code. In reality, once you login, it sends your details to the hijacekr. Notice how there is a "l" before steamcommunity

<Copy Pasted from the thread>
More Info: details of the hijacker(s) from Steamguard
We've received a request to access your Steam account from the Steam Client on a new computer located at IP address: 91.224.160.24
Our records show this IP address is in AMSTERDAM NOORD-HOLLAND NL
A new computer located at IP address: 46.118.100.222 Our records show this IP address is in KIEV KYYIV UA
Googling the IP address showed a lot of results related to hacking, botting and spamming. That IP is very notorious

This is serious, some friends of mine have been hijacked too, and they sent me such a link. I knew about the thread, so I guess they were hijacked. Just a PSA, mods, please don't punish me, but this is serious. I know most users on ST are too concerned about their ahem valuable trades than personal safety of others, so here you go.

The original thread contains some user links, so wont add that link here

11 years ago*

Comment has been collapsed.

Thanks, but 1 2.

11 years ago
Permalink

Comment has been collapsed.

Except that it contains the ST link, which does call out in some extent

11 years ago
Permalink

Comment has been collapsed.

it's not calling out. it's not specifically blaming them for the problem.

11 years ago
Permalink

Comment has been collapsed.

Seriously, if people aren't smart enough to not check for an SSL connection when logging in to website, they deserve all their internet valuables stolen.

There I said it.

11 years ago
Permalink

Comment has been collapsed.

Deleted

This comment was deleted 2 years ago.

11 years ago
Permalink

Comment has been collapsed.

+1

11 years ago
Permalink

Comment has been collapsed.

had same thing happen to me on tfoutpoast someone pasted this but i seen the link and reported him

11 years ago
Permalink

Comment has been collapsed.

We could just make a thread that says "PSA: Don't be stupid and use your head" and then we wouldn't need all of these additional ones.

11 years ago
Permalink

Comment has been collapsed.

This. All that needs to be said is use Steam Guard and always check the address bar few times. Bah, Steam actually sends you to a browser with a message that you have to be careful. And if it's an actual Steam website, you are send to the website on Steam Browser. It's so hard to get scammed, yet there are people who somehow manage to fall for it. I don't even.

11 years ago
Permalink

Comment has been collapsed.

Impersonation, just because people are lazy

11 years ago
Permalink

Comment has been collapsed.

+1

11 years ago
Permalink

Comment has been collapsed.

+1

11 years ago
Permalink

Comment has been collapsed.

+1

11 years ago
Permalink

Comment has been collapsed.

Deleted

This comment was deleted 1 year ago.

11 years ago
Permalink

Comment has been collapsed.

Thanks for the warning! Keep this at the top so others can see it.

11 years ago
Permalink

Comment has been collapsed.

no need.. if you fall for that u deserve it.. i understood its fake in MILISECONDS (has happened to me yeS)

11 years ago
Permalink

Comment has been collapsed.

Nobody "deserves" to be scammed, but if you use the same password for Steam and your email, AND indiscriminately click on links without first running it through the [apparently redundant] fleshy thing atrophying in your skull, you aren't ready to use the internet.

11 years ago
Permalink

Comment has been collapsed.

hehehe yes you get me, i like the way you put it however..

11 years ago
Permalink

Comment has been collapsed.

PSA- mass user stupidity ongoing

11 years ago
Permalink

Comment has been collapsed.

Business as usual.

11 years ago
Permalink

Comment has been collapsed.

Well, I feel bad for people who get scammed like this, but I make it a habit not to enter any sensitive information from a link I click.

Folks better wise up, I guess.

11 years ago
Permalink

Comment has been collapsed.

If it's such a notorious IP (assuming it isn't spoofed or a proxy) can't you just report it to the cyber/fraud division of a law enforcement agency (google provides several including ones for the UK and the FBI

11 years ago
Permalink

Comment has been collapsed.

One question... How do you pronounce "hijacekr"? :P
Thanks for the head up but I already know about it. ;)

11 years ago
Permalink

Comment has been collapsed.

We should all go on the link and enter in bogus information.

11 years ago
Permalink

Comment has been collapsed.

You should probably not post the actual link. Yes, I know in the context of this topic it's basically posted with huge flashing DON'T CLICK THIS on it, but seriously... people are stupid. Someone's bound to at some point.

11 years ago
Permalink

Comment has been collapsed.

The actual link isn't posted in OP

11 years ago
Permalink

Comment has been collapsed.

Also, the link requeires you to log in before your account gets hijacked. Clicking is not a sin, but entering your details sure is

11 years ago
Permalink

Comment has been collapsed.

Why do people always use these threads to jerk eachother off over how smart and l33t and unhackable they are lol

Thanks for the heads up.

11 years ago
Permalink

Comment has been collapsed.

I posted the same thing two weeks ago

Oh well, at least people know now :p

11 years ago
Permalink

Comment has been collapsed.

I thought you can't directly trade when you log in from unknown machine - even after you enter Steam guard codes?

11 years ago
Permalink

Comment has been collapsed.

They don't care about the trade, they want your log in details.

They can still "gift" all your items to other places. make purchases with your account. etc

11 years ago
Permalink

Comment has been collapsed.

Im wondering how people can enter on suspect links from unknown people rly.

11 years ago
Permalink

Comment has been collapsed.

11 years ago
Permalink

Comment has been collapsed.

"Just a PSA, mods, please don't punish me, but this is serious."

Why on Earth would we punish you?

11 years ago
Permalink

Comment has been collapsed.

Some people have gotten the ides, due to some trigger happy mods. That anything that may shed this website in a bad light. ei mentioning the existence of hacking will get you banned.

Sadly to say, i've seen these links popping up a lot recently.

11 years ago
Permalink

Comment has been collapsed.

Exactly what AJ said.

If you remember my ArmA sharing, it was not taken kindly by a mod, and though I agree it was calling out to some extent, I felt it needed to be shared, people were getting scammed here and there. And I already have received 4 more of these "Add him for trade" messages, just blocked them for the time

11 years ago
Permalink

Comment has been collapsed.

Is it just me, or the very long and having lots of easy to imitate letters link to the actual steam community makes it very, VERY easy for hijackers to make phishing sites? I have seen probably 10, if not more, different variations of phishing links, and this is mostly due to the elaborate steamcommunity name in link.

Its far harder to make a hijacker site leading to gogle, goggle, yaaho, and idk what else because they keep to small words without much to improvise in terms of letters. But how many times I have seen staem, comnutiy, conmunity, steem, sleam and idk what else is just hard to imagine.

So imo, to make the life of a hijacker harder, Steam need to change their steamcommunity link to something else, but ... I assume that will require quite a lot of server migration and other web dev things I dont really understand. But yeah, make sure you read the steamcommunity link you are clicking very well several times before you even open the page.

11 years ago
Permalink

Comment has been collapsed.

Even on ST, impersonation is still at large, lazi people don't bother checking the profile, then whine about it in the forums here

11 years ago
Permalink

Comment has been collapsed.

Closed 11 years ago by Hague.