Well, first time happening to me, I don't understand how could this happen I didn't download anything, neither open any suspicious links or told anyone my account details, my mail password is aswell changed, so I can't recover my account that way, what should I do?

Theres no way somebody could guess my passwords.

That guy changed my profile picture, my community ID, my mail password, deleted all my friends on steam and "About me" aswell.

Be careful guys, there seems to be a new trick/way to hijack accounts, without knowing username/passwords/mail, well I don't have idea how, but this just happened to me.

9 years ago*

Comment has been collapsed.

Deleted

This comment was deleted 5 years ago.

9 years ago
Permalink

Comment has been collapsed.

Hmm, how could this happen then, I can't believe, how could that keylogger appeared on my PC, I don't understand, also, I never logged in any untrusted website, only websites I logged are steamgifts and steamcompanion, also I'm not that stupid to fell for that trick, I'm well aware of those links and I never ever clicked, there must be something else, I even scanned my PC for viruses, but it didn't find anything.

9 years ago
Permalink

Comment has been collapsed.

There is your mistake malware and virus are two SEPERATE things, you need a malware scanner too.
Even if you are not stupid people will always try to trick you making stuff look legt while it's not you probably did fell for something.

9 years ago
Permalink

Comment has been collapsed.

I did both malware and virus scan, and I know they're separate things I did Malwarebytes Anti-Malware already and avira full scan, I'm 100% sure I did not fell into anything, trust me, theres something else!

9 years ago
Permalink

Comment has been collapsed.

Well they say there will be or are some new viruses/trojans instaling to Grapic Card bios or HDD internal drivers. For now non detectable (NSA ond others spy agencies), the same goes for USB drives, SD card too is a mini PC with small simple CPU, if you into it, you can run OS like linux on it and who know what else xD

9 years ago
Permalink

Comment has been collapsed.

I assure you that the .corn TLD is used only by good, honest farmers!

9 years ago
Permalink

Comment has been collapsed.

My Gmail was hacked yesterday by someone from Seatle , Washington, though i'm from italy. I managed to get back my account and did alot of security measurements, i have no idea how this person managed to change my password and my recovery email.... I got a huge scare since my steam account was linked to it, luckily the password was different, Then I changed the email from steam right the way.

But yea, something very weird since it never happened to me before, also my password is impossible to guess imo.

9 years ago
Permalink

Comment has been collapsed.

NazG, do you use gmail two step verification?

9 years ago
Permalink

Comment has been collapsed.

I didn't have telephone verification before, now I do.

9 years ago
Permalink

Comment has been collapsed.

Excellent. Is not bad to check for malicious guests also.

9 years ago
Permalink

Comment has been collapsed.

+1

I prefer to use another service and since three years ago i decided to make finally a serious e-mail that should have been last for years, i made every kind of security on it. I linked it to another e-mail [In that case a Gmail one, that's the same one i use on my Nexus 5 so it's really simple to see if anything happens to my main e-mail since i receive a notification for every important operation on it.], and i linked the first mail to my cell number, plus two step verification with an app on my Smartphone similar to the Steam Guard and all the secuirity-stuff i could do.
I did the same for the Gmail with the Authenticator app and so on.

Well, i guess that if my Nexus 5 should be stolen or lost i would be in big troubles, lol.

9 years ago
Permalink

Comment has been collapsed.

Just use Cerberus, and everything will be okay (probably).

9 years ago
Permalink

Comment has been collapsed.

Well i don't move so much from home and when i do it i always check to have everything with me when i leave a place, so i hope i'll never need it.

9 years ago
Permalink

Comment has been collapsed.

A good strategy, I act the same way.:)

9 years ago
Permalink

Comment has been collapsed.

I don't like Facebook so much not 'cause i'm against social networks, just i don't care so much about but i've to admit that the Facebook security measures are cool.

I don't know how it could works here on Steam, but i like the stuff about you link up to five friends for an easy way to recover your account just in case...

9 years ago
Permalink

Comment has been collapsed.

Yep keylogger...

9 years ago
Permalink

Comment has been collapsed.

Well... I doubt that, this morning I wake up, steam asks to refresh login, after I failed typing my main password for few times, then I went to recover password with mail, but then, I see that I can't even login to my mail, strange, it doesn't accept password, also my steam and mail passwords were different, and almost impossible to guess, strange, very strange

9 years ago
Permalink

Comment has been collapsed.

Try to contact email support to get your email account back. Do you have any antivirus? Malwarebytes Anti-Malware is FREE and it's good to have along with an antivirus.

9 years ago
Permalink

Comment has been collapsed.

Maybe someone has found a new exploit ...

9 years ago
Permalink

Comment has been collapsed.

That's why you never use the same password for multiple accounts. Every password should be unique, especially for email and accounts that have your credit card linked to.
Usually you can recover your mail by contacting your mail support (they'll ask you some questions that only you know the answer at, provided the info you put are correct).
As for your Steam account, you could try contacting support as well. They will check and notice the suspicious activity, and perhaps you'll get your account back.

9 years ago
Permalink

Comment has been collapsed.

Yeah, I had different passwords for mail and steam, but still they managed to change both passwords, and aswell changed mail to their own probably, or whatever, I hope I can get my account back, anyway, still be careful guys, I recommend everyone who reads this, change your passwords, and mails if they don't have phone verification, my mail didn't had, that's why It got hacked so easily, now I've added but I hope it's not too late, and still I don't understand how they managed to guess my passwords, they had symbols and numbers, nearly impossible to guess, and both mail/steam at same time.

9 years ago*
Permalink

Comment has been collapsed.

Possibly they hacked your email and then found your steam account... This is really bad situation.

9 years ago
Permalink

Comment has been collapsed.

Yesterday I cleared all my mails, leaving them with 0 messages, got hacked today morning

9 years ago
Permalink

Comment has been collapsed.

Deleted

This comment was deleted 5 years ago.

9 years ago
Permalink

Comment has been collapsed.

Nothing suspicious, I only deleted all my mail messages, they were like.... over 1500 for each mail, I was running Terraria(TShock) server last few days, and playing Terraria or GTA V, haven't done anything that could result in this situation.

9 years ago
Permalink

Comment has been collapsed.

I think it might be related to the server you were running. I think I read there was some exploit used to hack PCs via these, correct me if I am wrong.

9 years ago
Permalink

Comment has been collapsed.

Well, I doubt, there are many people using TShock to host servers, in fact it is very popular, I've also used TShock few years ago to play Terraria with friends.

Funny fact, the only way I can find my profile right now, is via my steamgifts profile via "Visit Profile Profile" button, theres no other way to find my account, since that retarded hacker kid changed my community ID and name, damn how the f*** did I get myself into this....

9 years ago
Permalink

Comment has been collapsed.

Well, maybe they found that your steam account was tied to that mail, and then they started hacking your mail account, because it is much easier to hack than steam account on some services (this is why you need two-step authorisation).

9 years ago
Permalink

Comment has been collapsed.

Yeah right, the mail which was tied to my steam didn't had mobile code verification on each login, which I added today, I guess that's why they hacked it easily, but still what kind of genius was that guy to guess my password...

9 years ago
Permalink

Comment has been collapsed.

Format your computer, if you haven't done so, just to make sure that there won't be any keyloggers.
After that inform Steam support about the loss of your account and e-mail. It's also good to send photos of CD keys of box version games you own on Steam, that could speed up the whole process as otherwise you might be asked about it later.

9 years ago
Permalink

Comment has been collapsed.

I haven't formatted my PC, because if I do, I won't be able to reinstall windows for few weeks(thats bad), but well, I'm 100% sure I don't have keyloggers, I checked msconfig, services/startup, theres only skype and nvidia drivers, nothing else marked, also scanned with Malwarebytes Anti-Malware and avira antivirus.

9 years ago
Permalink

Comment has been collapsed.

Try running Combofix. that can root out any nasties that AV and malwarebytes didnt notice. just google combofix. the site is bleepingcomputers

9 years ago
Permalink

Comment has been collapsed.

Ok I'll try it, thanks.

9 years ago
Permalink

Comment has been collapsed.

You are using Windows 10?

9 years ago
Permalink

Comment has been collapsed.

No of course, I don't like either win8 or 10, I'm using Windows 7 Ultimate only.

9 years ago
Permalink

Comment has been collapsed.

ok ok, but how your still logged here? If you were hacked you say? You are obviously trolling us.

9 years ago
Permalink

Comment has been collapsed.

Oh well, um, I was so pissed I haven't thought of that, believe or not, I'm not trolling, I don't know how to prove, but look at my account, I wouldn't put this shitty picture, all my hundreds of friends are gone, all my groups are gone, my "About me" is gone aswell, I don't know how I'm logged, but in fact I'm, I can't login to my steam account however, if I logout I won't be able to login or if I try to login from other browser, and that retarded hacker is playing GTA V, gosh, I can prove that I'm not running GTA V on my PC right now though.

9 years ago
Permalink

Comment has been collapsed.

Deleted

This comment was deleted 5 years ago.

9 years ago
Permalink

Comment has been collapsed.

Well... I did, and I hope they'll believe that its my account, I send them every proof I could.

9 years ago
Permalink

Comment has been collapsed.

Deleted

This comment was deleted 5 years ago.

9 years ago
Permalink

Comment has been collapsed.

Thanks...

9 years ago
Permalink

Comment has been collapsed.

Deleted

This comment was deleted 9 years ago.

9 years ago
Permalink

Comment has been collapsed.

Deleted

This comment was deleted 5 years ago.

9 years ago
Permalink

Comment has been collapsed.

Not sure about it but my guess would be cookies.

9 years ago
Permalink

Comment has been collapsed.

yes I hope steam helps you out, also did you put a security question or a phone on your e-mail account? if so use that to recover your email. And that way you should be able to recover your steam account too.

9 years ago
Permalink

Comment has been collapsed.

no, he's not. this has happened many times before. as long as he doesn't log out, he can chat with us here.

9 years ago
Permalink

Comment has been collapsed.

Steamgifts seems like it doesn't check if you are logged into steam after the first time you log on

9 years ago
Permalink

Comment has been collapsed.

you searched ur email and password in google?, maybe u play other games on private servers and u are using the same pass on steam. there are a lot of pastebins of hackers that acces poor db and leech all the users and passwords, later they sell that data to some people.

9 years ago
Permalink

Comment has been collapsed.

Nope, I'm sure I hadn't used same password at other website or game.

9 years ago
Permalink

Comment has been collapsed.

Your email was probably the one hacked. Have you logged into your email from elsewhere like public computers or old computers? This probably could have happened months or years ago.

9 years ago
Permalink

Comment has been collapsed.

That's why you always use 2-step verification for your email (token, mobile app, SMS alerts etc) - this way even having your password it won't be possible to perform hijack.

What methor of password recovery did you use when you were setting up this email? Secret Question? Different backup email? Try to use it to reset your password. Also if you usedyour real info to register you can contact provider with scan of your ID, driver's licence etc to prove it's you and get your account back and from there contact Steam Support. If you created email with fake data and fake Password Recovery info - sorry, but you are screwed. Learn from it what not to do next time.

9 years ago
Permalink

Comment has been collapsed.

Deleted

This comment was deleted 5 years ago.

9 years ago
Permalink

Comment has been collapsed.

Good for you :> It's always wise to make such changes and preparations before something bad happen not afterwards :>

9 years ago
Permalink

Comment has been collapsed.

See below my advice about using a password manager. Even when people think their own made up passwords are difficult to guess, they aren't. Not for a computer.

9 years ago
Permalink

Comment has been collapsed.

Deleted

This comment was deleted 5 years ago.

9 years ago*
Permalink

Comment has been collapsed.

Skill isn't needed for account hacking. These tools are available to script kiddies. Arstechnica.com ran an article not long ago where one of their writers who didn't know much about hacking learned very quickly how to download and use password cracking tools that worked amazingly well.

9 years ago
Permalink

Comment has been collapsed.

If you have any games which you activated on Steam with a CD-Key, you can contact Steam Support and if you provide them the CD-Key which was used on your account, they can help.

9 years ago
Permalink

Comment has been collapsed.

If you lost both your email and steam, then it has to be a key logger. Could be a friend who installed it without you knowing. Or could be a phishing link. Anyway, focus on getting your email account back and enable 2 step authentication on it. Once you have that getting your steam account should be easy.

9 years ago
Permalink

Comment has been collapsed.

Bump for solved, hard puzzle m8!

It's a key logger. Use phone verification next time. Contact Steam Support and send them some of your used bundle keys, credit card or phone number, they will contact you fast for this situation.

9 years ago
Permalink

Comment has been collapsed.

Pretty simple. unless you are using the same password for both steam and your email.
It will be someone close to you that know your password for both your Email and Steam Account.
Either your friend or family member got to know your password and access your account.
There is no hack or glitch as none of us have the problem and email and steam account do not link so even they can hack steam to get your password, they will not be able to access your email unless you are using the same password.
Somewhere on your claims, you are lying.
Therefore they have a way to access your account and change everything.
Stop lying to yourself and you will know the source of the problem.

9 years ago
Permalink

Comment has been collapsed.

Good info here for contacting Steam. Let me offer another suggestion. Once you've recovered your accounts and installed 2-factor authentication, get yourself a password manager like KeePass and have it randomly generate your critical passwords (email and basically any account that has critical data about you or that contains banking info). For those sites you access frequently, write down the randomized passwords and stick them in your wallet until you can type them in from memory.

You mentioned your password was hard to guess, but unless a computer generated it randomly, it's probably based on a pattern that has already been cracked. There are entire databases out there of containing the hashes for tens of millions of passwords that hackers routinely use to break into accounts. If they can get your hashed password, then it's a simple matter of looking it up in the database to find out your real password. There are also tools that apply common patterns and substitutions that can quickly crack your password even if it's long.

A reasonably secure password is randomly generated, uses numbers, mixed case letters and symbols and is at least 12 characters long. Password managers can easily generate ones that are longer and virtually unbreakable.

9 years ago
Permalink

Comment has been collapsed.

^This + stay away from suspicious websites, install some kind of java block on your web browser, dont execute .exe files that you dont have 99,9% trust

9 years ago
Permalink

Comment has been collapsed.

damn, that's extra scary :(

hope you can recover your accounts.

9 years ago
Permalink

Comment has been collapsed.

Closed 9 years ago by BladeMaster7.