THE POST LOOKS WAY BETTER ON BLAEO, JUST SAYING, BE NICE TO YOUR EYES

Hi everybody ! It's Wednesday (just saying in case you would be shook that it's not a Monday post) and today we're gonna speak of something important that not everybody know, HELL I didn't even know about it until randomly clicking on a link that I'm 99.99% sure that most of us didn't guess that it may have such effect.

For those who may not know about it, my Steam account has been hacked around two weeks ago without me putting my credential anywhere and even using Steam Guard. For those who didn't follow the story, I got back my account, but only after the ones who got access to my account tested CS:GO or whatever it's called on it and contacted all my friend list, calling them "Hey Bro!" and adding a shady link for them to win a game.


The Facts

Before writing the lengthy explanation on how to lock your account, kick anybody who is currently using it and teaching you how to proceed, I would like to speak of Steam attitude regarding the problem.
I didn't follow a shady link, I didn't put my credential anywhere and my mail is secured. I tried to have some information as I attempted to recover my account, but it was one of those dialogue of the deaf like we love them:

  • When I told them that I didn't put my credential anywhere, they told me to get steam guard.
  • When I told them that I had steam guard, they told me to make sure my mail was safe.
  • When I told them I had steam guard and that my mail was safe, they told me to not put my credential anywhere.
  • When I told them that I didn't put my credential anywhere AND that I had steam guard AND that my mail was safe, they closed the conversation saying that apparently I had my account back.

So I have absolutely no answer to give you on what happened, just that I have less reason to lie about putting my credential anywhere than Steam has to cover the fact that some people, and not only me, get hacked despite being on a similar situation as I am (secured mail, steam guard, no credential entered anywhere). There may be a breach somewhere, and it's more that and the fact that some people who are actually playing CS:GO may get their item stolen that pushes me to explain how the hell to lock your account.

Phishing

Around the time I've been hack, a new sort of phishing appeared, and someone made a post on Steamgifts warning people about it and linking an article from a website called BLEEPINGCOMPUTER. The article was named "Steam Accounts Being Stolen Through Elaborate Free Game Scam".
My account sent the link to the shady website exposed on the article, but the article itself doesn't explain how to lock your account in case of phishing. This is what it states:

Steam Policy

Which is absolutely true, but while they added a lot of pictures to explain what happens when you get phished, they forget to point at a really specific link visible on one of their screenshot and we're going to speak about this specific link and how you will receive it.

How to Lock your Steam Account

Let's play a little game. Without reading the next part of this article, try to find the answer of this > tiny quizz < ♥
You found the answer ? You didn't find the answer ? You didn't try to find the answer ? It doesn't matter really (does it ?) because I'm going to tell you how the hell to lock your account right now.
Are you ready ?
Are you really ready ?
ARE YOU SURE YOU'RE READY TO LEARN THE TRUTH ?
THE TRUTH THAT WAS WRITTEN IN SO SMALL LETTERS THAT YOU NEVER EVER PAID ATTENTION TO IT ?

I mean, this is true. You can even do the test at home and see by yourself how big is the link that allows you to lock your account, because it appears ONLY on a specific occurrence and it's when you change your email.

I have to precise they use Arial 9pt to give the damn link

So, yeah, if you read through the whole stuff, which, I guess, isn't exactly something that comes to your mind when you're stressed as you've just been kicked from your account and been told that your email has been changed, you can see that there is a specific recovery link at the bottom that you have to use to recover the account and/or lock it.

The link will not appear anywhere else, it's not a basic link, it's a link with a specific token to solve the specific situation that got you to receive this email. If you click on it, you'll be asked if you can access to the account (aka "does your password works") which is obviously never the case when you've been hacked.
I decided to make it simple and to give you an easy to follow tutorial. The procedure takes maybe, wow, 15 seconds and can save your items if you have some valuable for hackers (I'm thinking of you CS:GO)

Can't log in

Secure your email

Use Steam Guard if you have it

Aaaand we get to the LOCK CODE

Congratz your account is self-locked

The locking feature allows to "Locked features will include purchasing, changing password, changing email, Trading, Community Market, and playing on VAC enabled servers."
If you log in the account, you have an alert showing of which states this :

Steam Alert

In case you wonder, YES CS:GO is part of the "VAC enabled game servers", which means that if you bought loot box there and got lucky, you can avoid people to trade your items if you follow that simple guide and are fast enough to do so. So as bonus as making this small tutorial, I recommend you to link your steam to your main account so you have the "your email has been changed" message right away.
Also, in case you wonder, yes I did create a steam account especially for locking it.. From myself.


What do you think of my explanation, was it clear enough ? Did you actually learn anything ? If you play CS:GO, do you think that this may be useful for you to know that ? Did phishing happen to you or one of your friend ? Did they recover their account without any problem ? Did they lose anything ?

Reminder : This topic isn't meant to give an opinion on people who got their account compromised so I would appreciate it to not turn onto some sort of shaming topic while it's not its purpose.

5 years ago*

Comment has been collapsed.

Did you ever got your account compromised ?

View Results
Yeah, I mean, it can happen to anybody
No way in hell !
POTATO

Since somebody in the original thread just asked for a TLDR summary (and I've already written it) I'll just post it here. I hope you don't mind otherwise I'll delete this comment.

When your account gets compromised whoever did it will change the mail adress associated with your account. You will get a mail from Steam notifying you that your mail adress has been changed. At the bottom of that email there's a link to lock your account.

5 years ago
Permalink

Comment has been collapsed.

I didn't know what TLDR meant, I'll sleep less stupid tonight. Thanks for the summary, I'll just add the picture since I worked so hard on it ,)

View attached image.
5 years ago
Permalink

Comment has been collapsed.

You're welcome :) Yeah, good idea since it's not possible to try it out yourself unless you change your email.

5 years ago
Permalink

Comment has been collapsed.

View attached image.
5 years ago
Permalink

Comment has been collapsed.

I just rewatched the trilogy (and The last Flight of the Osiris) after hearing here that they're appartly planning to make a sequel.

Part 2 and 3 are not as bad as everybody makes them out to be but granted they are not the fun ride the first one was.

5 years ago
Permalink

Comment has been collapsed.

Final Flight of the Osiris, is that the exact same content as in Animatrix? Or is there anything extra?

5 years ago
Permalink

Comment has been collapsed.

You're right. It's the Final Flight not the Last. Sounds way cooler with the alliteration :D
Yeah, I was actually talking about the first episode of the Animatrix. I didn't (re)watch them all because they're not all equally good in my opinion (Final Flight and Second Renaissance 1 & 2 being my favourites) but when I got to the beginning of Matrix 2 when they have that meeting where they say they've confirmed the report of the Osiris I just had to watch it.

The animations are not as good as I remembered them but back in the day I was mindblown by that foreplay-like swordfight the captain and his first officer have in the construct and thrilled about the fact they both sneak a peek :D Not just him being the horny guy as usual but that she also appreciates the male form. I also liked the ending quite a lot. Guess I'm a sucker for a good last stand in fiction.

5 years ago*
Permalink

Comment has been collapsed.

It's easy to mock people for getting their accounts compromised... until it happens to them. We all fuck up some times. Sure, not everyone will fuck up the same way, but we all fuck up.
I remember when I got scammed on SteamTrades years back and when I made a thread for it, multiple people just called me a moron and a "scammer" for trading a key that was previously free (I got it through a legitimate purchase, didn't know of the giveaway) and that I deserved to get scammed because of it. One of them is still a moderator for this site.

Basically, point being that we all screw up and there could always be more than a few people who could boldly say "You're stupid for falling victim, so you deserve it!". Just try and make sure that before you say something like that, that you can say that nothing every negative thing that happened or will happen are 100% inevitable. Fact is that you can't really say that, so perhaps instead of shaming someone for screwing up, just be quiet or actually try and be useful.

Fuck, that sounded way too preachy and like some Sesame Street episode...

5 years ago
Permalink

Comment has been collapsed.

I agree with you and want to add that we don't know how the hacker / phisher will proceed in the future. Time has proved that they are more and more inventive and find new breach every single day. Let's say that it's useful to know that it exists an option that protect your account, whether or not you ever have a need for it.

5 years ago
Permalink

Comment has been collapsed.

Free bump, for trying to help people with this.

PS: Maybe you should add somehow the words "hacked account" or something similar into the title for search reasons.

View attached image.
5 years ago
Permalink

Comment has been collapsed.

I changed the title, hope it's a little better ^^ !

5 years ago
Permalink

Comment has been collapsed.

Bumf for solved?

5 years ago
Permalink

Comment has been collapsed.

A bump for awesome and useful and cracked me up too! Have a 💙 and thanks for sharing.

5 years ago
Permalink

Comment has been collapsed.

Sign in through Steam to add a comment.