WARNING: Protecting Your Steam Account

If your post doesn't fit any other boards subject, then post it here
Locked
Stevo
Everlasting Villun
Everlasting Villun
User avatar
Posts: 8753
Joined: Sun Oct 22, 2006 10:01 pm
Location: Orange County, CA
Minecraft name: StevoTVR
Uplay name: StevoTVR
Contact:

Games Played

Ville Awards

StevoTVR’s avatar
Loading…

WARNING: Protecting Your Steam Account

Post by Stevo » Mon Apr 13, 2009 12:52 pm

Many people lately have been falling victim to Steam "phishing" scams that result in their account being stolen. This post is an attempt to prevent this from happening to you by explaining how to identify these scams in the first place. Much of this is common sense.

For a more detailed article, see https://support.steampowered.com/kb_art ... -OAFV-8478

What is phishing?
Phishing scams generally involve either a person directly asking for your credentials under false pretenses or directing you to a website to log in. Sometimes they will pose as some official that must "verify" your account before it is locked, or they may entice you with an offer of free games.

Sometimes the website you are directed to will be an exact replica of the Steam website, but this in no way an indication that the site is legitimate. It is very easy to make an exact copy of a website. Even the address can look almost identical, which is why you should always type it in manually. I'll give some tips on avoiding these sites.

How do I avoid these scams?
First, some important rules you should always follow:
  • NEVER GIVE YOUR PASSWORD TO ANYONE, EVER! Valve employees will never ask for your password under any circumstances.
  • DO NOT enter your username or password to any website after following a link. Either manually type in the address or use a bookmark.
    Use only the official Steam website!
  • Do not use the same password for other websites or services. Use a strong password, preferably with a mix of letters, numbers, and symbols.
  • Use virus/malware protection and always keep it up to date. Scan regularly.
    If you do not have virus protection, Microsoft Security Essentials is a good free option for Windows.
  • Verify your Steam email (https://support.steampowered.com/kb_art ... 543#verify)
  • Enable Steam Guard (https://support.steampowered.com/kb_art ... -ALZM-5519)
  • Finally, always use common sense. This is the most powerful defense.
    • DO NOT download any files from unknown sources.
    • DO NOT follow ambiguous or shortened links. There should be no reason to use shortened links on Steam.
To be safe, I recommend only logging into Steam via the Steam client, and not via a website. However, if you are going to log in via the Steam or Steam Community website, always check the address and that the website is verified. SSL certificates are a secure way to verify that a website is legitimate.

Here is what an official Steam site looks like in some popular browsers:
Image
Note the website address from the list above and the "https://" prefix as well as the identification of "Valve Corporation." This is a sure sign of an official website.
If you do not see this identification, the website is not real!

I found a phishing website. What should I do?
You should report the website so it can be blocked to prevent others from falling into the trap:
FireFox: Help > Report Web Forgery...
Internet Explorer: Tools > Phishing Filter > Report This Website
Others: Go to http://www.google.com/safebrowsing/report_phish/

My account was hijacked! What should I do?
See: https://support.steampowered.com/kb_art ... -QDFN-4366


So I hope at least some of you learn something from this and that this prevents stolen accounts in the future. Knowing what to look for is the best way to avoid phishing scams. Let me know if you have any questions or if I forgot anything. :)
Last edited by Stevo on Sun Aug 30, 2009 8:48 pm, edited 2 times in total.

matt101
Villun
Villun
User avatar
Posts: 297
Joined: Thu Feb 21, 2008 8:44 pm

Games Played

Ville Awards

Matt101’s avatar
Loading…

Post by matt101 » Mon Apr 13, 2009 1:02 pm

Well said Stevo

Yahoo!!
Villun
Villun
User avatar
Posts: 1076
Joined: Sat Dec 01, 2007 3:32 pm
Location: Calgary Alberta

Games Played

Ville Awards

Yahoo!!’s avatar
Loading…

Re: WARNING: Protecting Your Steam Account

Post by Yahoo!! » Mon Apr 13, 2009 1:14 pm

Can we get a sticky for this thread please.

Not sure if it needs to be a global sticky or not like the intro thread.

sgt stutter
Server Ops
Server Ops
User avatar
Posts: 7242
Joined: Sun Oct 15, 2006 3:47 pm
Location: May as well be Canada

Games Played

Ville Awards

Post by sgt stutter » Mon Apr 13, 2009 1:22 pm

I'll sticky and lock, no need for spam on this thread.

Thanks stevo
Image
RIP-Trigger
RIP-Blue
RIP-Stevo

Stevo
Everlasting Villun
Everlasting Villun
User avatar
Posts: 8753
Joined: Sun Oct 22, 2006 10:01 pm
Location: Orange County, CA
Minecraft name: StevoTVR
Uplay name: StevoTVR
Contact:

Games Played

Ville Awards

StevoTVR’s avatar
Loading…

Re: WARNING: Protecting Your Steam Account

Post by Stevo » Tue Jul 07, 2009 1:39 pm

Updated to account for the latest scam.

Do not follow strange links or download files from unknown sources.

Stevo
Everlasting Villun
Everlasting Villun
User avatar
Posts: 8753
Joined: Sun Oct 22, 2006 10:01 pm
Location: Orange County, CA
Minecraft name: StevoTVR
Uplay name: StevoTVR
Contact:

Games Played

Ville Awards

StevoTVR’s avatar
Loading…

Re: WARNING: Protecting Your Steam Account

Post by Stevo » Sun Aug 30, 2009 8:52 pm

Added instructions for verifying your Steam email address. Once you have verified your email, it will be used to confirm any changes to your account. This makes it impossible for someone to hijack your account without access to your email. For more info see Steam support.
  1. Go to Settings (right-click Steam try icon and select Settings or go to File->Settings)
  2. Make sure your contact email is correct
  3. Click Verify email address (if it isn't there and it says Verified next to your email, you are already set)
  4. Follow the instructions
  5. Wait for an email from Steam support and follow the included link
  6. It should now say Verified next to your contact email

Locked

Who is online

Users browsing this forum: No registered users and 46 guests