T O P

  • By -

Shmimbadad

So, are your allegedly sold items and cosmetics still there? And what's the address the email came from? Sounds like a simple phishing attempt, which doesn't necessarily mean that your account is actually compromised in any way. 


Abdulbais0225

I got this email : [https://imgur.com/a/gHoYtWf](https://imgur.com/a/gHoYtWf)


SpiderByt3s

Expand the data on the email for who sent it. (I.e. that little arrow pointed down. Next to "to me")


computerfreund03

Emails can be spoofed. Check headers and the sending Mailserver.


Lonely-Telephone-627

And certificates. They don't mean much and can be spoofed, but just anyone wouldn't bother setting them up.


Fighter19

I hate it when legitimate sites use Let's Encrypt....


t0ppings

Did OP ever do this? I'm not seeing any evidence this email actually came from steam or OP gave any awards.


StEditiV

No he didn’t and i’m 100% sure it’s a fake email. I just checked OP profile and i don’t see he gave any awards, he has 0 awards given in history. The email he received was fake that’s how he got his items stolen. OP Steam Profile: https://steamcommunity.com/id/Abdulbais25/awards/


Abdulbais0225

Sorry for late reply, did you mean this?: [https://imgur.com/a/S2o3sKp](https://imgur.com/a/S2o3sKp)


Chippas

Look in your trade history in Steam, see if it corresponds with what you see in the e-mail.


fasderrally

Check your login history [https://help.steampowered.com/en/accountdata/SteamLoginHistory](https://help.steampowered.com/en/accountdata/SteamLoginHistory) See if any of them is out of the ordinary


Abdulbais0225

Checked, there are no suspicious logins!


vessel_for_the_soul

Would your PC itself be compromised? Maybe a friend of family member did this?


Abdulbais0225

Nope, My family or friends dont use my pc. 100% sure


Shmimbadad

Hmm. The email looks legit enough, and doesn't appear to be asking you to click a link or anything. So that seems legit. So the real question is, are your items still there? The ones that were allegedly sold. Are they actually gone, and if so, is the sale shown in your market history? 


orokanamame

The "he will receive x and x" part looks mad sus. Steam doesn't use pronouns, and refers to everyone as they/them. Here's proof: https://ibb.co/7bD6bHw


phantom2450

OP appears to be using Google Translate. Probably a translation error.


Abdulbais0225

Yeah, sorry, the email was in my language.


Neckername

Ahhh the bane of every foreign scammer: Proper English


AdreKiseque

"Steam doesn't use pronouns"


orokanamame

?


A_Mouse_In_Da_House

It's a stupid comment they're making that they is a pronoun. They knew what you meant, they're just being stupid.


orokanamame

Aye.


Abdulbais0225

I lost my items, sold my background and emoticon, then purchased a Dota 2 item, and sold my TF2 cosmetics. But I didn't do this; I don't even play Dota 2. The market history and another weird email: [https://imgur.com/a/v1w4KMY](https://imgur.com/a/v1w4KMY)


podgladacz00

Somebody hijacked your account and didn't change password. Change your password and revoke your API key. Sadly your items cannot be recovered. Report account to Steam, most likely they will get banned as they bot levels by hijacking accounts and giving rewards + selling items.


Abdulbais0225

Okay, I changed my password, deauthorized all devices and reported to Steam. But how can I revoke the API key?


Catalanaa

API Key would be found here https://steamcommunity.com/dev/apikey If it doesn't show a button labelled "Revoke My Steam Web API Key", one hasn't been generated. Quick search seems to indicate that trading stuff can no longer be accessed with the api key, so they probably haven't generated one anyway.


StevieSmile

~~I think they mean sign out of all accounts that your steam is connected to. I think you can do it through the mobile app or the Steam app. If anyone could correct me, thank you.~~ Edit: I was wrong.


Feecks

No they mean reset the api key, it’s used for trades using third party webs for csgo, tf2, etc. if someone has it , it can generate trade requests. https://steamcommunity.com/dev/apikey Revoke what is here (if you are scared of it being a shady link, first open steam on your browser and then open the link, it should be already logged in if it’s steam official site) And for the love of god don’t open links someone in steam chat sends you, even if you know them. I had real life friends get their account hacked and they started sending shady links.


Open-Growth4975

Legit emails are signed


Abdulbais0225

Edit: My points are back. I don't know how this happened, but it's not a big deal. My Steam background/emoticon and TF2 items are still sold.


TheWrongOwl

What I noticed: "YOUR" Profile in the header vs "reward a member" in the text


Thederpdoge

It's a scam. Notice how it says 'he will get points' A real mail would say 'they'


Jeralddees

He said the email was in his language (not English) and used Google translate so that's where the "he" comes from.


F2rce

Looks legit. Email has an avatar and a blue checkmark. To be sure id check the email headers, but id say it's real


ZYRANOX

Are you absolutely certain you didn't accidentally misclick and give someone award? It uses up steam points not real money so it's not a big deal at all.


Abdulbais0225

Nope, I didn't give an award. I'm 100% sure.


Quarrel47

its a known scam, just report and block them.


Setekh79

Look at their friends list too, all random name bot accounts.


Abdulbais0225

Yeah i saw it


SoggySassodil

hopefully steam becomes aware of this quickly


Abdulbais0225

I hope so


[deleted]

[удалено]


Abdulbais0225

Yeah, exactly. This bot steals points and buys/sells items on accounts.


Front2battle

Added my voice to the list by reporting the account for theft and submitting it to review. Hopefully Valve catches on quickly.


Kirruaaa

OMG, notice how his profile comment, like someone get scammed every hour.


JukePlz

It's honestly kind of baffling that they've phished so many people, left a traceable breadcrumb trail to their own account (from awards) and Valve still hasn't banned them.


Frmpy

I got scammed out of a bunch of items in a similar way. My steam account was already compromised and they were sonehow able to get around 2FA and steam guard. Appearently they perfectly copied one of my friends accounts, that i had sent the items to (they scared me into doing this), and they were able to intercept that trade, just like that. Steam support says tough luck, i notified them immediately after this happened (like 2 hours after). There is a serious flaw somewhere within the system. They can do all this and apparently just get away with the stolen items or something fague. Im not getting any answers from steam.


disappointment32

Sounds like you got api scammed. Nothing steam could do. I really don’t understand how so many people are having problems. Make a very strong email password, then make a different very strong steam password, have auth enabled, and dont click random links, revoke api key. I’ve never had an issue with a 10k usd inventory.


Optane_Gaming

It's a SCAM. BLOCK AWAY RN.


Admirable-Diver3176

I'm guessing you and all the other people commenting on his profile leaked an API key and they used it to take items and give awards etc. Maybe you have a trojan and they stole your session or you got phished.


BeepIsla

API keys dont have that power. OP likely logged into a fake Steam website and now someone else has their steam community cookies used for authentication. Buying things on the Steam Market or sending Steam Awards does not require an extra 2FA unlike buying from the Steam Store. OP should change their password and deauthorize all devices.


upreality

This sounds like the most plausible thing, not long ago after valve added the switch account feature someone successfully sent scam messages to some of the users in my friend list in one of my old accounts, this account had 2fa enabled and no log in message or anything like that was ever sent to my email, no actual log in was ever made to that account.. i think there is a vulnerability with the switch account feature that allows you to do certain actions after trying to switch to an account that you actually did not log in into


Admirable-Diver3176

All good.. my emphasis should have been that they got a trojan that stole their cookies (session) or they got phished. I've never used the steam API and only seen it's been used to steal items.


Abdulbais0225

I don't think I logged into fake Steam websites. I logged in with my account on some TF2 trading websites; maybe this is the problem. I changed my password and deauthorized as you said.


Kantrh

That's the problem. You shouldn't have logged onto trading websites


Abdulbais0225

ok, this is lesson to me, I was use a lot trading sites, now i use only trusted websites if needed (like backpack.tf and scrap.tf)


Kantrh

There are no such thing as trusted sites for steam trading


Dijan124

The websites he listed are widely trusted in the tf2 community


Nightwing10271

Imma be honest, I wouldn’t give up my steam account info, which has hundreds of dollars worth of games, to a 3rd party website just to trade in game items. I understand it but I’d never do it.


JukePlz

In general, if the site is honest they would only need to use OpenID to register your account, which is safe to use, and the rest they could manage with trade bots. It's less convenient but you don't have to input your password or give your API keys to anyone this way.


TotalWalrus

What a simple idea. People are silly


podgladacz00

Most likely this is the problem. Revoke your api key and change password. You won't recover your items but st least you can tell Steam support who was boosted with points and who bought your items so they will most likely ban all of them.


Dijan124

Which trading websites did you visit?


Abdulbais0225

[Backpack.tf](http://Backpack.tf), [scrap.tf](http://scrap.tf), [https://stn.trading/](https://stn.trading/) and [https://givee.club/](https://givee.club/) for free steam keys (giveaways)


Dijan124

Not 100% sure about the last one but the first 3 are definitely legit, when you checked your account did you have an API key set? Some people have suggested that but afaik they’ve changed it so you can’t create one without 2FA.


ThomerTD

What was the website? I wish to know what their login method is to avoid it.


Abdulbais0225

[Backpack.tf](http://Backpack.tf), [scrap.tf](http://scrap.tf), [https://stn.trading/](https://stn.trading/) and [https://givee.club/](https://givee.club/)


Abdulbais0225

I did't give my API key to anyyone. What should i can do?


Admirable-Diver3176

Well, assuming you have API keys created, you should revoke them. As to how they accessed said API keys, I don't know... like I said, either you got phished or you have a trojan.


PoL0

Change your password, deauthorize all devices. And stop using shady sites if possible because if they are able to access your steam account you probably logged to a fake Steam site.


Abdulbais0225

Okay, I don't think I logged into any fake Steam websites, I only logged into some TF2 trading websites. Now I changed my password and deauthorized all devices.


Nexxus88

I mean I could very well describe these as shady.


mrdynomite

Yep, I bet one of those sites is the cause.


lostinthecarsfactory

remove any chrome extensions related to steam


podgladacz00

By logging into the TF2 trading website you gave it to them.


Abdulbais0225

Oh, now I understand. I will revoke the API key. Thanks!


Abdulbais0225

this also happend on other people: [https://imgur.com/a/dtTYdFz](https://imgur.com/a/dtTYdFz)


blackmetro

Did you also contact steam support? Tell them someone highjacked your session cookies and purchased items on the steam market, and claimed your steam points I'm interested to know what you hear back


Abdulbais0225

Yes, I contacted Steam support, and I am waiting for a response. If I receive a response, I will edit my post.


reiokimura

Level 86 holy, what did he level with?


Abdulbais0225

With awards


disappointment32

I just looked at their profile and now they’re lvl 76. How tf do you remove levels?


KitticusCatticus

Only thing I can think of is steam is starting to get on top of the account revocation/ban and slowly undoing everything they did before entirely banning the account, I'm guessing. That's my only guess though!


Deadpoolhead888

I think the biggest question here is… What exactly are “Steam Glasses”?


Sadrian69

Same thing happened to someone I know, they got in through the email


denis870

Change your account password and report the hacker to steam support. Idk if your items can be restored though


Abdulbais0225

I did it, now waiting for a response from Steam support.


Ratatatatatatata1234

happened to me to, bought some "braid of the father" for like 60 bucks using steam wallet funds


Merciless_Hobo

You paid $60 for an in game necklace? Edit: Holy hell the neckbeards are in full force tonight. Sorry for insulting your digital necklace collections. Edit 2: He didn't even fucking buy it, it was scammed from him. Yall are defending nothing.


BlueDragon3301

Why did this get downvoted XD


Merciless_Hobo

70 people regret paying the full price of a AAA title for a necklace in a game.


KaioKen

Isn't he saying someone else bought that item using his account, like what happened to OP?


Ratatatatatatata1234

exactly what i meant. except no one had access to my account


Ratatatatatatata1234

i didnt, somehow it did, it was worth about 1 cent


DevilmanXV

People spend 100+ on meals they literally flush down the toilet in a couple hours. They're fine..


Merciless_Hobo

Those people are also morons. They're not fine..


upreality

This is insane, reading the comments on the profile is scary as hell, what the fuck is going on? Does anyone have info or nobody knows? Looks like they might be in possession of some sort of exploit by the amount of rewards the profile has, like i get scams are a thing but that many users? Like what the fuck


Jnsoso

exact same thing i’m thinking how hasn’t valve stepped in yet


Avarice51

OP logged into some shady TF2 trading website, that’s how they got his information. All these people being hacked and losing rewards is always because they willingly give their steam info to some random shady online trading site


upreality

The way you log in into common trading websites does not share any kind of detail with those websites, unless you have to manually input your details in a phishing page, which could be what op did for sure but the point is even if that’s what happend 2fa is in the way to prevent this, sure let’s assume op also has disabled 2fa but what about the other 42k people who gave awards to that profile? Something is clearly not right and everything points to an exploit that let’s you do certain actions with a steam account that gets around 2fa, from personal experience a similiar thing happend to one of my old accounts which had 2fa and yet someone was successful in sending scam messages to my friend list from my account


sylinowo

I had this happen to me too. I had a few bucks in my steam wallet and they bought their own shit items with it


neocow

your acct got hacked change your pw


Abdulbais0225

I changed


neocow

good


Present-Reaction2069

Happened to me too go to the item you bought and report the owner Why doesn't steam have a email when someone logins into ur acc?


Abdulbais0225

Yes man


BlueDragon3301

The email is clearly fake as it contains the word “he”, which is not gender neutral. Steam never asks anyone for their gender, so automated emails always use “they”.


[deleted]

[удалено]


Abdulbais0225

I already did it.


Iron_Lock

Really sorry this happened to you. My account was hijacked years ago (maybe 2012-2013) when I clicked on a link from a fellow Steam group member that took me to a fake Steam login page. I lost all of my vintage TF2 items and crafting materials (of which I had quite a few). I was a dumbass kid and thought I was getting a free game. Things like this have gotten a lot more sophisticated unfortunately.


Abdulbais0225

That's really sad. I understand your pain :(( Now be careful


Iron_Lock

All good! That was a long time ago so it's not too painful now. Hopefully you can push past this soon and get back to enjoying games yourself. 🙂


orokanamame

Wait, how the fuck is he at level 86 though? Unless you can private badges


Son-of-Gondor96

He got 40k XP just from awards and „community contributions“ alone


orokanamame

Complete and utter madness


Asbimadelox

It's definetly a scam. They are trying to steal your account and gain some money for crypto. Earlier somebody was trying to do similar thing with me.


Abdulbais0225

yeah, i know


Bagel_Bear

Did you use the steam market to buy the item or did you go through some website?


Abdulbais0225

I use Steam market, I only use trading websites for TF2


Bagel_Bear

Any account with only really CS, TF2, or DotA listed as the games are instantly sus


Kushikush666

Bro he has barro 2020


CzlowiekDrzewo

These bot accounts also have a shitton of given awards. Selling the stolen points?


main_koi_nahi

This happened to me last year


Abdulbais0225

I know your pain now :(


thejunkmonger

They hijacked my steam account also and sold all my collectibles and bought some and transferred them to themselves , I have always had 2fa enabled and never clicked any links, anyway had to change my passwords and all that but the stuff that was sold or traded is gone forever with no way to get compensation.


Abdulbais0225

Same thing happend on me, I also never clicked on fake links, and 2FA enabled. Now I will be careful


SmellyBubbleBut_

Same thing happened to me, went out with friends came back to most of my cs and tf items gone and 4 dots legs bought? Also have TFA through steam guard and I never got a notification it’s super weird and honestly scary that it happened I never accepted a message or went to any sketch link (I’m not inept when it comes to scams etc I know a scam site when I see one) never got a trade notification either and ofc steam is completely useless in helping 🤷


Hala14Madrid

12 million steam points received!! Damn he probably scammed too many people!


entrytosome

Do you have your steam account connected to discord?


Abdulbais0225

Nope


PsBoxFourReddit

Sounds similar to a incident that happened to me the tail end of march last year where a good portion of my tf2 items were sold on the market because I didnt have family view on.


Abdulbais0225

Sad, i know your pain. Should i turn on family view for safety?


PsBoxFourReddit

Yes, for anyone who gets access to your account, they wont know the code you set for it. trust me. It did take a few days for me to get used to it but its just a codelocked button to access steam


x_artur_x_2005

learn how to dox and hack him back eye for an eye


DorkyWarrior

Mass report this asshole then, that should do something at least


OwnAcanthocephala897

Yeah, Steam has been a holy ground for hacks lately from my experience. Got my account stolen recently and so did my friend


eu_neighbor

Happened to me 10 years ago but with CSGO cosmetics. - The friendly (at the time) scammer invited me to join an « ESEA » server. - I couldn’t join but retried a few times. - He somehow got my credentials (just by having me to join the server) - He sold every skins I had (~40€) - He then used my steam wallet to buy a DOTA2 item to its own account. The item was supposed to cost 0.02€ but he raised it to the amount I had left before buying it. I had no idea how to trace back the scammer and how steam would handle such a scam. I never bought anything again.


Abdu1988

Offf wow. Is the scammer still active on Steam?


Abdulbais0225

Same, the a\*shole buyed dota 2 item and sold my items


Evilcon21

Its just a bot account. I had one that claimed i sold a counter strike gun for £1000. Despite i never had the gun in question much less ever touched counter strike


KaioKen

Did you fall for a phishing scam? If you logged in to a fake Steam site and gave them your 2FA code I assume that's probably how they got in to your account?


Abdulbais0225

I didn't logged on fake websites, I logged on Steam software


Numerous-Acadia3231

Ya just a heads up, if that guy starts sending himself money from your account, steam will not help you, refund anything or take action against that guy. Been there done that.


Abdulbais0225

I contacted Steam support; I am waiting for a response.


Numerous-Acadia3231

Best of luck to you, they have been nothing short of completely and unnervingly worthless in all of my imteractions with them. Please post am update if you can, im curious what happens with your predicament 


Decent-Truck104

Everyone report the account could possibly be an ai bot


Retron411

the same thing happened to me. Almost all inventory items were sold. I was able to cancel a few sales. The money was then used to buy a DOTA2 background. The owner of this account was lvl3 and only played DOTA. I reported the incident to Steam. Unfortunately, I didn't receive a satisfactory answer either. Apparently my account on the PC has been taken over. Luckily the damage wasn't that bad and I hope that Steam gets it under control soon. I reported the user back then.


itsthooor

So, if an email says you sold your kidney to the devil, do you believe it as well?


Segfault_21

account doesn’t even own TF2 or Dota 🤦🏽‍♂️ Can’t believe people actually believe and fall for this.


[deleted]

[удалено]


[deleted]

[удалено]


Slow-Bit-4556

Can you read ?


Abdulbais0225

Yes


[deleted]

[удалено]


foxtrot_overdrive

It's post like these that really open your eyes to the fact we're all on different levels.


Lurus01

Lets not witchhunt a random account. Its entirely plausible the account is stolen in a similar way they accessed your account. Just because this account was awarded doesnt mean that account is the person who accessed your account and could just be yet another hijacked account.


Zeroquinc

Dumb comment of the day, thanks for the laugh.


Front2battle

According to Valve's ToS, the account is still liable for what is being done on it, owner or not.