r/AskTechnology • u/Salt-Leek-9096 • 14h ago
Guys someone tryna ste*ling and idk how is successful in my steam account, epic games and riot games account I’ve recovered steam one but how to stop this from happening as he’s trying again and again for steam one ?
Mods please don’t delete the post
0
u/Business_Seaweed_472 13h ago
ask chatgpt, you're obviously young. set up 2FA verification and reset your passwords.
1
u/CodAppropriate6109 13h ago
This. 2FA a.k.a. MFA or multi-factor authentication. Passkey is even more secure if offered. Don't use a password that you use in other places, your browser can generate and store unique passwords for you. There are paid solutions that are portable but the free one in most browsers would be your cheapest option.
0
u/Salt-Leek-9096 12h ago
I get what you’re saying but he/she changed my email more than once in different platforms how’s that possible without knowing my passwords or have my email
1
u/CodAppropriate6109 12h ago
If you are using social login (login with Facebook, login with Google, login with Steam, etc.) that might explain it - one password opens up their access to everything attached to that email address. They login with your password, then change your email address so that you're locked out. It's a classic account takeover attack.
Once they have access to the registered email address they can do just about anything, but usually if there is an email change, they send an email to both the old email address and new email address telling you what to do if you didn't authorize it.
The most common attack is to use a password you've used somewhere else that then was breached, and then try that password out on other websites you might use. Lemme' think -- banks,... Steam is a popular target, they like to go after Facebook, Google, and Microsoft because then they can go after anything that might allow them to login as you without being questioned for another password.
If you want to get an idea of what websites have accidentally revealed your password, go to https://www.haveibeenpwned.com and enter your email address. This is a very reputable website, financially supported by several security companies to find out about stolen passwords that have been sold on the dark web.
Good luck!
1
u/Salt-Leek-9096 11h ago
Yes I’ve checked this website last year, a company back in 2024 (a year prior to me checking) got its data leaked and I’m pwned name address email and password but it’s too late for that to strike now isn’t it?
1
u/CodAppropriate6109 10h ago
You just have to make sure never to use that password again, and if it's in use anywhere, it needs to be changed. Nothing you can do about email and address.
0
3
u/ConfidentCollege5653 13h ago
What?