Share:
Add to Favorites   |  

Here's An Example Of A Phishing Attempt On A Steam Account

8965 views

Back in March we posted a warning about thieves masquerading as Steam in order to get into customers' accounts and download games to resell. One reader, Richard, just received this special "alert" on his Steam IM pane this evening.




Remember to always be on your guard for stupid stunts like this. If someone is alerting you to a security risk, take the time to contact the business yourself through the standard address you've always used. And of course never click a link someone gives you as part of a security warning.

Post a comment

Comments:

46
user-pic
Ben Edwards
Flag for review

Such a great scam; almost anyone online has heard 'they have an IP'. What they rarely know is that IP's are not static like a phone number.

user-pic

The things people fall for amaze me... I got a phone call the other day saying I won a trip to Florida and a cruise to the Bahamas. They said I had qualified with a recent credit card purchase at a participating retailer and just needed my Mastercard number beginning with the number 5 to verify...


p.s. for those not in the know, last time I checked all Mastercard issuer identifiers begin with the number 5...

user-pic

once I went into MySpace and received a message from my friend Monica alerting me that my photo had been published on a site and that I should go check it out. so I went and upon loading the page I was asked for my MySpace email and password. I thought they wanted me to set up an account with them so I put my email address but a different password. I forgot what happened afterwords but none of my photos were on that site and upon my return to MySpace half an hour later I was tol my acount was phished or whatever. all I had to do was sign in.

Monica later told me she never sent that email although she got something similar from her friend

user-pic

The great thing about Steam is that it's actually designed so that you can play your games on multiple computers, so the very nature of these phishing attempts is kind of silly.

user-pic

@Ben Edwards: They usually are for days, weeks, sometimes months.

user-pic

@Michael Monaco:

Exactly!

By the way, I also know a Michael Monaco who occaisionally plays on Steam, is a recent medical professional, and can create concise, cogent points.

Based on the unlikely odds, it is my theory that you are his subconscious doppleganger that is revealed during his moments of sleep.

I'd like to hear your comments on my theory.

user-pic

@Ben Edwards:

Mine's static, I've had it for more than 10 years.

user-pic

I think the real lesson here is: Don't trust links that end with '.tk'. I've learned that one the hard way.

user-pic

@Ben Edwards: IPs are much like opinions. Some fluid, others unchanging. Others wrong. :)

user-pic

If someone tried taking my Team Fortress 2 account off me, I'd give them such a hosing down with flaming napalm.

user-pic

they've been trying to do this for quite some time now, lemmie see if i can dig up some screen caps of this...

user-pic

@Ben Edwards: Mine's static. Most ISPs provide dynamic and charge for a static. I choose to pay for a block of static IPs being that I run servers off my DSL. (To clarify, I don't run mission-critical services - that'd be really, really stupid to run off a home connection - just small things that simply aren't worth the cost of a dedicated box.)

user-pic

the sad part is, contacting steam customer support is usually near impossible.

user-pic

The part of this message that makes me laugh is that the title is "Never give out your password to anyone" then they ask you for your password.

user-pic

@Elk: I won't trust a company that doesn't capitalize their own name.

user-pic

@cuchanu: No, they asked him to login. They didn't asked for his password. Not quite the same thing.

user-pic

@cuchanu: The funny thing is, that message appears every time you open an IM with someone on steam and people STILL fall for this kind of crap.

user-pic

@Mackinstyle: That's not static though, it's merely a very, very long DHCP lease.

user-pic

@Michael Monaco: If the person who phishes the account cheats at a game and gets VAC banned, you've just lost the ability to play multiplayer on all your games. Also, if your CC info is stored, they can buy games as 'gifts' for others.

user-pic

It amazes me that some people do still fall for this nonsense. You think they could at least try to be a little creative.

user-pic

@Moosehawk: They don't need to be creative if people still fall for this.

user-pic

It really doesn't surprise me that people fall for this-- Steam is an online game service, and I think that at least there are some people who just are clueless about computers, but able enough to set up online gaming accounts (like parents for their kids, etc.). So, of course there will be some percentage of ill-informed people that will fall for these scams.

user-pic

@Trai_Dep: And when you keep your opinion to yourself: 127.0.0.1

user-pic

@WiiPoleNotIncluded_GitEmSteveDave:er, why? some people do that as a stlye/design thing.

user-pic

The funniest part of this to me is that the phisher's argument really doesn't make sense. Very few people have static IP addresses for their home Internet connection, so it's actually logical that multiple IPs would have logged into the Steam account even if it was all from the guy's home.

user-pic

What a great phrase, masquerading as steam... it sounds like something Merlin would do.

user-pic

The problem with Steam is that they don't have an easy or efficient way to contact them about anything, even account problems. Their forum is the only way to contact them, and that is unlikely to get their attention either. So when they receive these kind of scam attempts and try to verify the information, they simply can't until a number of people have tried. That leads to many a fail in the beginning.

user-pic

I've recently been getting text messages to my phone from "Chase" requiring me to call a number because there's been some fraudulent activity on my account. I know not to call it, but I know for SURE that if it happened to my mom or a few of my friends would have called it. It's tough, you really have to be vigilant and protect your identity well.

user-pic

@Optimus:
"So when they receive..." => "So when a person receives..."

user-pic

@arstal: Yay TF2!
We need to get a Consumerist clan, quickly becoming the acknowledged masters of the snarky putdown and the kitteh graffiti. And dying. Lots and lots of dying.

user-pic

@jc364: if you unplug your equipment and re plug it in later it will give you a new IP unless it's static.

user-pic

@Ben Edwards: Static IP's are usually only given out on business plans or as requested by the user. If everyone was given static IP's 100% of the time, services that linked your current ip to an online url wouldn't be needed anymore (the homeip.net service comes to mind).

Dialup ip's are dynamic, cable modem ip's are static if there is a constant connection, DSL ip's are typically dynamic unless otherwise requested.

user-pic

@Skankingmike: Sorry, 127.0.0.1 refers back to the localhost. I guess it was a bad attempt of a joke ;)

user-pic

Is :: a generic thing phishers use? The phishers steam name is ::, same name of someone that phished a few of my friends. Tried to phish me, I messed with his head, and he threatened to "Hack my pc with my ip address that he got from the steam chat." So I mean, your not dealing with the most intelligent individuals ever here if its more then one. If its one, hes really persistent.

user-pic

Well, that was fast: I tried going to steamprotectip.tk, and it's already a placeholder site. Guess they didn't like the publicity.

user-pic

I like this one:

[futuremark.yougamers.com]

somehow all these Steam Scam turn-abouts end up with "Go mow some lawns" Are Steam gamers really hung up on "mowing lawns"?

user-pic

@Skankingmike: Not true. I have a "dynamic" ip with comcast and mine changes about once a month and it even if I unplug everything for hours it stays the same. It depends on the ISP.

user-pic

@Révolution: It's up.
[steamcommunity.com]
PM me for admin. (On gawker, not steam)

user-pic

@parad0x360: Even if you are given a dynamic one, you can manually change it to a static one. FWIW.

user-pic

@Révolution: Awesome!
Joined just now. Fair warning, though, I only play a couple hours a week (not bad, considering, but only play a few hours a week)

user-pic

@arstal: First set on fire.
Then run to Supply Depo to switch classes.
Then Jarate them!

(Jarate only puts out teammate's fire, right? So enemies would burn... Slowly?)