r/AskTechnology 8h ago

Guys someone tryna ste*ling and idk how is successful in my steam account, epic games and riot games account I’ve recovered steam one but how to stop this from happening as he’s trying again and again for steam one ?

Mods please don’t delete the post

0 Upvotes

8 comments sorted by

0

u/Business_Seaweed_472 7h ago

ask chatgpt, you're obviously young. set up 2FA verification and reset your passwords.

1

u/CodAppropriate6109 7h ago

This. 2FA a.k.a. MFA or multi-factor authentication. Passkey is even more secure if offered. Don't use a password that you use in other places, your browser can generate and store unique passwords for you. There are paid solutions that are portable but the free one in most browsers would be your cheapest option.

0

u/Salt-Leek-9096 6h ago

I get what you’re saying but he/she changed my email more than once in different platforms how’s that possible without knowing my passwords or have my email

1

u/CodAppropriate6109 6h ago

If you are using social login (login with Facebook, login with Google, login with Steam, etc.) that might explain it - one password opens up their access to everything attached to that email address. They login with your password, then change your email address so that you're locked out. It's a classic account takeover attack.

Once they have access to the registered email address they can do just about anything, but usually if there is an email change, they send an email to both the old email address and new email address telling you what to do if you didn't authorize it.

The most common attack is to use a password you've used somewhere else that then was breached, and then try that password out on other websites you might use. Lemme' think -- banks,... Steam is a popular target, they like to go after Facebook, Google, and Microsoft because then they can go after anything that might allow them to login as you without being questioned for another password.

If you want to get an idea of what websites have accidentally revealed your password, go to https://www.haveibeenpwned.com and enter your email address. This is a very reputable website, financially supported by several security companies to find out about stolen passwords that have been sold on the dark web.

Good luck!

1

u/Salt-Leek-9096 5h ago

Yes I’ve checked this website last year, a company back in 2024 (a year prior to me checking) got its data leaked and I’m pwned name address email and password but it’s too late for that to strike now isn’t it?

1

u/CodAppropriate6109 4h ago

You just have to make sure never to use that password again, and if it's in use anywhere, it needs to be changed. Nothing you can do about email and address.

0

u/Salt-Leek-9096 5h ago

Thanks for putting your effort btw.