All posts
Technology

They Got Into Your Steam Account and You Had 2FA On. Here's Why Changing Your Password First Was the Wrong Move.

Session-token theft walks straight past Steam Guard, and changing your password on the infected machine just hands over the new one. The right order, and what won't come back.

9 views
Photo: Vlada Karpovich / Pexels
A conversation with a TrueTalk advisor about: They Got Into Your Steam Account and You Had 2FA On. Here's Why Changing Your Password First Was the Wrong Move.

An hour after you changed the password, they were still in

The second trade goes out sixty minutes after the password change. Say that's how yours went, because that's usually how it goes: a six-year-old account, a few hundred dollars of inventory, thirty-odd dollars sitting in the wallet, and an email on file that's now some address you've never seen.

You did what everyone says to do. New password, straight away, from the desktop you were sitting at.

You had Steam Guard on the whole time.

What happened to you is a different attack from the one that advice was written for.

Nobody guessed your password

The thing that hurt you is probably an infostealer — a category of malware whose entire job is to be run once on a machine and hoover up whatever is already logged in. Browser cookies. Saved passwords. Crypto wallet files. And, specifically, the session tokens that games and chat clients keep on disk so you don't have to log in every morning.

A session token is the part people don't think about. It isn't a password and it isn't a code. It's proof, already issued, that somebody at this keyboard passed the login check earlier. Paste that token into another machine and the platform sees a session that has already cleared authentication. There's nothing left for two-factor to challenge. The gate was passed hours ago. The attacker walked in through a door you left open behind you.

Which is why Steam Guard didn't save you, and why it isn't useless either. It stops a completely different attack that also gets tried on you constantly. It just wasn't built for this one.

It's also why changing your password on the infected machine was the wrong first move. Some platforms do end every existing session when a password changes; some don't, and the behaviour shifts between versions. But that's the smaller problem. The bigger one is that if the thing is still resident, you just typed the new password into a machine the attacker controls.

Honest caveat: plenty of stealers are grab-and-go. Run once, exfiltrate, exit, no persistence. Yours might not be there any more. You can't tell which kind you have from the outside, and a clean scan doesn't settle it.

The order that actually works

Do all of this from a different device — a phone, a friend's laptop, anything that wasn't there when you clicked the link.

1. The email account first. Everything else recovers through email. If they've already changed the Steam address, your email was almost certainly the first thing they took, and every step below can be undone by whoever still reads your inbox. Recover it, change the password from the clean device, then check for forwarding rules and filters they've added — the classic move is a rule that auto-deletes anything from Steam or Discord so you never see the notifications. Sign out all sessions on the email account too.

2. Clean or abandon the machine. Not a scan. A scan that comes back clean tells you the scanner didn't recognise anything, and stealer builds get churned out faster than signatures get written. The only answer you can trust is a full wipe and reinstall of the operating system, from installation media, with your files backed up as data and nothing executable carried across. That's a miserable afternoon. It's also the only step that makes the rest of this stick, and skipping it is why people do the whole recovery twice.

3. Kill the sessions, before you rotate anything. Steam has a deauthorize-all-devices control in the Steam Guard section of your account details, and Discord lists active sessions under its device settings. Find the current version of each yourself rather than following a two-year-old screenshot; these menus move. This is the step that actually evicts the person using your stolen cookie.

4. Now change passwords. From the clean device. Unique per site, in a password manager. If you reused that password anywhere else — and you probably did, on something old — those accounts are gone too, they just haven't been used yet.

5. Revoke API keys. This one gets missed, and it's why some people get robbed again a week after they think they're safe. A Steam Web API key registered on your account can be used to watch and interfere with trades even after you've taken the password back. Look at steamcommunity.com/dev/apikey and revoke anything sitting there that you didn't create. Do the same sweep for connected apps and authorised third-party sites on both platforms.

6. Then file the support ticket. Not first. First is the instinct, and it wastes the hours that matter, because while you sit in a queue the session is still live.

What you are not getting back

Assume the traded items are gone.

Steam's published support policy on restoring items lost in trades is not encouraging, and it's worth reading the current version yourself rather than taking a forum thread's word for it. But do not organise your week around getting your inventory restored. People spend a fortnight escalating a ticket, refreshing it hourly, writing longer and longer replies, and the answer they get on day fourteen is the answer they got on day one.

The account itself is usually recoverable. The wallet balance and the items usually aren't. Purchased games generally stay with the account, which is the one piece of good news in here.

How it got in, so it doesn't happen twice

It was almost certainly something you ran or somewhere you typed.

A message from a friend whose account was already taken, asking you to vote for their team in a tournament. A free key for a game that isn't out. An invite to playtest an indie project, with a download attached. A page that looks exactly like the Steam login prompt, floating inside a browser window, which is not a browser window at all but a picture of one drawn by the page underneath.

The common shape: it arrives from someone you know, it's slightly urgent, and it asks for one small action. Same as every other confidence trick, just faster.

Cybersecurity Sam on TrueTalk is an AI you can throw the blast-radius question at while the ticket sits in a queue — what else was logged in on that box, what else used that password. It can't run Steam's recovery flow. Only Steam can.

Your password was never the weak point and it won't be next time either. The weak point is that your machine holds proof-of-login for a dozen services, all day, in files, and any program you run can read them.

Which leaves one thing to do before you close this tab. Steam applies a hold to trades when the mobile authenticator isn't in the picture, and the current windows are on Steam's support pages. If a hold caught anything that went out of your account, it's still in flight, and that hold is the only lever in this entire mess with a clock running on it.

Go and check that now, before the wipe, before the ticket, before anything else.

account securitygamingmalwaretwo-factor authenticationsteam