My Steam on Windows got hacked and I lose 7750rs.

nikola

Contributor
So Where to start? hmm... OK

This is the first time i lost money online in my life, and i still don't know how this happened, so I am going through all the steps if someone can spot something and help other to be safe online.

So I am an adult using steam for more than 8 years, I just play CS for fun and I was collecting CS cases to sell and buy games from that money. A year back when CS2 launched cases prices go high and i made 7k from that. Since I was not gaming because of many reason.

On 1st of June 2025 I tried to sell a case but steam denied it because i haven't used (made any purchases) steam for last one year all my steam wallet money was sitting there, Assuming its safe.
2nd of June I bought cheap game so i can sell my cases.
13th of June (Today 1:03 am) someone bought Dota stuff worth 10rs for whooping 7749rs from my steam account and I have not get any single notification/mail/message.

Lets talk about security.
I have my personal Desktop PC and Nobody have access of it. On which my steam windows app is installed. (Removed possibility of in person hijacking)
I have 2FA on with Steam Guard on my phone and also i have not given access of my phone. (Removed possibility of hijacking through steam guard)
I have never sign in on steam on browser since i am using steam, only steam windows app. (Removed possibility of hijacking through browser cookies)
I have never given any third-party app or site to sign in using steam.
I have not entered Steam API or created API.
In last week I had downloaded only 2 apps, fan control from GitHub and hwinfo from direct download.
Email and mobile no associated with steam is my privet i.e I don't enter it to any random website.
Last one I use windows defender for protection. (I just replied yesterday to someone in this site that i never have virus issue for past few years as user of win defender)
Also i have every single notification is turn on for selling/buying/trading stuff from steam market.

Now what i have done after this.
Scanned my system using Malwarebytes for malwares and it only detected my torrent client as malware which is i am using for years.
Deauthorize all my steam devices (PC and phone).
Changed my password of steam on other pc.
Changed my backup-codes.
Cleared all cookies from browser.
I also have contacted the steam but they have not replied yet and I know they dont refund once sold steam market item.

Good thing is I have not saved my Card information on steam and all of my steam wallet money was from selling cases but money is money. Hacker have not changed my password or email-id i wonder why?
Steam will not give refund or ban that person who sold 0.5rs item for 10-1000rs because thats how they make money shameless steam even though they know there are thousand of dollars of scam happens every day and that money goes into illegal activities. Internet says 77000 steam account get hijacked every months.

Every Purchased was made from same guy whose display name is ceygiojg0079.

So if any security expert reading this can explain how the F*** this happened i would appreciate the help.
And also DONT KEEP MONEY IN STEAM WALLET.

I have attached Screenshot what they bought for x10 to x100 price of original worth. one item for 1200 and 80 items for 82.13 Screenshot 2025-06-13 202246.png1.png2.pngx8
 

Attachments

  • Name.png
    Name.png
    25.9 KB · Views: 37
  • 1749837949461.png
    1749837949461.png
    26.9 KB · Views: 31
Last edited:
I mean this left me stranded how could this happened with this much safety net and Steam acting as money hording company for millions of people. There are people who lost 5k usd worth of inventory still helpless.
 
What is utorrent doing on your PC? What torrents you downloaded? If you had to use torrent why didn’t you use bittorrent which is open source?
i havent used it for year now it was portable torrent client just laying around, and im more than 100% sure it was not the problem. I think last time i download a file using torrent was linux distro.
no shady shady.
 
No idea. Think, maybe you missed something. Any of your steam friends/non-friends sent you any suspicious messages?
nah i know this can be possible but not the case, no suspicious messages and i dont click and link from unknown person.
Also CS is so toxic game i Just dont talk or read/reply messages from my friend. :)
 
This seems similar to below. Some stupid victim blaming replies in the thread, but op issues looks similar.

Somehow the thief got access to your steam account - either password or session.
Apparently items less than a dollar are exempt from 2nd factor which is abused through multiple transactions.

Hard to believe that steam doesn't know this and couldn't understand the obvious problem. Whats the point of 2factor for market if you leave an obvious flaw and then don't fix it either.

 
Are you this guy who posted on r/indiangaming ?

He later claim his other accounts were hacked like Ubisoft,Epic etc which only indicates the problem lies elsewhere.
Me thinks, support is ignoring these cases because it doesn’t trigger anything on their end, which means it’s some sort of session hijack on your pc. The machine and IP listed for those transactions must be same as yours.

Highly likely this attack is executed on your pc remotely.
 
Just to be safe (if not done already) do change the password of everything you can. I personally would panic & fresh install the OS itself before/after the password reset.
yep already did changed password and back up code not gonna lie, already thinking about clean wiping os. Also i dont sahre similar password with other sites so...
Somehow the thief got access to your steam account - either password or session.
Apparently items less than a dollar are exempt from 2nd factor which is abused through multiple transactions.
I know this can be case, but even with all security measure from steam and my self this happend, and all people who are victim of this kind of attacks give steam theif's steam id, they dont ban them and dont refund. so only reason for steam to do not take action against them is to make profit from sales.
 
Last edited:
Yes as Tracer_Bullet said in earlier reply steam must know this and apparently dont want to fix it either
It's far worse than what the previous commenter was suggesting: there's no mfa confirmation for purchases regardless of purchase value eg: If the hacker purchased an item for $500, they still wouldn't get asked for mfa.

Unless you're going to examine the network requests going out of your system, you should format and reinstall windows. Considering this optional is a mistake.