Qvantor logo QvantorInfrastructure, explained plainly
Games

How Online Game Accounts Stay Safe From Phishing Emails

Game accounts are worth stealing. A Steam account with a few hundred games, a Counter-Strike 2 inventory with rare skins, a Fortnite account with old season cosmetics, or a World of Warcraft account with a long history can all be resold,...

Shield over a game account login screen

Game accounts are worth stealing. A Steam account with a few hundred games, a Counter-Strike 2 inventory with rare skins, a Fortnite account with old season cosmetics, or a World of Warcraft account with a long history can all be resold, emptied or used to scam the owner's friends. Attackers know this, and players are often younger, more trusting of anything that looks like their favorite game, and less used to thinking of a game login as something sensitive.

I work on account security, and I want to be blunt about one thing up front. Most stolen game accounts are not hacked in any clever technical sense. The owner typed their password and their code into a page that was not real. So this piece is about recognizing that moment, and setting up your account so that even a bad moment does not cost you everything.

What game phishing actually looks like

Phishing aimed at players comes in a handful of familiar shapes. You will see these again and again:

  • The fake security alert. An email saying your account will be suspended for a rules violation unless you "verify" within 24 hours. Urgency is the whole trick.
  • The free item. Free skins, free premium currency, a giveaway for a new season. It links to a login page that looks like the real one.
  • The "I reported you by accident" message. A friend or stranger on Steam or Discord says they mistakenly reported your account and you need to contact a "Valve admin" to fix it. The admin is the scammer.
  • The tournament or team invite. You are invited to join an esports team or vote in a competition, and you must sign in through a page they provide.
  • The fake login popup. A site opens what looks like a separate browser window with a Steam or Discord login, but the window is just a picture drawn inside the page.

Notice that only the first two are classic emails. Much of game phishing now arrives through in game chat, Discord DMs and friend messages, often from an account that was already stolen. That makes the message feel trustworthy, because it really does come from your friend's account.

The advice I disagree with: look for the padlock

For years people were told to check for the padlock icon in the address bar before typing a password. That advice is now close to useless, and it may be making things worse.

The padlock means the connection to the site is encrypted. It does not mean the site is who it claims to be. Free certificates are available to anyone, including scammers, so nearly every phishing page today has a padlock. Players who were taught "padlock means safe" are reassured by exactly the thing that tells them nothing.

"Check the sender address" has a similar problem. It helps sometimes, but legitimate studios send from several domains and email providers, and attackers register lookalike domains that pass a quick glance. Checking is fine. Relying on it is not.

The safest habit is boring: never sign in from a link. Open the app or type the address yourself.

If an email says your account has a problem, close it, open the Steam client or the game launcher you already have installed, and look there. Real account problems show up in the real account. This one habit defeats almost every message in the list above.

How studios try to help, and where it falls short

Studios have reasons to make their genuine emails easy to recognize. Good ones keep transactional messages plain, avoid asking you to click to log in, and never ask for your password by email. They also publish the email authentication records that let Gmail and Outlook catch forged messages using their exact domain. Ilkka explains that side in how online game studios send messages to players.

But authentication only stops attackers from forging the studio's real domain. It does nothing about steampowered-support-center.something or a hundred other lookalikes. That is why the defense has to live partly on your side.

Set up your account so one mistake is not fatal

Here is the order I recommend, from most to least important:

  1. Turn on the strongest second factor the game supports. For Steam, that means the Steam Guard Mobile Authenticator in the Steam app rather than email codes. For Epic, Battle.net, Riot and others, use an authenticator app or the platform's own app. Text message codes are better than nothing, but they can be stolen through SIM swaps.
  2. Use passkeys where offered. Some platforms now support passkeys, which are tied to the real website and simply will not work on a fake page. This is the most phishing resistant option for ordinary players.
  3. Give the game account a unique password. A password manager makes this easy, and it also helps in a quiet way: it will not autofill on a lookalike domain. If your manager does not offer to fill in your Steam password, stop and look at the address.
  4. Secure the email account behind it. Whoever controls your email can reset your game password. Your email deserves the strongest protection you own.
  5. Write down your recovery codes and keep them somewhere offline.

Point three deserves emphasis. I have watched people type their password manually into a fake page because the manager "was not working". It was working. It correctly refused to fill a password into the wrong site.

If it already happened

Speed matters. If you typed your details somewhere suspicious, do these in order, today:

  • Change the game account password from the real app or site.
  • Sign out of all other sessions. Steam, Epic and most launchers have an option for this.
  • Remove and re-add your authenticator if the attacker may have added their own.
  • Check the email account for new forwarding rules or filters. Attackers often add a rule that hides messages from the game company.
  • Warn your friends, because your account may already have sent them the same scam.
  • Contact the platform's official support through the real site, not through any contact offered in a message.

Many communities now run their own Discord or chat servers and act as a first line of defense by deleting scam links quickly. My piece on how gaming communities run their own chat servers covers what moderators can do there, and more general account advice lives under security.

One task for this week: open the account settings for the game you play most and check which second factor is turned on. If the answer is "email" or "none", switch it to an authenticator app before you play your next match. It takes about five minutes, and it is the difference between a scary email and a lost account.

ON
Obi Nwachukwu

Obi works on account security and explains phishing, passwords and access in plain terms.

More posts by Obi

More in Games