How to Secure Your Steam API Key from Scam Attacks | DMarket | Blog (2024)

  1. DMarket Blog
  2. Guides
  3. How to Secure Your Steam API Key from Scam Attacks

Tonhy Johns Sep 19, 2018

How to Secure Your Steam API Key from Scam Attacks | DMarket | Blog (3)

The number of phishing bots and websites has drastically increased in recent months. Man-in-the-middle attacks are aimed at intercepting and collecting users’ ID and authentication data to then gain access to their funds and other assets, like your in-game items on Steam.

Notorious social engineering tricks seem not to be effective anymore, at least to experienced users, since Valve introduced its cybersecurity weapon, the Steam Guard.

Two-factor authentication makes it far harder for cybercriminals to steal or otherwise misuse your personal account data. All transactions between users on the website thereby must be approved via email or, preferably, via a user’s smartphone.

Unfortunately, cyber fraudsters invent new ways to deceive gamers. One of the new phishing threats to users’ accounts on Steam is the Web API Key scam. It also holds true for any other digital marketplace, where personal API keys are used to confirm transactions.

How to Secure Your Steam API Key from Scam Attacks | DMarket | Blog (4)

Here is How a Typical Scam Works:

  1. Scammers profile and target their potential victims by leveraging public Google ad tools like keyword research and analysis to collect information on popular websites and marketplaces mostly visited by gamers and others.
  2. Once the search results of a common gamer are measured, the cybercriminals make use of direct ad means like Google AdWords to ensure top rankings for their counterfeit websites. A phishing site’s web address always looks almost identical to the authentic one, except a few added or misspelled symbols.
  3. A misguided user clicks the top link on the search results page, which is not a genuine one, and leads him to the phishing website.
  4. Fake sites usually fully imitate the original UI, home and landing pages, asking the deceived users to authenticate and leave their personal data like a login and a password. That’s where scammers jump in to steal user accounts.
  5. When the account data is retrieved, cybercriminals get full control over scammed Steam accounts and receive Web API Keys to monitor further transactions.
  6. The scam will come into action as soon as a user decides to purchase or sell his in-game items on Steam or any similar marketplace.
  7. Once a legitimate trade offer is sent by a Steam bot to the user, a scam bot immediately cancels the trade and initiates his own fake offer, sending it to the user’s mobile phone or email address.
  8. Since the fake and the real trade offers look quite identical, the victim confirms it with his email or a mobile phone authentication app. From now on, all the items are gone forever.
  9. If the victim checks his trade history, he may see there are two trade offers, the real one getting rejected.

With this in mind, let’s figure out what a regular user can do to prevent such a fraud so to keep his Steam account safe and sound from scam attacks?

There is almost nothing to do about listing phishing websites in Google top search rankings, except sending complaints to tech support services. However, users can protect their own Steam accounts by following some simple steps.

How to Secure Your Steam API Key from Scam Attacks | DMarket | Blog (5)

4 Ways to Avoid Scam Threats

A rule of thumb here is better safe than sorry. There are several simple things you can do beforehand to protect your Steam (or any other) account from getting scammed and stolen.

  • Authentication only via Steam and trusted websites. To minimize your chances of getting into serious trouble with phishing websites, log into your Steam account on Steam only, or, at least, on marketplaces, which you are confident about. Keep an attentive eye on the website link you are about to click. It is always far safer to authorize with Steam first, no matter what in-game trade marketplace you are eventually going to use.
  • Password change. This is a great way to terminate your current session on Steam and block scam bots from accessing your account. You can alter your Steam login credentials in two ways – by clicking Forgot password or Change my password options. The first variant is preferable, since it allows you to continue trading on Steam without any trade suspension period.
  • Revoke Steam Web API Keys. If your account is scammed, the API key is obviously in the fraudsters’ database. So visit your user’s page on Steam, call back your current API key, and let Steam generate a new one instead. Take up the habit of regularly changing your Steam Web API Key to ensure your account is safe and not exploited by cybercriminals.Here you can revoke and re-generate your keys.
  • Check sent trade offers. Visit your Steam user page and go to this page every time you have offers to be confirmed via your mobile phone or email.

Remember that the security of your Steam account is primarily your own duty. Follow our instructions and enjoy a great time trading your in-game items in a secure and transparent way. Besides, we strongly recommend that you read the article on how to trade on Steam.

How to Secure Your Steam API Key from Scam Attacks | DMarket | Blog (6)

Tonhy Johns

Tonhy Johns is an enthusiastic copywriting professional with over 5 years of expertise. Being a digital tech and video game industry evangelist, he is passionate about creating eye-catching yet meaningful web content on various topics such as gaming, fintech, eCommerce, IoT, AI, ML, VR & AR, just to name a few.

Trade CS:GO skins Trade DOTA2 skins

Related posts

The Most Common Steam Scams and How to Avoid Them

Eugene Bozhenko Nov 2, 2023

Information about the Latest Steam Update and Its Impact on DMarket Services (Updated)

DMarket Updated Apr 6, 2024

The Crucial Role of 2FA in Skins Trading

Eugene Bozhenko Nov 21, 2023

Anti-Scam in Trading Game Items: Check List

Eugene Bozhenko Oct 17, 2023

Navigating the Risks: How to Identify and Prevent Mobile App Scams

Eugene Bozhenko Aug 14, 2023

Skins Scam With Fake Google Ads: Be Safe

Eugene Bozhenko Aug 8, 2023

Update on Steam Services

DMarket Apr 2, 2023

All You Need to Know About Trade on Steam

Tonhy Johns Apr 1, 2019

Steam.tv — New Broadcasting Service from Valve

Tonhy Johns Aug 21, 2018

How to Secure Your Steam API Key from Scam Attacks | DMarket | Blog (2024)

References

Top Articles
Latest Posts
Article information

Author: Lidia Grady

Last Updated:

Views: 5517

Rating: 4.4 / 5 (65 voted)

Reviews: 80% of readers found this page helpful

Author information

Name: Lidia Grady

Birthday: 1992-01-22

Address: Suite 493 356 Dale Fall, New Wanda, RI 52485

Phone: +29914464387516

Job: Customer Engineer

Hobby: Cryptography, Writing, Dowsing, Stand-up comedy, Calligraphy, Web surfing, Ghost hunting

Introduction: My name is Lidia Grady, I am a thankful, fine, glamorous, lucky, lively, pleasant, shiny person who loves writing and wants to share my knowledge and understanding with you.