Kinetic Hub

Security

Game account security and the scams built around it

A game account is a small store of value: purchased items, progress that took months, and an email address that probably unlocks other things. That combination is why players are targeted, and why the approaches used against them are more specific than generic spam. This page describes the approaches, the defences that hold, and the recovery sequence if an account is taken.

Why game accounts are worth stealing

Three properties make them attractive. They hold items that other players will pay for, sometimes in cash and outside the game's own rules. They are tied to an email address that may be reused elsewhere, so a working password is worth testing against other services. And they belong disproportionately to younger users, who are less likely to have multi-factor authentication switched on and more likely to accept a message from someone who appears to be a fellow player.

The result is a small economy: credentials tested in bulk, accounts emptied or resold, and a steady supply of new players arriving with the same password they use everywhere. Almost none of it involves breaking anything technical. It involves a person being asked for something at a moment when the request looks ordinary.

The approaches used, named

Credential stuffing
Passwords exposed in an unrelated breach are tried automatically against game logins. It works only where a password has been reused, which is why a unique passphrase per account is the single highest-value habit here.
Phishing pages
A copy of the game's login screen at an address that resembles the real one, reached from a chat message, a video description or a search advertisement. Everything typed into it goes to the operator.
Currency “generators”
Sites offering free in-game currency in exchange for a login, a survey or an installed application. No such generator exists; currency is issued by the game's own servers and cannot be produced from outside them.
Trade and gifting bait
An offer to gift an item or complete a trade, conditional on logging in through a supplied link, or on handing over a one-time code “to confirm”. The code is the second factor being harvested in real time.
Modified clients and cheats
Downloads promising advantages or unlocked content. These are installed voluntarily, run with the user's own permissions, and are a routine delivery route for password-stealing software.
Account resale
Buying or selling accounts, which nearly every vendor's terms forbid. The buyer has no means of preventing the original owner recovering the account through support, and no recourse when it happens.
Support impersonation
A message claiming a violation, a ban appeal or a verification requirement, with urgency attached. Genuine support does not ask for a password, and does not need a one-time code read out to them.

The five requests no legitimate game makes

  • Your password, in any channel, for any reason.
  • A one-time code or authentication code, read out or forwarded to a person.
  • Remote access to your computer to “fix” an account problem.
  • Payment by gift card, voucher code or cryptocurrency transfer.
  • A login on a domain other than the vendor's own, particularly one reached from a message rather than typed.

Tells that hold up

Visual imitation has become good enough that judging a page by appearance no longer works. Three checks survive it.

  1. Read the address, right to left. The part immediately before the first single slash is the real domain. Everything to the left of it can be made to say anything at all, including the vendor's name.
  2. Arrive under your own steam. Type the vendor's address or use your own bookmark, then look for the message the page claimed to be about. If the account really has a problem, it will be visible there too.
  3. Distrust the deadline. Urgency is the common element across nearly all of these approaches, because a person given time tends to check. Nothing legitimate about a game account is decided in the next ten minutes.

The Australian Cyber Security Centre publishes current advice on recognising these approaches at cyber.gov.au, and Scamwatch publishes warnings about scam types currently circulating in Australia.

Four defences that do most of the work

  • A unique passphrase for the game account. Long, generated, stored in a password manager, used nowhere else. This alone defeats credential stuffing entirely.
  • Multi-factor authentication wherever it is offered. An application-based code or a security key is stronger than a code by SMS, because a phone number can be taken over at the carrier.
  • A protected email account. The mailbox is the recovery route for everything else; if it falls, the game account follows. It deserves its own unique passphrase and its own second factor.
  • Nothing installed from outside official sources. Clients, patches and add-ons from the vendor or an official store only, which is covered in detail on our page about devices and installation.

If an account has been taken

Order matters here, because each step protects the next one.

  1. Secure the email account first. Change its password, check for forwarding rules or recovery addresses that were added, and enable multi-factor authentication if it was not already on.
  2. Use the game's own password reset and account recovery process, from the vendor's site typed in directly. If reset fails because the address was changed, use the vendor's support channel and say the account was compromised.
  3. Revoke active sessions and connected applications if the account settings allow it, so a stored session cannot be used to log straight back in.
  4. Change the password anywhere the same one was used, starting with banking, then email, then everything else.
  5. Check for unauthorised charges on the payment method attached to the account, and contact the bank or card issuer if any are present.
  6. Run a full scan with the security software already installed on the device, particularly if any modified client or cheat tool was installed before the compromise.
  7. Write down dates, times, amounts and message contents while they are fresh. Every report you may later make asks for them.

Reporting it in Australia

Reports go to different places depending on what happened, and more than one may apply.

Money lost, or a scam attempted: report to Scamwatch, run by the National Anti-Scam Centre. A cybercrime such as account compromise or fraud: report through the Australian Cyber Security Centre at cyber.gov.au, which operates the national cybercrime reporting route. Identity information exposed: IDCARE is a not-for-profit service providing free support to individuals in Australia and New Zealand dealing with identity and cyber incidents. Cyberbullying of a child, or seriously harmful content: the eSafety Commissioner has a complaints scheme. Personal information mishandled by an organisation: raise it with the organisation first, then the Office of the Australian Information Commissioner.

A report rarely returns a stolen item, and it is still worth making. Reports are how patterns are identified and how warnings are issued to the next person who receives the same message. Our page on where to get help in Australia sets out what each body can and cannot do before you spend time on a submission.

Talking to a child about it

The practical problem is not knowledge but disclosure: a child who has been scammed often knows exactly what happened and does not want to say so. Two things help. Agree in advance that losing an account or an item is never a punishable event in your household, so reporting it costs nothing. And make the rule concrete rather than abstract — no codes to anyone, no logins from links, no downloads from a friend — because a rule of that shape survives a moment of excitement better than a general warning about strangers.

The eSafety Commissioner publishes guidance written for parents and carers on gaming, chat and online contact at esafety.gov.au, including material suitable for reading with a child rather than at them.