0
  • Articles
    • Premium Content
    • AI Adventures
    • Code Chronicles
    • Fintech
    • Big Data
    • Cloud
    • Guarding the Grid
    • IoT
    • Gaming
    • Mixed Reality
    • Regulatory Radar
    • Startup Stories
    • IT Events
    • Hardware
    • WWW
    • Mobile
    • Interviews
    • Telecom
    • Green Tech
    • Career Compass
  • Store
  • Database
  • Career Compass
  • 0
  • Login
  • Join Now!
  • (0)

Steam increases security measures after developer accounts get hijacked

Avatar img-thumbnail img-circle
By Dejan Sokoloski

30 October 2023 in Gaming, Security

Photo by Elimende Inagella on Unsplash
Avatar img-thumbnail img-circle
By Dejan Sokoloski

30 October 2023 in Gaming, Security

It is a shame when Steam makes headlines for online attacks and security breaches instead of gaming news. Steam, the largest online store focused on video games, has announced that it will increase security after some developer accounts were hijacked and used in attacks.

Valve has already contacted video game developers whose accounts were hijacked and were used for the new for of sophisticated attacks.

Unfortunately, the problem is bigger than simply losing control over the profile. Attackers used the account to install and hide malicious code in a small portion of Steam video games.

The idea is simple, and you can probably already guess it. The attackers would set the game to receive a game update, but instead of a game update, users download a malicious code was onto their computers. The good news, if you can actually see it that way, is that the number of victims of the attacks is surprisingly small. Only about 100 users downloaded any of the malicious updates.

Security experts at Steam immediately took action. After discovering the attack, Valve rolled back to the previous versions of the games and removed the malicious updates from Steam. At the same time, they proactively contacted affected account owners to alert them to the security threat.

For greater security, and to prevent the situation from happening again, Valve has added additional security measures. One of them is mandatory double authorization and identity verification. Identity verification is via SMS, and developers must add a phone number to their profile before October 24. Furthermore, any upgrade that they push will have to be confirmed by SMS authorization.

Some of the developers are not satisfied with the urgency imposed by Valve, especially when it comes to finding a phone that they can use, reported NME. In general, this is a standard two-factor authentication. After releasing an update for a video game, Steam will send an SMS code to the developer which must then be entered into the client to select the current version of the game.

As an additional security measure, Valve will also limit who can send invitations to new users. This will only be enabled for admins in Steamworks groups in the future.

The company wants to be “crystal” clear about the change. Developers who do not enter a phone number will not be able to push updates after October 24th.

Steam has not yet released an exact number of compromised accounts, or how attackers gained access to developer accounts. One of the games that got involved into this whole mess is NanoWar: Cells VS Virus. The game’s creator, Benoît Freslon, says he was the victim of malware that stole his access tokens. With them, the attackers gained access to all the services on which he was logged in at the moment. As expected, one of the platforms he was logged into was Steam, reported PC Gamer.

Subscribe
Login
Notify of
guest
guest
0 Comments
Newest
Oldest Most Voted
Inline Feedbacks
View all comments

← What is the effect of cyberbullying and how to help protect your kids from its many forms


Coolinarika presents SuperfoodChef – the first Croatian AI assistant that helps you discover recipes →


related topics

account games hijack security Steam

similar articles

Online fraud in-depth analysis: Smishing attack on Macedonian Post Office

24 October 2023 by Ljubomir Davitkov

Origin secures €4M to deliver cost-effective drone-launched precision-guided weapon systems

25 October 2024 by Bojan Stojkovski

Interview with Dr. Kucho about his game Moons of Darsalon that’s been 8 years in development

17 January 2025 by Martin Jovanchevski

Adria Security Summit 2025 presents strategic themes and future security perspectives

2 October 2025 by Editorial Team

career compass

see all ads on career.itlogs.com

market

  • Promoted Job Listing

    $29,00
    Add to cart
  • Standard Job Listing

    $9,99
    Add to cart
  • PR Article

    $199,00
    Add to cart
  • Submit an Event

    $4,99
    Add to cart
for full range of items visit market.itlogs.com

Делуваш како човек што би го поддржал it.mk со премиум членство.

Стани премиум член и добиј куп бенефити - попусти, премиум содржина и дополнителни функционалности.

претплати се сега

Let’s create the largest SEE tech community! Join now!

  • Tech Pulse
  • New Tech
  • Startup World
  • Coder's Corner
  • Tech Gear & IoT
  • WWW, MarTech & Business
  • Cybersecurity Hub

Get instant Notifications

  • Facebook
  • Twitter
  • LinkedIn
  • Instagram

About

  • Employer BrandingNew
  • Impressum
  • Contact
  • Marketing
  • Privacy Policy
  • Ethical Statement

Quick links

  • Articles
  • Community
  • Store
  • Career Compass
  • Events

SEE Tech insider

Thank you! You have successfully joined our subscriber list.


2026 itlogs.com All right reserved. • Published by ctrl+alt+del media

Suggest a product

    Полињата означени со * се задолжителни.

    To use CAPTCHA, you need Really Simple CAPTCHA plugin installed.

    Suggest a company

      Filed marked with * are required.


      Company details:


      Close ✕

      Brand

      Price

      Availability

      Discount

      Ofc we use cookies - some website features depend on them. For how we use them, pls read here.
      Accept All Reject All Settings
      Manage consent

      Privacy Overview

      This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
      Necessary
      Always Enabled
      Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
      CookieDurationDescription
      cookielawinfo-checkbox-advertisement1 yearSet by the GDPR Cookie Consent plugin, this cookie records the user consent for the cookies in the "Advertisement" category.
      cookielawinfo-checkbox-analytics1 yearSet by the GDPR Cookie Consent plugin, this cookie records the user consent for the cookies in the "Analytics" category.
      cookielawinfo-checkbox-functional1 yearThe GDPR Cookie Consent plugin sets the cookie to record the user consent for the cookies in the category "Functional".
      cookielawinfo-checkbox-necessary1 yearSet by the GDPR Cookie Consent plugin, this cookie records the user consent for the cookies in the "Necessary" category.
      cookielawinfo-checkbox-others1 yearSet by the GDPR Cookie Consent plugin, this cookie stores user consent for cookies in the category "Others".
      cookielawinfo-checkbox-performance1 yearSet by the GDPR Cookie Consent plugin, this cookie stores the user consent for cookies in the category "Performance".
      CookieLawInfoConsent1 yearCookieYes sets this cookie to record the default button state of the corresponding category and the status of CCPA. It works only in coordination with the primary cookie.
      Functional
      Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
      CookieDurationDescription
      __cf_bm30 minutesCloudflare set the cookie to support Cloudflare Bot Management.
      mailchimp_landing_site1 monthMailChimp sets the cookie to record which page the user first visited.
      Performance
      Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
      Analytics
      Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
      CookieDurationDescription
      _fbp3 monthsFacebook sets this cookie to display advertisements when either on Facebook or on a digital platform powered by Facebook advertising after visiting the website.
      _ga1 year 1 month 4 daysGoogle Analytics sets this cookie to calculate visitor, session and campaign data and track site usage for the site's analytics report. The cookie stores information anonymously and assigns a randomly generated number to recognise unique visitors.
      _ga_*1 year 1 month 4 daysGoogle Analytics sets this cookie to store and count page views.
      _gat_gtag_UA_*1 minuteGoogle Analytics sets this cookie to store a unique user ID.
      _gid1 dayGoogle Analytics sets this cookie to store information on how visitors use a website while also creating an analytics report of the website's performance. Some of the collected data includes the number of visitors, their source, and the pages they visit anonymously.
      CONSENT2 yearsYouTube sets this cookie via embedded YouTube videos and registers anonymous statistical data.
      Advertisement
      Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
      CookieDurationDescription
      test_cookie15 minutesdoubleclick.net sets this cookie to determine if the user's browser supports cookies.
      VISITOR_INFO1_LIVE5 months 27 daysYouTube sets this cookie to measure bandwidth, determining whether the user gets the new or old player interface.
      YSCsessionYoutube sets this cookie to track the views of embedded videos on Youtube pages.
      yt-remote-connected-devicesneverYouTube sets this cookie to store the user's video preferences using embedded YouTube videos.
      yt-remote-device-idneverYouTube sets this cookie to store the user's video preferences using embedded YouTube videos.
      yt.innertube::nextIdneverYouTube sets this cookie to register a unique ID to store data on what videos from YouTube the user has seen.
      yt.innertube::requestsneverYouTube sets this cookie to register a unique ID to store data on what videos from YouTube the user has seen.
      Others
      Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
      CookieDurationDescription
      cookies.jssessionNo description available.
      mnp_d894de8c1 yearDescription is currently not available.
      SAVE & ACCEPT
      Powered by CookieYes Logo
      {title}wpDiscuz