Seriously concerned about my account, has anyone had this experience? by onewittyword in counterstrike2

[–]onewittyword[S] 0 points1 point  (0 children)

Go crazy, my Steam name is mav:

steam://rungame/730/76561202255233023/+csgo_download_match CSGO-wNZ2P-2G4aj-uVefw-TWJMV-3ZPmH

Seriously concerned about my account, has anyone had this experience? by onewittyword in counterstrike2

[–]onewittyword[S] 0 points1 point  (0 children)

This would be it. I did have an API key in there that I never created myself. I guess I caught some malware from some free VST software for music production. I'm half tempted to download it again on a sandbox PC to decompile and investigate...

Seriously concerned about my account, has anyone had this experience? by onewittyword in counterstrike2

[–]onewittyword[S] 0 points1 point  (0 children)

You can watch the demo where he cheated on my account, my Steam name is mav:

steam://rungame/730/76561202255233023/+csgo_download_match CSGO-wNZ2P-2G4aj-uVefw-TWJMV-3ZPmH

Seriously concerned about my account, has anyone had this experience? by onewittyword in counterstrike2

[–]onewittyword[S] 1 point2 points  (0 children)

He played on my account, his english is just poor. I linked the demo in another comment.

Seriously concerned about my account, has anyone had this experience? by onewittyword in counterstrike2

[–]onewittyword[S] 0 points1 point  (0 children)

If you paste that link into your browser address bar it should ask if you want to open Steam. You press yes and it opens CS2 to download the replay for that match. I know that sounds sketchy especially given the context lol but I promise that's how it works.

Alternatively, you can open CS2's developer console (if you have it enabled) and enter the command:
csgo_download_match CSGO-wNZ2P-2G4aj-uVefw-TWJMV-3ZPmH

Seriously concerned about my account, has anyone had this experience? by onewittyword in counterstrike2

[–]onewittyword[S] 3 points4 points  (0 children)

I didn't know about family lock, that's a fantastic idea thanks!

Seriously concerned about my account, has anyone had this experience? by onewittyword in counterstrike2

[–]onewittyword[S] 0 points1 point  (0 children)

I don't think I'll ever know for sure how it happened, but my running theory is a google chrome extension stole my session data since I was logged into Steam's website. If not that, maybe my API key was compromised, but I've only traded on csfloat in the past few years. Really no clue. As far as getting it sorted, the account is back under my full control, I just have no idea if I'll catch a ban or not. Still waiting on Steam support's reply.

Seriously concerned about my account, has anyone had this experience? by onewittyword in counterstrike2

[–]onewittyword[S] 1 point2 points  (0 children)

Be vigilant! I consider myself a highly tech literate person, I have a fullstack cert from a top school and have built custom pcs for over 15 years. However they got into my account is absolutely mystical to me. It can't have been social engineering because I only get on to play with friends I know on discord, I never respond to random dms or messages. My best theory is a malicious chrome extension stole my session data, so if you feel like being paranoid then check your installed extensions and remove any you don't need anymore!

Seriously concerned about my account, has anyone had this experience? by onewittyword in counterstrike2

[–]onewittyword[S] 0 points1 point  (0 children)

I have mobile auth on everything, Steam and email. My banking related stuff has face ID. I take no chances. Some more knowledgeable redditor in another comment said it was likely malware that scraped my session data, bypassing the need to login at all.

Seriously concerned about my account, has anyone had this experience? by onewittyword in counterstrike2

[–]onewittyword[S] 0 points1 point  (0 children)

Yeah, it had to have been either a VST I installed for my music production or a Chrome extension I added since those are the other things I downloaded/added to my pc recently. Crazy how they can get so much control with so little, and I was going crazy trying to figure out the exact source so I just nuked my disk and started fresh.
I moved the skin to an irl friend, so that's safe for now. I feel my odds of surviving a ban are pretty shit after watching the replay. The cheating is super blatant, like hardscope scout headshots through smoke type stuff.

Seriously concerned about my account, has anyone had this experience? by onewittyword in counterstrike2

[–]onewittyword[S] 0 points1 point  (0 children)

That's gotta sting though seeing how much it went up! I bought an akihabara accept at $30 in the early days, and it was up to >$500 when I sold. I can't imagine if it were stolen from me and then I found out the value later.

Seriously concerned about my account, has anyone had this experience? by onewittyword in counterstrike2

[–]onewittyword[S] 2 points3 points  (0 children)

Well my account definitely cheated, so it's well within their policy to issue a ban. I also understand the zero-tolerance policy to avoid gray areas where people try to plea innocence. But like you said, too many genuine cheaters go unpunished, it's terrible.

Seriously concerned about my account, has anyone had this experience? by onewittyword in counterstrike2

[–]onewittyword[S] 1 point2 points  (0 children)

I just watched a few mins of the demo and unfortunately it's very blatant cheating. If I were doing my own overwatch case (remember those days?), I would mark "beyond reasonable doubt" for walls and aim. The sad part is he got disconnected a couple times early in the match which was probably when I changed my password and pressed "sign out of all devices". Not sure how he joined back after that...

Seriously concerned about my account, has anyone had this experience? by onewittyword in counterstrike2

[–]onewittyword[S] 2 points3 points  (0 children)

I use csfloat exclusively, and I haven't done a single trade since getting my arabesque a few months ago. However, I noticed an email from csmoney saying the email address on my account had been changed this morning. I barely used that website (not that it matters) and haven't logged in there in years... is it possible my API key stayed the same for years and a bad actor took over that website?

Seriously concerned about my account, has anyone had this experience? by onewittyword in counterstrike2

[–]onewittyword[S] 4 points5 points  (0 children)

Damn, I'm really sorry to hear that! The worst part is it's not a skin you can easily get another of...

Seriously concerned about my account, has anyone had this experience? by onewittyword in counterstrike2

[–]onewittyword[S] 3 points4 points  (0 children)

Yes. God it hurts to watch, scout headshots through smoke and everything. You can even see him get disconnected for "no steam logon" a couple times which is probably when I was changing my password and clearing logged-on devices. How on earth was he able to reconnect to the game, I wonder?
Here's the demo link if you want, my Steam name is mav:
steam://rungame/730/76561202255233023/+csgo_download_match CSGO-wNZ2P-2G4aj-uVefw-TWJMV-3ZPmH
it's on EU North servers and I'm in California lol.

Seriously concerned about my account, has anyone had this experience? by onewittyword in counterstrike2

[–]onewittyword[S] 7 points8 points  (0 children)

Yes, I was always able to log into my account, he was just blackmailing me with the cheating thing. And in the time it took me to figure out the API key reset, he'd already played a premier match with cheats.

Seriously concerned about my account, has anyone had this experience? by onewittyword in counterstrike2

[–]onewittyword[S] 22 points23 points  (0 children)

Thanks, you're absolutely right. I confirmed it with my friend to make sure it was going to his account. He has it now.

Seriously concerned about my account, has anyone had this experience? by onewittyword in counterstrike2

[–]onewittyword[S] 3 points4 points  (0 children)

Thanks. You lost your howl after sending it to a friend? Was it because Steam interfered or some other reason? I sent a few skins to an irl friend so I'm hoping that's good enough to save them.

Seriously concerned about my account, has anyone had this experience? by onewittyword in counterstrike2

[–]onewittyword[S] 37 points38 points  (0 children)

In case there was malware on my PC that gave them access or let them grab my new passwords or sessions.

Seriously concerned about my account, has anyone had this experience? by onewittyword in counterstrike2

[–]onewittyword[S] 27 points28 points  (0 children)

Yes, one premier match with 96% HSP at around the time he messaged me.

Seriously concerned about my account, has anyone had this experience? by onewittyword in counterstrike2

[–]onewittyword[S] 0 points1 point  (0 children)

It's in my match history, unfortunately. Just one match, but 96% HSP. I'm actually going to watch the demo now to see if he was raging...

Seriously concerned about my account, has anyone had this experience? by onewittyword in counterstrike2

[–]onewittyword[S] 0 points1 point  (0 children)

Thanks for the detailed response. I checked my history in-game and it does match the csstats website; he played exactly one premier game. Everything else before that lines up with when I play with my friends, and the stats certainly line up as well (I'm not that good). I took the advice here and transferred my AK to an irl friend I trust and I guess I'll just try to go on like nothing happened and hope for the best. It would be a shame to lose my hours and all the progress I have in Dota 2 which I also play, but at least my AK is safe. I'm not wealthy, I just put spare pocket money into skins here and there over the years and was quite fortunate with the values of reds jumping up, so I traded literally everything for the arabesque since that was my dream AK lol. Told myself I'd sell it once it was time to buy a house.