Innovabase › Security
Account security, and the scams built around games
Game accounts are taken by ordinary means: a password reused from a site that was breached years ago, a convincing sign-in page that was not the real one, or a program installed to get something free. Nothing exotic is involved, which is fortunate, because it means ordinary measures work.
Short answer
A unique password for the game account and two-factor authentication where the vendor offers it remove most of the risk. If an account has already been taken, the order that matters is: recover the email address first, then the game account, then check payment methods. Report scams to Scamwatch and cyber incidents to the Australian Cyber Security Centre; both take reports from the public.
How accounts are actually taken
- Reused passwords
- When any service is breached, the email and password pairs from it circulate and are tried automatically against other services. An account is at risk not because the game was breached but because the same password was used somewhere else that was.
- Look-alike sign-in pages
- A link in a message leads to a page that resembles the real sign-in screen. Whatever is typed there goes to whoever built it. These are often well made, and the address bar is the reliable place to check rather than the appearance of the page.
- Programs promising something free
- Downloads offering free in-game currency, unlocked items or automation frequently carry software that reads stored credentials. The promised feature is the reason the program is run at all.
- Session tokens taken from a device
- Some malicious software copies the token that keeps you signed in, which can bypass a password entirely. This is the reason vendors offer a sign out everywhere function and the reason it is worth using after any suspected incident.
- Support impersonation
- Someone presents themselves as staff, in chat or by email, and asks for a password or a code. Legitimate support does not ask for either, and treating any such request as false regardless of how plausible it seems is the correct default.
Why the email account comes first
The email address attached to a game account is the key to it, because it is where password resets arrive. Someone who controls that mailbox can reset the game password at leisure, and can do the same to every other account registered to it.
That makes the mailbox the place to secure first and the place to check first if something seems wrong. Two things are worth doing on it today rather than eventually: turning on two-factor authentication, and looking at the forwarding and filter rules. A rule that quietly forwards or deletes messages from a particular sender is a common way for access to be retained after a password change, and almost nobody checks.
Measures worth the effort
- A password used nowhere else for the game account and for the mailbox behind it. Length matters more than punctuation; a passphrase of several unrelated words is easier to remember and harder to attack than a short string of substituted characters.
- A password manager to make the first point practical. Remembering one strong passphrase and letting software handle the rest is a real improvement over any system based on memory.
- Two-factor authentication wherever a vendor offers it. An authenticator application is preferable to SMS where there is a choice, though SMS is considerably better than nothing.
- Recovery details kept current. A recovery address you no longer control is worse than none, because it directs the recovery process somewhere you cannot reach.
- Devices kept updated. Operating system and browser updates close the routes that credential-stealing software relies on, and applying them promptly is among the most effective habits available.
- Nothing installed to get something free. This one rule prevents a large share of the incidents described on this page.
The Australian Cyber Security Centre publishes government guidance for individuals and families covering passwords, multi-factor authentication and device updates, which is worth reading once as a whole rather than in fragments.
The scams that circulate around games
The mechanics repeat across every popular title, which makes them easy to recognise once described.
- Free currency generators. A site or program claims to add in-game currency and asks for your account details, or for a "verification" step that installs something. In-game currency is created by the game's servers and by nothing else.
- Trade and gifting tricks. An offer to trade valuable items, with a sign-in on a third-party site to "verify" ownership. The sign-in is the point of the exercise.
- Giveaway impersonation. An account resembling a known player or the vendor runs a giveaway requiring a small payment or a login. The resemblance is superficial and the address is the giveaway.
- Recovery services for a fee. A service offers to restore a lost account. Only the vendor can do this, and only through its own process.
- Fake refund help. A contact found through a search offers to process a refund the store would not. It is a route to your payment details.
- Urgent warnings about your account. A message says the account will be closed unless you act immediately and provides a link. Urgency is the tell; check by opening the vendor's site yourself rather than through any link you were sent.
Scamwatch, run by the National Anti-Scam Centre, publishes descriptions of scam types currently in circulation in Australia and is the place these are reported. Reports there contribute to what is published, so making one is useful even when nothing was lost.
If it has already happened
Order matters more than speed here, because recovering the game account before the mailbox simply hands it back.
- Recover the email account. Change its password, review its forwarding and filter rules, and sign out of all sessions.
- Start the vendor's account recovery process. Use the official site, reached by typing the address. Expect to prove ownership: original address, approximate creation date, purchase receipts.
- Sign out everywhere. Where the vendor offers it, this invalidates any session token that was copied.
- Change passwords anywhere the same one was used. Start with anything financial. This is the step people skip and the reason incidents recur.
- Check payment methods on the account. Look for stored cards you did not add and for charges you did not make, and contact your bank about anything unexpected.
- Scan the device with a reputable product. If credentials were taken by software, a password change alone does not remove it.
- Report it. See below. Reporting does not slow recovery and contributes to what is known about the method used.
Evidence worth keeping
Screenshots of any message that led to the incident, the dates and times of unauthorised activity, and any transaction records. Support processes and reporting forms both ask for these, and they are difficult to reconstruct after access is restored and the evidence is cleared.
Where to report, in Australia
- Scamwatch
- For scams of any kind, whether or not money was lost. Operated by the National Anti-Scam Centre.
- Australian Cyber Security Centre
- For cyber security incidents, including compromised accounts and devices, and for government guidance on preventing them.
- eSafety Commissioner
- For harm between people online — harassment, threats, image-based abuse and cyberbullying affecting children and young people.
- Office of the Australian Information Commissioner
- For complaints about how an organisation handled personal information, after raising it with the organisation itself.
Households with younger players
Younger players meet the same scams described above, presented in language aimed at them, and often through in-game chat rather than email. The useful protection is not surveillance but a standing arrangement that nothing embarrassing will be met with anger — most losses are made worse by a delay in telling someone, and the delay is usually about anticipated reactions rather than the incident itself.
Practical settings — restricting who can send messages, disabling in-game purchases, and separating the child's game account from an adult's payment method — are covered on the family settings page. The eSafety Commissioner publishes material written for parents and carers on both the technical controls and the conversations.
Is a password manager safe to use?
Reputable password managers are widely recommended by security agencies, including in the guidance published by the Australian Cyber Security Centre, because the alternative in practice is reusing passwords. The risk of a manager is concentrated and manageable; the risk of reuse is spread across every account you hold.
The vendor does not offer two-factor authentication. What then?
Put the effort into the mailbox instead, since that is the recovery route for the game account. A unique password on the game, two-factor on the email, and no stored payment method on an account that does not need one is a reasonable position.
How do I tell a real sign-in page from a copy?
By the address, read carefully, and by how you arrived. Navigating to a site you typed yourself, or from a bookmark you made earlier, removes the question entirely. Appearance proves nothing, because appearance is trivial to copy.
Should I report something if no money was lost?
Yes. Scamwatch uses reports to publish warnings about what is currently circulating, and an unsuccessful attempt is still information about a method in use. Reports take a few minutes.