Steam accounts are worth real money — libraries, inventories, trading cards, skins — which makes them a constant target. Valve estimates tens of thousands of accounts are hijacked every month, and almost every single case starts with a preventable mistake. Here is the complete security checklist, from essential to paranoid.
Level 1: The non-negotiables
Enable the Steam Mobile Authenticator
Not email confirmation — the mobile app authenticator. It generates rotating codes and requires approval for logins and trades. This single step blocks the vast majority of hijacks, and Valve requires it for instant trading anyway. Steam app → Steam Guard → set up authenticator.
Unique password, used nowhere else
Most Steam “hacks” are not hacks at all — they are password reuse. A breach at some forum you registered on in 2019 gets tried against Steam automatically. A password manager makes unique passwords effortless; if you do nothing else today, change your Steam password to something unique.
Verify the login page URL, always
Phishing is the #1 attack in 2026. Fake “vote for my team”, “free skin”, and “you won a giveaway” links lead to pixel-perfect copies of the Steam login page. The real one is only ever on steamcommunity.com or store.steampowered.com — check the address bar character by character before typing anything. Our guide to spotting fake giveaways covers the current scam patterns in detail.
Level 2: The commonly missed
Check your API key
Visit steamcommunity.com/dev/apikey. Unless you registered one yourself, it should say no key exists. A registered key you do not recognize means malware or a phishing kit has automated access to your account — revoke it immediately and change your password. This is the mechanism behind most modern inventory-draining attacks.
Review authorized devices
Steam Guard settings list every device authorized to skip codes. Deauthorize everything you do not recognize (and everything old — that laptop you sold in 2023 does not need access).
Watch for the SSFN trick
Never run “FPS unlockers”, “free VAC bypasses”, or files strangers send you “to test my game”. A classic attack steals Steam session files from your disk, silently cloning your logged-in state. If you ran something sketchy, assume compromise: change password, deauthorize all devices, revoke API key.
Level 3: For traders and collectors
- Trade confirmations on mobile only — and actually read them. Attackers who compromise an account often swap trade contents at the confirmation step.
- 15-day trade holds are your friend. They exist precisely so hijackers cannot instantly liquidate your inventory. Do not disable them if you hold value.
- Family View PIN adds a second barrier around purchases and settings even if someone gets into a logged-in session.
If you have already been hijacked
- Use Steam’s account recovery at
help.steampowered.com— recovery beats making a new account; Valve can nearly always restore access to the original owner. - Change your email password FIRST (attackers usually control it too), then the Steam password.
- Revoke the API key, deauthorize all devices, cancel outstanding trades.
- Scan your PC before logging back in — a keylogger makes every reset pointless.
The 5-minute audit, right now
Mobile authenticator on → unique password → API key page empty → authorized devices recognized → no sketchy software installed. Do those five checks today and your account is safer than 95% of Steam. Your library took years to build; five minutes protects it.
Emergency response: your account is compromised right now
If you are reading this because something is already wrong — items vanishing, friends receiving strange messages from you, a password that stopped working — here is the exact sequence, in order:
- Use Steam’s account recovery (help.steampowered.com) from a clean device. Even with a changed email, Steam’s recovery can verify you through original purchase details — the one thing a hijacker can never fake.
- Change the password and immediately deauthorize all devices in Steam Guard settings. This kills every stolen session at once.
- Audit the account edges: confirm your email and phone on file are yours; revoke any Steam Web API key you did not create (steamcommunity.com/dev/apikey — hijackers plant these to silently redirect trades after you think you have recovered); cancel open trade offers and market listings.
- Scan the machine that got you phished or infected before signing back in from it — recovering an account through a keylogged PC just hands it back.
- Message your friends — whatever link the hijacker sent from your account, your friends are the next victims, and a two-line warning breaks the chain.
Expect item recovery to be limited — traded-away inventory often cannot be restored, by policy. The account itself, your games, and your history are nearly always recoverable. Speed matters most in step 3: the API-key trick is how “recovered” accounts get re-robbed a week later.
Frequently asked questions
Is the Steam Mobile app authenticator really necessary?
It is the single highest-value step on this page. Confirmation-based login means a stolen password alone is worthless, and trade confirmations mean even a session hijack cannot empty your inventory silently. If you do exactly one thing from this guide, do this.
How do accounts with Steam Guard still get stolen?
Almost exclusively through the fake-login-page scam — the victim types their credentials and approves the confirmation, believing they are signing into a tournament, giveaway, or trading site. Steam Guard cannot protect a login you personally approve. The address bar is the last line of defense, every time.
Should I use a unique password even with the authenticator?
Yes. Reused passwords from unrelated site breaches are the top way attackers get their first foothold. A password manager makes unique passwords effortless — and it will refuse to autofill on a lookalike phishing domain, which quietly protects you from the biggest scam in the ecosystem.