Most Steam phishing doesn't open with a threat. It opens with a favour: vote for a friend's team, fill the last slot in a tournament, claim a free case. Every version ends in the same place, a login window that looks like Steam's and isn't, so once you know the pattern you can spot all of them.
Lure one: "Can you vote for my team?"
Malwarebytes described the "vote for my team" scam in March 2022 as an old trick that kept flaring up. A stranger messages you on Steam or in a Steam-themed Discord channel, makes small talk, then asks you to vote for their team in a competition or join it. The vote button opens a phishing page. If you use Steam Guard, the page asks you to switch it off.
Two details make it work. People change their Steam display names all the time, Malwarebytes noted, so a stranger can pass for a friend you've forgotten. And the scam is often sent from accounts that have already been compromised, so sometimes it really is your friend's account asking. Bitdefender, covering the same scam in April 2024, added a third: the request doesn't mention money, crypto or trades, so it doesn't feel like a scam at all.
A developer who received one in November 2024 published the whole exchange. The stranger had added him two weeks earlier and waited. Then came a request for feedback on a logo for a university esports team, then a request to vote for it. The voting site was largely copied from a real student esports organisation and filled with recent-looking news posts. Clicking "Vote" opened a Steam login pop-up drawn in JavaScript, which fell apart when he tried to drag it past the edge of the browser.
Lure two: "Join our tournament"
In September 2022, the security firm Group-IB reported a campaign that invited Steam users by direct message to join teams for League of Legends, CS, Dota 2 or PUBG tournaments. Other lures in the same campaign offered a vote for your favourite team or cheap tickets to esports events. The links led to sites posing as organisations that host competitions.
Joining meant signing in with Steam through a pop-up that was really part of the page, complete with a fake padlock and a believable address. BleepingComputer, covering the report, said the pages detected the visitor's browser language and offered 27 of them, asked for the Steam Guard code after the password, and finally sent the victim on to a legitimate address so nothing seemed wrong. Group-IB said the kit wasn't sold openly but used privately by groups organising on Discord and Telegram. The aim, BleepingComputer reported, was to sell access to the stolen accounts, some prominent ones valued at $100,000 to $300,000.
When the attackers copied the look of a real tournament platform, that platform told BleepingComputer its genuine sign-in uses a standard OpenID flow that keeps your Steam credentials private. A real site never needs to see your password.
There's also a malware version. Valve's scam FAQ warns about people who say you must install voice software, anti-cheat or another program to play in their tournament, when the download is malware. Our guide to screen-sharing and remote-access scams covers that route.

Lure three: free skins and fake streams
Giveaways ride on big events. In February 2025, Bitdefender found hijacked YouTube channels rebranded as s1mple, NiKo and donk, looping old footage as fake livestreams during IEM Katowice 2025 and PGL Cluj-Napoca 2025. A QR code or link on the stream led to sites promising free skins, cases or crypto, and claiming the prize meant signing in with Steam.
A month later, BleepingComputer reported research by Silent Push on sites offering a free CS2 case under Navi branding, promoted partly through YouTube and using the same fake pop-up technique. Our guide to spotting Steam phishing sites covers that campaign in detail.
| Reported | Lure | How it arrived | Source |
|---|---|---|---|
| March 2022 | Vote for my team | Steam chat, Discord | Malwarebytes |
| September 2022 | Join a tournament team, cheap tickets | Steam direct messages | Group-IB via BleepingComputer |
| November 2024 | Vote for a university team's logo | Steam friend request | utf9k |
| February 2025 | Free skins on fake pro streams | YouTube | Bitdefender |
| March 2025 | Free CS2 case | YouTube videos | Silent Push via BleepingComputer |
What all three have in common
Strip away the story and the same pieces remain:
- Someone brings the link to you. You didn't go looking for a tournament or a giveaway; it found you.
- Steam sign-in happens on someone else's page. Valve says official Steam sign-ins happen only on
www.steampowered.com,store.steampowered.com,steamcommunity.comandhelp.steampowered.com. - There's a request to weaken your security. Turning off Steam Guard, typing a Steam Guard code into the page, or installing software.
- Friendship or urgency does the persuading. A vote takes "a second", the tournament starts soon, the giveaway ends tonight.

Checks that work against every version
Don't sign in from a link someone sent. Valve's advice is never to click unknown links and to check links even from friends, because their account may be compromised. If you want to see a tournament or giveaway, find it yourself and sign in to Steam directly first.
Test any pop-up. The creator of the fake pop-up technique, mr.d0x, told BleepingComputer the simplest test is to drag the window to the edge of your browser: if it disappears under the border, it's fake. Group-IB added two more checks. A real pop-up can be resized, and on Windows 10 with taskbar grouping turned off it appears as its own window in the taskbar.
Check who you're talking to. On Steam, Malwarebytes suggests hovering over a user's name on their profile to see their previous names. If a "friend" asks for a vote, ask them about it somewhere else.
Refuse anything that touches Steam Guard. No vote, tournament or giveaway needs your authenticator code or for you to switch protection off.
If you already signed in
Change your Steam password from a device you trust, use Sign out everywhere on the Authorized Devices page, secure your email and revoke any Steam Web API key you didn't create. If CS2 items left in trades within the last seven days, you can reverse them under trade protection. Our account security checklist covers the rest.
Sources
- Fake Esports voting sites looking to phish Steam users — Malwarebytes
- Hackers steal Steam accounts in new Browser-in-the-Browser attacks — BleepingComputer
- The 'Vote for My Team' Scam Is One Way to Lose Your Steam Account to Criminals — Bitdefender
- A fascinating attempt at Steam phishing — utf9k
- Streamjacking Scams On YouTube Leverage CS2 Pro Player Championships to Defraud Gamers — Bitdefender
- Browser-in-the-Browser attacks target CS2 players' Steam accounts — BleepingComputer
- Scam FAQ (Confidence Scams and Trade Scams) — Steam Support
- Account Security Recommendations — Steam Support



