Fake tournament, team-vote and giveaway scams on Steam that end in phishing

Vote for my team, join our tournament, claim a free case: three lures that all end at a fake Steam login. Dated examples from 2022 to 2026 and the checks that expose every one of them.

Most Steam phishing doesn't open with a threat. It opens with a favour: vote for a friend's team, fill the last slot in a tournament, claim a free case. Every version ends in the same place, a login window that looks like Steam's and isn't, so once you know the pattern you can spot all of them.

Lure one: "Can you vote for my team?"

Malwarebytes described the "vote for my team" scam in March 2022 as an old trick that kept flaring up. A stranger messages you on Steam or in a Steam-themed Discord channel, makes small talk, then asks you to vote for their team in a competition or join it. The vote button opens a phishing page. If you use Steam Guard, the page asks you to switch it off.

Two details make it work. People change their Steam display names all the time, Malwarebytes noted, so a stranger can pass for a friend you've forgotten. And the scam is often sent from accounts that have already been compromised, so sometimes it really is your friend's account asking. Bitdefender, covering the same scam in April 2024, added a third: the request doesn't mention money, crypto or trades, so it doesn't feel like a scam at all.

A developer who received one in November 2024 published the whole exchange. The stranger had added him two weeks earlier and waited. Then came a request for feedback on a logo for a university esports team, then a request to vote for it. The voting site was largely copied from a real student esports organisation and filled with recent-looking news posts. Clicking "Vote" opened a Steam login pop-up drawn in JavaScript, which fell apart when he tried to drag it past the edge of the browser.

Lure two: "Join our tournament"

In September 2022, the security firm Group-IB reported a campaign that invited Steam users by direct message to join teams for League of Legends, CS, Dota 2 or PUBG tournaments. Other lures in the same campaign offered a vote for your favourite team or cheap tickets to esports events. The links led to sites posing as organisations that host competitions.

Joining meant signing in with Steam through a pop-up that was really part of the page, complete with a fake padlock and a believable address. BleepingComputer, covering the report, said the pages detected the visitor's browser language and offered 27 of them, asked for the Steam Guard code after the password, and finally sent the victim on to a legitimate address so nothing seemed wrong. Group-IB said the kit wasn't sold openly but used privately by groups organising on Discord and Telegram. The aim, BleepingComputer reported, was to sell access to the stolen accounts, some prominent ones valued at $100,000 to $300,000.

When the attackers copied the look of a real tournament platform, that platform told BleepingComputer its genuine sign-in uses a standard OpenID flow that keeps your Steam credentials private. A real site never needs to see your password.

There's also a malware version. Valve's scam FAQ warns about people who say you must install voice software, anti-cheat or another program to play in their tournament, when the download is malware. Our guide to screen-sharing and remote-access scams covers that route.

Big events lend their names to fake streams and giveaways
Big events lend their names to fake streams and giveaways

Lure three: free skins and fake streams

Giveaways ride on big events. In February 2025, Bitdefender found hijacked YouTube channels rebranded as s1mple, NiKo and donk, looping old footage as fake livestreams during IEM Katowice 2025 and PGL Cluj-Napoca 2025. A QR code or link on the stream led to sites promising free skins, cases or crypto, and claiming the prize meant signing in with Steam.

A month later, BleepingComputer reported research by Silent Push on sites offering a free CS2 case under Navi branding, promoted partly through YouTube and using the same fake pop-up technique. Our guide to spotting Steam phishing sites covers that campaign in detail.

ReportedLureHow it arrivedSource
March 2022Vote for my teamSteam chat, DiscordMalwarebytes
September 2022Join a tournament team, cheap ticketsSteam direct messagesGroup-IB via BleepingComputer
November 2024Vote for a university team's logoSteam friend requestutf9k
February 2025Free skins on fake pro streamsYouTubeBitdefender
March 2025Free CS2 caseYouTube videosSilent Push via BleepingComputer

What all three have in common

Strip away the story and the same pieces remain:

  • Someone brings the link to you. You didn't go looking for a tournament or a giveaway; it found you.
  • Steam sign-in happens on someone else's page. Valve says official Steam sign-ins happen only on www.steampowered.com, store.steampowered.com, steamcommunity.com and help.steampowered.com.
  • There's a request to weaken your security. Turning off Steam Guard, typing a Steam Guard code into the page, or installing software.
  • Friendship or urgency does the persuading. A vote takes "a second", the tournament starts soon, the giveaway ends tonight.
Free-skin pages promise items like these and deliver a fake login instead
Free-skin pages promise items like these and deliver a fake login instead

Checks that work against every version

Don't sign in from a link someone sent. Valve's advice is never to click unknown links and to check links even from friends, because their account may be compromised. If you want to see a tournament or giveaway, find it yourself and sign in to Steam directly first.

Test any pop-up. The creator of the fake pop-up technique, mr.d0x, told BleepingComputer the simplest test is to drag the window to the edge of your browser: if it disappears under the border, it's fake. Group-IB added two more checks. A real pop-up can be resized, and on Windows 10 with taskbar grouping turned off it appears as its own window in the taskbar.

Check who you're talking to. On Steam, Malwarebytes suggests hovering over a user's name on their profile to see their previous names. If a "friend" asks for a vote, ask them about it somewhere else.

Refuse anything that touches Steam Guard. No vote, tournament or giveaway needs your authenticator code or for you to switch protection off.

If you already signed in

Change your Steam password from a device you trust, use Sign out everywhere on the Authorized Devices page, secure your email and revoke any Steam Web API key you didn't create. If CS2 items left in trades within the last seven days, you can reverse them under trade protection. Our account security checklist covers the rest.

Sources

更多安全文章

全部安全文章