One of the commonest ways to lose a Steam account is typing your password into a page that isn't Steam's. The better phishing kits now draw a fake login window that shows a believable steamcommunity.com address, which defeats the usual advice to "check the URL". Here is how these pages reach CS2 players, how the fake windows work, and the checks that give them away.
How phishing pages find you
The bait tends to be something you want: free skins or cases, a giveaway, a tournament spot, or a fix for a problem with your account. Recent campaigns show the pattern.
- Free case sites. In March 2025, BleepingComputer reported on a campaign, found by Silent Push, that promised a free CS2 case on sites themed around the esports team Navi. Promotion ran partly through YouTube videos, and claiming the "gift" meant signing in through a fake Steam pop-up.
- Fake livestreams. In February 2025, Bitdefender described hijacked YouTube channels rebranded as players such as s1mple, NiKo and donk, looping old gameplay during IEM Katowice 2025 and PGL Cluj-Napoca 2025. QR codes and links on the stream led to "free skin" sites that asked for a Steam login.
- Fake verification pages. In June 2026, Malwarebytes reported fake FACEIT "verification" pages on lookalike domains such as
faceit-discord.comandfaceit-clubs-verify.com. The pages claimed there was a problem with your CS2 account and asked you to sign in with Steam to prove you weren't cheating.
Messages from friends deserve the same caution. Valve warns that a friend's account may itself be compromised, so a link from a familiar name proves nothing.

How a fake login pop-up works
The technique is called browser-in-the-browser. Instead of opening a real window, the page draws a picture of one inside itself, complete with a title bar, an address bar reading steamcommunity.com and Steam's login form. Some versions ask for your Steam Guard code as well, so the attacker gets that too.
Because the "window" is part of the page, it can't behave like a real one. Silent Push found the fakes in the Navi campaign couldn't be maximised, minimised or moved outside the browser. That gives you a quick test:
- Drag it. Grab the pop-up's title bar and try to pull it past the edge of your browser. A real window can go anywhere on your screen; a fake one can't leave the page. Silent Push calls this the easiest way to confirm a pop-up is real.
- Resize it. A real pop-up can be resized. The fakes in that campaign couldn't.
- Look at the real address bar. The one at the very top of your browser shows the site you're actually on. Malwarebytes puts it simply: trust that one, not the one drawn inside the page.
The safest habit beats all three tests. If a site pushes a Steam login at you, close it, open Steam yourself by typing the address or using the app, and sign in there. A genuine "Sign in through Steam" page will usually recognise that you're already signed in and just ask you to confirm; a phishing page will keep asking for your password.
Lookalike addresses
Valve lists the domains where official Steam sign-ins happen: www.steampowered.com, store.steampowered.com, steamcommunity.com and help.steampowered.com. Anything else asking for your Steam password is not Steam. Valve also warns that scammers use "clever mis-spellings" to make links look official, so read the domain letter by letter, especially the part just before .com.
Don't rely on your browser or antivirus to catch new fakes. Malwarebytes notes that many of these domains are only hours or days old, so a site not being flagged as dangerous doesn't mean it's safe.
QR codes
The Steam Mobile app can sign you in by scanning a QR code on a Steam login screen. The code signs in the device that's displaying it, which is why you should only scan codes on a sign-in screen you opened yourself. Before you approve, the app shows the sign-in attempt with a map and an approximate location; if that doesn't match where you are, deny it.
A QR code on a giveaway site, a stream overlay or a "verification" page is a red flag. In the fake FACEIT pages, Malwarebytes found the QR code was deliberately blurry, likely to push people towards the fake "Sign in through Steam" button instead.
Codes, chats and "Steam Support"
Valve's rules here are absolute. Never share your Steam Guard codes, never type them into a site Valve doesn't run, and never give anyone an SMS recovery or removal code. Steam Support will never ask for any of them. Valve employees also never contact you about your account through Steam Chat, Discord or any other chat app; the only real support channel is help.steampowered.com.
If you already typed your password
Act quickly:
- Change your Steam password from a device you trust.
- On the Authorized Devices page in your Steam account, use Sign out everywhere.
- Make sure Steam Guard is on, and change your email password too if it was the same as your Steam one.
- Open
steamcommunity.com/dev/apikeyand revoke any key you didn't create (our API key scam guide explains why). - Change the password anywhere else you reused it, and scan your computer for malware.
Then check your trade history. If CS2 items went out in trades within the last seven days, you can reverse them under Steam trade protection, and our account security checklist covers the rest.
Sources
- Browser-in-the-Browser attacks target CS2 players' Steam accounts — BleepingComputer
- Hackers target Counter-Strike 2 players with fake Steam login pop-ups — PCMag
- Fake verification pages are stealing Steam accounts from players — Malwarebytes
- Streamjacking scams on YouTube leverage CS2 pro player championships to defraud gamers — Bitdefender
- Account Security Recommendations — Steam Support
- Steam Guard Mobile Authenticator — Steam Support
