Entry 5 of 7
Accounts, logins and scam awareness
Quick answerA game account in this category holds years of progress and often a payment method, which makes it worth stealing. The defences are ordinary: a unique password, a second factor, a recovery address you control, and a habit of ignoring offers that arrive uninvited. If something does go wrong, Scamwatch and the Australian Cyber Security Centre are where it gets reported.
This entry is written the way a public advisory is written: generally, about how these problems work, with the reporting routes named. It makes no claim about your computer, your account or your current situation, and it has no product to recommend as a remedy. The reason account security has an entry on a site about games is simply that progression in this category is slow, valuable and tied to a login, and that combination attracts attention.
Why accounts in this category are targeted
Three things make a mature account attractive to someone else. It represents a large amount of time, which some people will pay to skip. It often has a payment method attached, saved for convenience. And its value is legible — a rare or premium vehicle is visible to anyone who logs in, so a stolen account can be priced and resold quickly.
None of that is specific to any one publisher, and none of it implies a weakness in any particular game. It is an ordinary consequence of accounts that store value, which is the same reason streaming and shopping accounts are targeted.
The usual routes in
- Reused passwords
- A password used on a game account and also on a site that suffered a breach elsewhere can be tried automatically against the game. This is the most common route and the easiest to close.
- Imitation login pages
- A page that looks like a publisher's sign-in, reached from a message, an advertisement or a video description, which captures what is typed into it. The giveaway is almost always the address bar rather than the page design.
- Offers of items or currency
- A message offering free premium content, a giveaway entry or a trade, which requires a login, an authentication code or remote access to complete. Legitimate publishers do not ask for a password or a one-time code to give you something.
- Software from the wrong place
- Clients, modifications or "helpers" downloaded from somewhere other than the publisher or an authorised platform. Installation guidance is in the setup entry.
- Support impersonation
- Contact claiming to be publisher support, asking to verify an account by supplying a code. Support staff do not need your code, and a code you did not request is a signal in itself.
Multi-factor authentication, and why it is the one to do first
A second factor means a stolen password is not enough on its own. For accounts in this category it is usually offered as an authenticator application, an email code, or a hardware key, and any of them is a large improvement on a password alone. The Australian Cyber Security Centre publishes plain-language guidance on multi-factor authentication for individuals, including how the different methods compare, and it is the sensible source to read rather than a summary here.
Two details are worth adding because they are specific to games. First, the account often has a separate launcher login and forum login, and enabling a second factor in one place does not necessarily cover the other. Second, a one-time code arriving unexpectedly is information: it means someone has your password, and the correct response is to change it rather than to ignore the message.
Passwords that hold up
Current advice from the ACSC favours length over complexity: a long passphrase of unrelated words is both stronger and easier to remember than a short string with substitutions. The other half of the advice matters more for gaming accounts than most people expect — the password must be unique, because reuse is what makes a breach somewhere else into a problem here. A password manager, including the one built into most browsers and operating systems, makes uniqueness practical.
The recovery email address deserves the same treatment. An attacker who controls the recovery address controls the account, regardless of how good the game password is, so the email account behind it should have its own unique password and its own second factor.
A reasonable standard, not a counsel of perfection
Unique password, second factor enabled, recovery email secured, software installed only from the publisher. Four things, done once, that close most of what this entry describes. Nothing on this page requires anyone to buy anything, and this site does not sell or recommend security products.
Third-party key sellers and cheap accounts
Two adjacent markets sit around these games and both are worth understanding before rather than after.
The first is the resale of activation keys and premium currency at prices below the publisher's. Some of that trade is legitimate; some involves keys bought with stolen payment details, which are revoked when the original transaction is reversed. The buyer's loss in that case is the whole purchase, and the seller is usually outside Australia and outside practical reach. Buying from the publisher's own store or a platform the publisher lists avoids the question entirely.
The second is the sale of established accounts. Beyond being prohibited by most publishers' terms, a bought account remains recoverable by its original owner through support, and the buyer has no standing to object. Money spent on it is generally unrecoverable.
Where an offer of either kind is promoted misleadingly to Australian consumers, the ACCC is the relevant regulator, and Scamwatch publishes descriptions of current approaches so you can check one before acting on it.
Chat, conduct and reporting
Most titles in this category include text or voice chat between strangers, and that raises a different class of problem from account theft. Publishers provide in-game reporting and muting tools, and using them is the first step.
Where behaviour goes beyond what a mute button addresses — serious online abuse, image-based abuse, or material involving a child — the eSafety Commissioner is Australia's online safety regulator and operates reporting schemes for exactly those categories. It also publishes guidance for parents and carers about games with open chat, which is covered further in the family guidance entry.
If an account is taken, in order
- Try the publisher's account recovery from the publisher's own site, reached by typing the address rather than by following a link in any message about the problem.
- Secure the recovery email account first if you still have access to it. Recovering the game account is pointless while the email behind it is compromised.
- Contact the publisher's support in writing, with the account name, the approximate date of the last legitimate login, and any order numbers. Purchase records are often the strongest proof of ownership.
- Check the payment method attached to the account, and contact your bank or card issuer about any transaction you did not make.
- Change the password anywhere else it was used, which is the step people skip and the one that prevents a repeat.
- Report it, using the routes below. Reporting does not usually recover an account, but it is what informs the national picture of how these approaches work.
Where to report in Australia
- Scamwatch, run by the National Anti-Scam Centre — for scams, including fraudulent sellers and giveaway approaches.
- Australian Cyber Security Centre — cyber security advice for individuals, and the route to ReportCyber for cybercrime.
- eSafety Commissioner — for online abuse, image-based abuse and serious harm arising in online play.
- Office of the Australian Information Commissioner — for complaints about how an organisation has handled your personal information, including after a data breach.
What to watch out for
- Urgency in a message. A warning that an account will be closed within hours is a technique, not a deadline. Publishers do not resolve account matters by chat message.
- Codes you did not request. Treat an unexpected one-time code as evidence that a password needs changing.
- Links in video descriptions and comments. A common delivery route for imitation login pages, because the surrounding content looks legitimate.
- Anything requiring remote access. No legitimate game support process needs control of your computer.