Steam
· Historical listing archivePUBLIC THREAT INTELLIGENCE
The archive at a glance
Historical listings collected over time. Removed offers stay in the archive; totals do not measure current availability or unique accounts.
Try another platform name or collection state.
| Category | Listings | Share of records | New records | Collector |
|---|
How these numbers are counted
About this data
Historical marketplace listings, retained after sale or removal. Each category + listing ID appears once; different listings may concern the same account. Totals are not unique accounts or verified victims. Origin and country are source-reported. Missing fields remain unknown; legacy zeros may include missing data. The first archived snapshot is retained.
Asking prices are not sale proceeds. Missing prices and values at or above $1,080 are excluded from price totals and averages; this threshold can also exclude legitimate high-value offers. Original values remain in exports. Recorded spend and inventory value are separate measures, not proven loss.
Defensive research and incident response only. Source links and seller identities are redacted. No credentials or marketplace access are provided.
2. Change your main e-mail password and enable 2FA. (Warning: if the attacker still has access to your inbox, they will steal the account back immediately after recovery.)
• Forced logouts on your devices
• Unknown logins from foreign IPs
• Items or funds moving without you
• Friends receiving scam messages you didn't send
2. Log out every session and revoke connected apps / API keys on every platform that shares a password.
3. Rotate the compromised platform's password, then immediately enable MFA (preferably a hardware key or Authenticator app).
If caught by Phishing (fake login page): rotate the password everywhere it was reused and add MFA. Local malware is less likely, but run a scan just in case.
| Category | Dominant Attack Vector | Threat Level | Indexed Count |
|---|
Infostealer logs (RedLine, Vidar, Lumma), phishing token capture, password reuse / credential stuffing.
Credentials bulk-uploaded and checked live. Sorted by game library, inventory value, geo, linked payment methods.
Buyer plays with cheats / smurfs until ban. Spams and scams the friends list. Strips tradeable items — CS2 / TF2 / Rust skins, Path of Exile currency & gear, Rocket League items — to mule accounts. Burns wallet / store balance.
Stripped husk is re-sold cheap or kept as a throwaway for more spam and cheating. Victim stays locked out.
Methodology: Metrics are derived programmatically from periodic snapshots of listings on a monitored underground marketplace (source designation redacted). Asking prices are normalized to USD. Recorded spending reflects platform-side purchase history recovered with the account, not illicit resale price. Seller handles are replaced with stable actor aliases (Actor #N). No live marketplace URLs are exposed. Growth figures are computed only from recorded collection snapshots and always carry their true measurement window.
Use cases: victim identification and recovery · platform Trust & Safety triage · academic measurement of account-takeover resale · control-efficacy studies (MFA, session revoke, automated recovery).
Legal position: Content is published for security research, auditing, and victim mitigation. PhishDestroy does not facilitate, encourage, or participate in underground marketplaces. All source links are deliberately defanged and platform identifiers are anonymized. Buying, selling, or using stolen credentials is a crime (18 U.S.C. § 1030 and equivalents).