Steam

· Historical listing archive
Data as of —

PUBLIC THREAT INTELLIGENCE

The archive at a glance

Historical listings collected over time. Removed offers stay in the archive; totals do not measure current availability or unique accounts.

How to read these numbers
Categories

CategoryListingsShare of recordsNew recordsAsking-price totalLast checkCollector
How these numbers are counted

Archived listings
—
listings in this category · —
Total asking price
—
recorded asking prices · outliers excluded
Recorded spending
—
spending reported in listings
Average asking price
—
across priced listings
Inventory value
—
estimated in-game item value
About this data

Historical marketplace listings, retained after sale or removal. Each category + listing ID appears once; different listings may concern the same account. Totals are not unique accounts or verified victims. Origin and country are source-reported. Missing fields remain unknown; legacy zeros may include missing data. The first archived snapshot is retained.

Asking prices are not sale proceeds. Missing prices and values at or above $1,080 are excluded from price totals and averages; this threshold can also exclude legitimate high-value offers. Original values remain in exports. Recorded spend and inventory value are separate measures, not proven loss.

Defensive research and incident response only. Source links and seller identities are redacted. No credentials or marketplace access are provided.

Listing archive
Export
0 archived listings
Archive · live availability unknown
—
Research & account recovery
Search the archive, review account activity and find platform support.
Reading the archive Counts describe archived listings, including resales and automated registrations. They do not measure unique owners or confirmed losses.
Find your account in the archive
Search by username, display name, BattleTag, email or listing ID. Export matching records as CSV for an account recovery request.
Identity fields only (usernames, e-mails, listing IDs). Runs against the first-party index. Discord/Telegram/Steam rows often lack a public login name — match those by listing ID or metrics you still recognize (register date, country, game list).
Account recovery by platform
Step-by-step account recovery written for people who still have — or just lost — the platform login. Pick a platform for the official support path, what evidence to attach, and the order of operations. Do recovery from a clean device.
Golden Rule (every platform)
Support will ask for proof of ownership: purchase receipts, CD/game keys, original e-mail, creation date, ISP/IP at registration, and the last 4 digits of the first linked bank card. Collect these before filing a ticket. Never send full card numbers, CVV, passwords, or session tokens — only the last 4 digits of the card.
Before you start recovering
1. Run a full antivirus / anti-malware scan (e.g. Malwarebytes) to remove any infostealers.
2. Change your main e-mail password and enable 2FA. (Warning: if the attacker still has access to your inbox, they will steal the account back immediately after recovery.)
Suspicion Detection Signs
• Unexpected 2FA or e-mail changes
• Forced logouts on your devices
• Unknown logins from foreign IPs
• Items or funds moving without you
• Friends receiving scam messages you didn't send
First 30 Minutes (any platform)
1. Switch to a clean phone / PC — do not reset from the infected machine.
2. Log out every session and revoke connected apps / API keys on every platform that shares a password.
3. Rotate the compromised platform's password, then immediately enable MFA (preferably a hardware key or Authenticator app).
Stealer vs phishing note
If infected by an Infostealer (malware): your entire browser profile is burned. Deep-clean or reinstall your OS, and rotate EVERY saved credential.
If caught by Phishing (fake login page): rotate the password everywhere it was reused and add MFA. Local malware is less likely, but run a scan just in case.
Total Recorded spending
—
Original purchase spend on compromised accounts
Spend / Price Totals
—
original purchase spend ÷ cumulative asking price
Criminal Use-Case Matrix
Category Dominant Attack Vector Threat Level Indexed Count
Illustrative Impact Scenario
Estimated Impact at $50 assumed value per indexed record
—
Indexed records
—
Scenario total · not confirmed loss
—
Total asking price
Who Buys Stolen Accounts? (Buyer Profiles)
Cheat Resellers & Smurf Farms
Cheaters and rating boosters purchase cheap accounts (CS2, Valorant, Apex Legends) to deploy malicious hacks (aimbots, wallhacks) in high-level lobbies without risking their primary accounts, or to breed accounts for matchmaking resale.
HIGH THREAT · Elite gaming impact
Inventory Traders (Item Farmers)
Liquidators and botnet operators capture accounts with valuable game skins (CS2, Dota2, Rust, TF2) to automatically wipe out inventories, drain Steam wallet balances, and route items through cross-game P2P trading platforms.
HIGH THREAT · Wallet & Skins drainage
Spam & Scam Operators
Syndicates acquire bulk Telegram, Discord, and social media autoregs or phishing logs to run large-scale coordinate spam campaigns, invite-bombing, malicious phishing broadcasts, and fake crypto giveaway distribution.
MEDIUM THREAT · Bulk botnet execution
Account Resellers (Arbitrage)
Arbitrage actors purchase high-value region accounts (primarily DE/US region with payment methods on file) on source markets at a discount, then re-list them at a premium on public grey-market platforms.
LOW THREAT · Black market price arbitrage
Privacy Seekers / Grey Users
Ordinary cost-conscious gamers from lower-income jurisdictions buy pre-loaded game libraries or compromised active subscriptions for direct personal gaming or streaming use, ignoring platform terms of service.
LOW THREAT · Direct consumer usage
Fraud & Money Mules
Financial cybercriminals use active compromised accounts with attached payment cards, banks, or balances to run chargeback fraud schemes, test stolen credit card details, and execute complex laundry operations.
HIGH THREAT · Financial carding & wash loops
Who Gets Targeted & Why? (Target Vectors)
LEGACY NODES
2004-2012
High Trust
Un-MFA Protected Heritage Accounts
Old accounts created in the early years of platforms (e.g. 2004–2012 Steam logins) that lack modern Multi-Factor Authentication. These legacy nodes are highly trusted by platform security algorithms, possess rare badges, and are targeted to bypass fraud filters. Real Example from dataset: Account #253146921, registered 2008-05-31 and abandoned since 2009-12-24, was harvested and sold for arbitrage.
GEOGRAPHY
DE & US
Premium Tier
Geopolitical High-Value Targets
Threat actors run geo-specific infostealer distribution campaigns. Germany (DE) and United States (US) accounts are highly targeted due to high-value games on file, active linked PayPal/credit cards, and immediate liquid cash. Domestic markets in Brazil, Russia, and Ukraine are exploited for high-volume smurfing.
AI SUB
ChatGPT
New Frontier
LLM & Subscription Accounts (New Frontier)
With the rise of AI tools, infostealer logs are now aggressively filtered for active session credentials of OpenAI (ChatGPT Plus), Anthropic (Claude Pro), and Midjourney. These premium AI sub accounts are sold in bulk to speculators looking for cheap API compute resources.
The Money Flow Pipeline
1. STEAL / BRUTE LOG
Infostealer logs (RedLine, Vidar, Lumma), phishing token capture, password reuse / credential stuffing.
➔
2. BLACK MARKET LISTING
Credentials bulk-uploaded and checked live. Sorted by game library, inventory value, geo, linked payment methods.
➔
3. ABUSE THE ACCOUNT
Buyer plays with cheats / smurfs until ban. Spams and scams the friends list. Strips tradeable items — CS2 / TF2 / Rust skins, Path of Exile currency & gear, Rocket League items — to mule accounts. Burns wallet / store balance.
➔
4. EMPTY RE-LISTING
Stripped husk is re-sold cheap or kept as a throwaway for more spam and cheating. Victim stays locked out.
What the account is actually used for: cheats and smurfing on the victim's rank and games, scam / spam against the friends list, and liquidation of tradeable in-game items (Path of Exile, Rocket League, CS2, TF2, Rust and similar). Platforms that force sessions dead on password change and freeze trades after a geo / device change cut the drain window before mule transfers clear.
How To Read This Dataset
listing_id
stable row key
Quote this in support tickets. It is not a marketplace URL and cannot be traded.
listing_price_usd
asking price
What the reseller asked. Not the victim's real loss. Missing and outlier prices are excluded from price aggregates; no spend substitution.
Recorded spending / Inventory value
victim-side value
Purchase history and in-game assets recovered with the account — closer to true harm than the ask price.
origin
stealer · phishing · brute · resale · autoreg
How the credentials were obtained or re-listed. Drives the recovery branch you should follow.
Actor #N
anonymized seller
Stable alias for a source-market handle. Real handles are never published.
Growth delta
per-category · real window
Counted from collector snapshots. Window is labelled exactly (m/h/24h). No synthetic multipliers.
Research Methodology & Legal Disclaimer

Methodology: Metrics are derived programmatically from periodic snapshots of listings on a monitored underground marketplace (source designation redacted). Asking prices are normalized to USD. Recorded spending reflects platform-side purchase history recovered with the account, not illicit resale price. Seller handles are replaced with stable actor aliases (Actor #N). No live marketplace URLs are exposed. Growth figures are computed only from recorded collection snapshots and always carry their true measurement window.

Use cases: victim identification and recovery · platform Trust & Safety triage · academic measurement of account-takeover resale · control-efficacy studies (MFA, session revoke, automated recovery).

Legal position: Content is published for security research, auditing, and victim mitigation. PhishDestroy does not facilitate, encourage, or participate in underground marketplaces. All source links are deliberately defanged and platform identifiers are anonymized. Buying, selling, or using stolen credentials is a crime (18 U.S.C. § 1030 and equivalents).

Threat Origins & Theft Methodology Details
STEALER
—
—
Infostealer Malware Harvest
Victim's PC was infected with an infostealer (RedLine, Vidar, Raccoon, Lumma etc.). The malware silently extracted saved browser logins, passwords and autofill data. The thief receives a "log" — a package of all credentials from the infected machine — and extracts Steam/game accounts from it. Victim often has no idea the infection occurred.
RedLine / Vidar / LummaBrowser credential dumpMass infection via cracked software
BRUTE
—
—
Credential Stuffing / Brute Force
Criminal bought leaked password databases (from previous breaches of other services) and ran automated tools to test email+password combos against Steam/game platforms. Works because users reuse passwords across sites. A single purchased breach database of millions of credentials may yield thousands of valid game accounts.
Password reuse exploitationLeaked DB combosOpenBullet / SilverBulletHigh-volume automated
PHISHING
—
—
Fake Login Pages / Social Engineering
Victim was tricked into entering credentials on a fake Steam/game login page. Typically sent via trade offer links ("check this item price"), fake giveaway pages, or Discord/Telegram scam messages. Some campaigns use browser-in-the-browser (BitB) attacks that perfectly mimic real login popups, bypassing even user awareness training.
BitB attacksFake trade offersDiscord DM scamsFake giveaways
RESALE
—
—
Re-listed After Purchase — Multiple Use Cases
Account was previously purchased on this or similar underground marketplaces, used, and then re-listed for profit. Actor may have: (1) checked game inventories (CS2, TF2, Rust, ARK, Rocket League) for tradeable items worth more than account price; (2) used the account to send scam messages to friends list; (3) used Steam Wallet balance then re-listed; (4) listed on external grey-market platforms via automation. Germany/EU accounts especially targeted for high-value game libraries.
Inventory farmingGrey-market API resellFriends-list spamWallet drain → relist
AUTOREG
—
—
Bot-Registered Bulk Accounts
Automated mass-registration of fresh accounts. Used for: bulk Discord/Telegram spamming (invite bombing, DM spam), fake review farms, CS2 cheating (new accounts per ban), boosting friends-list count for social engineering credibility, and flooding platforms with fake activity. Telegram autoreg accounts are particularly common — cheap, disposable, used for mass promotional spam and scam DMs.
Mass Telegram spamDiscord invite bombingCS2 smurf / cheat accountsFake activity farms