Keeping a game account secure, and where to report problems
Nothing on this page says anything about the state of your account or your computer, because this site cannot see either and does not try to. It describes how game accounts are generally lost, the settings that prevent most of it, and which Australian body handles which kind of report if something does go wrong.
Quick answer
A unique passphrase in a password manager, multi-factor authentication on both the game account and the mailbox behind it, and a firm habit of never entering credentials on a page you arrived at from a link. Those three cover most of what follows. If something does happen, the game publisher restores the account and an Australian agency takes the report — they are different steps and both are worth doing.
How game accounts are generally lost
Accounts in this category have resale value, which is the whole explanation for why anyone bothers. Four routes account for most losses, and none of them involve anything sophisticated.
Reused passwords. A password used on a game account and also on a forum that is later breached becomes a working password for both. Automated attempts to use leaked credentials across other services — credential stuffing — are cheap to run at scale, which is why reuse is the single highest-value habit to change.
Phishing. A message or page that imitates the publisher and asks for a login. These are often well made, and the reliable defence is procedural rather than visual: never log in from a link, and instead type the publisher's address into the browser yourself.
Software from the wrong place. Cheats, unofficial mod packs, "unlockers" and cracked launchers are distributed by people whose interest in you is not the game. Downloading and running one is granting a stranger's program the same access to your computer that you have.
Trade and gift scams. An offer that requires handing over a password, logging into a third-party site, or moving the conversation to an outside chat application. Publisher staff do not ask for passwords, and no legitimate in-game trade needs your credentials.
The Australian Cyber Security Centre publishes the government's own guidance on passphrases, multi-factor authentication and recognising phishing, at cyber.gov.au. It is written for a general audience and is a better first read than any advice on a site like this one.
The settings that do the work
- Multi-factor authentication on the game account. An authenticator app is generally preferable to SMS, because it does not depend on keeping the same phone number and is not affected if a number is transferred away from you.
- Multi-factor authentication on the mailbox. The mailbox can reset the game account, so protecting the game and leaving the mailbox open protects nothing.
- A unique passphrase per account, in a password manager. Length matters more than symbol substitutions, and a manager is what makes uniqueness practical across dozens of accounts.
- Recovery details you have actually checked. Confirm that the recovery address on file is one you can open, today, before you need it.
Reading the signals calmly
| What you see | What it usually means | What to do |
|---|---|---|
| An email saying your password was changed, which you did not change | Either a genuine notice of a change someone else made, or a phishing message imitating one | Do not use links in the message. Open the publisher's site directly and attempt a password reset from there |
| A login notification from an unfamiliar location | Often a data-centre location from a legitimate mobile connection; sometimes a genuine third-party login | Change the passphrase and enable multi-factor authentication if it is not already on |
| Items or currency missing | Either a trade you authorised and misremember, or account access by someone else | Contact publisher support through its own site, and keep any transaction records |
| A message from "support" asking you to verify a password | Phishing, without exception | Do not reply. Report it to Scamwatch and delete it |
| A card charge you do not recognise | A stored payment method being used, or an unrelated card problem | Contact your bank about the transaction, then remove stored cards from the account |
Worked example: one password, two accounts
A player in Hobart used the same password on a game account and on a hobby forum. The forum suffered a breach two years ago. Nothing happened for a long time, and then the game account was accessed and its items traded away.
What was and was not the cause. The game publisher was not breached. The password was correct when it was used, which is why nothing looked unusual to the publisher's systems. The delay is normal: leaked credential lists are traded and reused long after the original breach.
The sequence that followed. Password reset from the publisher's own site; multi-factor authentication enabled; the same password found and replaced on four other services using a password manager's reuse report; a support ticket opened with the publisher about the traded items; a report lodged with the Australian Cyber Security Centre. The items were partially restored, which is a publisher's discretion rather than an entitlement.
The change that would have prevented it. Not a better password — a different one on each account, which is a password manager rather than a feat of memory.
If an account has been accessed by someone else
Work in this order. The first three steps are about regaining control, and the rest are about limiting the consequences.
- Reset the mailbox password first, because the mailbox controls everything else.
- Reset the game account password from the publisher's own site, typed into the browser rather than followed from a link.
- Enable multi-factor authentication, and sign out other sessions if the publisher offers that.
- Remove any stored payment method, and contact your bank about any charge you did not make.
- Open a support ticket with the publisher, with dates and what changed. Publishers can sometimes reverse trades, and always need specifics.
- Find every other account using that password and change them, using a password manager's reuse report rather than memory.
Where each kind of report goes in Australia
These are separate routes with separate purposes, and using the right one gets a useful response faster.
- Cybercrime, including account takeover: the Australian Cyber Security Centre, which provides the government's cybercrime reporting route.
- Scams, phishing approaches and fraudulent offers: Scamwatch, run by the National Anti-Scam Centre.
- Serious online abuse, or cyberbullying affecting a child: the eSafety Commissioner, which operates Australia's online safety reporting schemes.
- Mishandling of your personal information by an organisation: the Office of the Australian Information Commissioner, the national privacy regulator.
- Misleading conduct or a refused refund by a seller: the ACCC, and your state or territory consumer protection agency.
- Disputed card transactions: your bank, which is the only party that can reverse a payment.
Two categories to stay out of entirely
Cheat software and unofficial clients are a poor trade even on their own terms: they carry a real chance of a permanent ban and they require running an unknown program with full access to your computer. There is no version of this that is only a game question.
Currency "generators" and free-premium pages are also not what they appear to be. A page offering something a publisher sells, for nothing, is collecting either credentials or payment details. It does not need to be argued with; it needs to be closed.
Terms used above
- Credential stuffing
- Automated attempts to log in to many services using username and password pairs leaked from a breach elsewhere. It succeeds only where a password has been reused.
- Phishing
- A message or page imitating a legitimate organisation in order to capture a login or a payment detail.
- Multi-factor authentication
- A second proof of identity beyond the password, usually a code from an app. It makes a leaked password insufficient on its own.
- Password manager
- Software that generates and stores a different passphrase for every account, so that uniqueness does not depend on memory.
The checklist
- A unique passphrase on the game account, stored in a password manager.
- Multi-factor authentication on the game account, by app where available.
- Multi-factor authentication on the mailbox behind it.
- Recovery address confirmed openable before it is needed.
- No stored payment card in the account or launcher.
- A rule that logins are never done from links, only from an address typed into the browser.
- No cheat software, unofficial client or "generator", on any machine.
- The reporting routes noted somewhere findable, so they do not have to be researched on a bad day.
What to read next
- Account setup — where most of these settings are chosen in the first place.
- Classification and households — the same ground where a younger player is involved.
- Costs in AUD — consumer rights when a purchase goes wrong.