Vanguard HubDesktop gaming help, written in Australia

Reference · accounts

Game account security, and the scams built around game sign-ups

Game accounts accumulate value — time, progress, purchases, a name other people recognise — and that makes them worth taking. The measures that protect one are ordinary and finite, and this page sets them out along with the Australian services that handle reports when something does go wrong.

General guidance. Where a claim concerns an Australian government service, that service is linked and described in its own terms.

Quick answer

A unique password on every account, stored in a password manager, and two-factor authentication turned on wherever it is offered, together deal with the great majority of account takeovers. The rest is recognising the three places fraud tends to appear around games: fake sign-in pages, fake download sites, and offers of items or currency that require your account details.

Why accounts get taken, in plain terms

Almost all account compromise happens in one of three ways, and none of them involves anything exotic.

The Australian Cyber Security Centre publishes the Australian Government’s cyber security advice for individuals, covering passphrases, multi-factor authentication and what to do after an incident, at cyber.gov.au.

Four measures, in order of value

  1. Two-factor authentication on the game account and on the email address behind it. The email account is the more important of the two, because whoever controls it can reset the other. An authenticator application is generally preferred to SMS codes, since a phone number can be transferred away from you.
  2. A unique password for every service. This is only practical with a password manager, which is the point of using one. Long passphrases of unrelated words are easier to type and harder to guess than short strings of substituted characters.
  3. Recovery details that are current. An account recovers through the contact details on file. A recovery address you no longer read is the reason many accounts cannot be recovered after a compromise, and updating it takes a minute.
  4. Attention to the security notices you receive. A sign-in alert from an unfamiliar location or device is the earliest warning available, and it is only useful if the message reaches an address you actually check.

Recognising a fake sign-in page

The reliable test is not how the page looks, because the appearance can be copied exactly. It is where the page is.

Fake download sites and unofficial installers

Popular games attract sites that offer an installer, a “launcher fix”, or an unofficial client. Some are advertising wrappers; some bundle software you would not choose. The habit that avoids all of it is simple: obtain game software from the vendor’s own site or from a platform you already use, reached by an address you typed or a bookmark you saved.

The same applies to anything promising in-game currency, unlocks, or a modification that requires your account credentials. A tool that needs your password is a tool that has your password. Scamwatch, run by the National Anti-Scam Centre, publishes information about current scams and accepts reports at scamwatch.gov.au.

Account trading and third-party sellers

Buying, selling or sharing accounts is prohibited by most game services’ terms, which is worth knowing before money changes hands: a purchased account can be recovered by its original owner or closed by the vendor, and there is generally no recourse. Read the vendor’s own terms of service, which is the document that governs what happens.

Accounts used by children and young people

Where a household account is used by a child, two things are worth setting up at the start rather than later: the platform’s own parental controls, which typically cover spending limits, communication and playtime, and an agreement about who holds the password and what happens if someone asks for it in a chat.

The eSafety Commissioner is Australia’s independent regulator for online safety and publishes guidance for parents and carers, along with reporting schemes covering online abuse, at esafety.gov.au. For questions about what is in a game before it is installed, the Australian Classification Board classifies computer games for Australia and publishes its decisions at classification.gov.au.

If an account has been taken

Speed matters more than diagnosis at this point. Work through this order.

What to do, in sequence
StepWhy it comes here
1. Secure the email account firstWhoever controls the mailbox can reset everything attached to it. Change that password and enable two-factor authentication there before touching anything else.
2. Change the game account password and sign out all sessionsA password change alone may leave existing sessions active. Most services have a “sign out everywhere” control; use it.
3. Change the password anywhere it was reusedThis is the step people skip, and it is the reason a second account is compromised a week later.
4. Contact the vendor’s supportOnly the vendor can reverse changes to an account. Have the original email address, the username and any purchase records ready.
5. Check payment methods attached to the accountRemove stored cards you do not need, and review recent transactions with your bank if any are unfamiliar.
6. Report itScamwatch collects scam reports, and the Australian Cyber Security Centre takes reports of cyber security incidents. Reporting informs the national picture even when an individual case cannot be resolved.

The privacy side of a game account

Creating an account means handing over personal information: an address, often a date of birth, sometimes payment details, and thereafter a record of activity. What an organisation may do with that is a legal question, not only a settings question.

In Australia, the handling of personal information is regulated under the Privacy Act 1988 (Cth) and the Australian Privacy Principles. The Office of the Australian Information Commissioner explains those rights and handles privacy complaints at oaic.gov.au. In practice, the useful habits are reading the vendor’s privacy policy before signing up, giving optional fields no more than they ask for, and reviewing what a game publishes about you to other players by default — display name, activity and friends lists are frequently public until changed.

For what this site itself does with data, the answer is nothing: Vanguard Hub has no forms, sets no cookies and runs no analytics. The privacy policy and the cookie policy set that out in full.

The game covered on this site

Enlisted, the product linked from Vanguard Hub, is an online multiplayer first-person shooter set in the Second World War. Registration involves creating an account, confirming an email address and then signing in to launch the game, on a desktop computer running Windows, macOS or Linux. Its own account security features, privacy policy and terms of service are published by the vendor at enlisted.net and should be read there rather than summarised by a third party.

This is an advertisement. Vanguard Hub is paid a commission on registrations that come through this link, which funds the site; the security guidance above is standard practice and unrelated to it.

Visit the Enlisted website

Opens the vendor’s own site, enlisted.net, through our paid affiliate link, in a new tab. The sign-up we link to is for desktop computers only — Windows, macOS or Linux.