Reference · accounts
Game account security, and the scams built around game sign-ups
Game accounts accumulate value — time, progress, purchases, a name other people recognise — and that makes them worth taking. The measures that protect one are ordinary and finite, and this page sets them out along with the Australian services that handle reports when something does go wrong.
A unique password on every account, stored in a password manager, and two-factor authentication turned on wherever it is offered, together deal with the great majority of account takeovers. The rest is recognising the three places fraud tends to appear around games: fake sign-in pages, fake download sites, and offers of items or currency that require your account details.
Why accounts get taken, in plain terms
Almost all account compromise happens in one of three ways, and none of them involves anything exotic.
- A password reused from somewhere else. When any service suffers a breach, the exposed credentials get tried against other services. An account with a password used nowhere else is unaffected by a breach elsewhere; an account sharing a password with an old forum is not.
- A password entered on a page that was not what it appeared to be. A convincing copy of a sign-in page costs nothing to produce and is the most reliable technique available to someone who wants credentials.
- A password handed over during a conversation. An offer of free items, a trade, a giveaway, a supposed moderator asking to verify an account. This works on people who are not careless; it works because it arrives at a plausible moment.
The Australian Cyber Security Centre publishes the Australian Government’s cyber security advice for individuals, covering passphrases, multi-factor authentication and what to do after an incident, at cyber.gov.au.
Four measures, in order of value
- Two-factor authentication on the game account and on the email address behind it. The email account is the more important of the two, because whoever controls it can reset the other. An authenticator application is generally preferred to SMS codes, since a phone number can be transferred away from you.
- A unique password for every service. This is only practical with a password manager, which is the point of using one. Long passphrases of unrelated words are easier to type and harder to guess than short strings of substituted characters.
- Recovery details that are current. An account recovers through the contact details on file. A recovery address you no longer read is the reason many accounts cannot be recovered after a compromise, and updating it takes a minute.
- Attention to the security notices you receive. A sign-in alert from an unfamiliar location or device is the earliest warning available, and it is only useful if the message reaches an address you actually check.
Recognising a fake sign-in page
The reliable test is not how the page looks, because the appearance can be copied exactly. It is where the page is.
- Read the domain, right to left. The part immediately before the first single slash is what matters. Anything can be put earlier in the address, including the real vendor’s name.
- Reach sign-in pages yourself. A bookmark or a typed address cannot be redirected by a message. Following a link from an email or a chat is where the risk sits, and not following them costs nothing.
- Treat urgency as the signal it is. A message stating that an account will be closed, a ban applied, or a reward forfeited unless you act immediately is applying pressure because pressure works. A legitimate service allows you to navigate to it in your own time.
- Let your password manager decide. A manager fills credentials only on the domain it saved them for. A page where autofill silently declines to offer anything is a page worth looking at twice, and this is one of the quiet advantages of using one.
- A padlock is not an endorsement. Encryption tells you the connection is private, not that the operator is who they claim. Fraudulent sites have certificates too.
Fake download sites and unofficial installers
Popular games attract sites that offer an installer, a “launcher fix”, or an unofficial client. Some are advertising wrappers; some bundle software you would not choose. The habit that avoids all of it is simple: obtain game software from the vendor’s own site or from a platform you already use, reached by an address you typed or a bookmark you saved.
The same applies to anything promising in-game currency, unlocks, or a modification that requires your account credentials. A tool that needs your password is a tool that has your password. Scamwatch, run by the National Anti-Scam Centre, publishes information about current scams and accepts reports at scamwatch.gov.au.
Account trading and third-party sellers
Buying, selling or sharing accounts is prohibited by most game services’ terms, which is worth knowing before money changes hands: a purchased account can be recovered by its original owner or closed by the vendor, and there is generally no recourse. Read the vendor’s own terms of service, which is the document that governs what happens.
Accounts used by children and young people
Where a household account is used by a child, two things are worth setting up at the start rather than later: the platform’s own parental controls, which typically cover spending limits, communication and playtime, and an agreement about who holds the password and what happens if someone asks for it in a chat.
The eSafety Commissioner is Australia’s independent regulator for online safety and publishes guidance for parents and carers, along with reporting schemes covering online abuse, at esafety.gov.au. For questions about what is in a game before it is installed, the Australian Classification Board classifies computer games for Australia and publishes its decisions at classification.gov.au.
If an account has been taken
Speed matters more than diagnosis at this point. Work through this order.
| Step | Why it comes here |
|---|---|
| 1. Secure the email account first | Whoever controls the mailbox can reset everything attached to it. Change that password and enable two-factor authentication there before touching anything else. |
| 2. Change the game account password and sign out all sessions | A password change alone may leave existing sessions active. Most services have a “sign out everywhere” control; use it. |
| 3. Change the password anywhere it was reused | This is the step people skip, and it is the reason a second account is compromised a week later. |
| 4. Contact the vendor’s support | Only the vendor can reverse changes to an account. Have the original email address, the username and any purchase records ready. |
| 5. Check payment methods attached to the account | Remove stored cards you do not need, and review recent transactions with your bank if any are unfamiliar. |
| 6. Report it | Scamwatch collects scam reports, and the Australian Cyber Security Centre takes reports of cyber security incidents. Reporting informs the national picture even when an individual case cannot be resolved. |
The privacy side of a game account
Creating an account means handing over personal information: an address, often a date of birth, sometimes payment details, and thereafter a record of activity. What an organisation may do with that is a legal question, not only a settings question.
In Australia, the handling of personal information is regulated under the Privacy Act 1988 (Cth) and the Australian Privacy Principles. The Office of the Australian Information Commissioner explains those rights and handles privacy complaints at oaic.gov.au. In practice, the useful habits are reading the vendor’s privacy policy before signing up, giving optional fields no more than they ask for, and reviewing what a game publishes about you to other players by default — display name, activity and friends lists are frequently public until changed.
For what this site itself does with data, the answer is nothing: Vanguard Hub has no forms, sets no cookies and runs no analytics. The privacy policy and the cookie policy set that out in full.
The game covered on this site
Enlisted, the product linked from Vanguard Hub, is an online multiplayer first-person shooter set in the Second World War. Registration involves creating an account, confirming an email address and then signing in to launch the game, on a desktop computer running Windows, macOS or Linux. Its own account security features, privacy policy and terms of service are published by the vendor at enlisted.net and should be read there rather than summarised by a third party.
This is an advertisement. Vanguard Hub is paid a commission on registrations that come through this link, which funds the site; the security guidance above is standard practice and unrelated to it.