Suspicious
Phishings targeting Steam
Suspicious and active websites
Phishings targeting Steam
Suspicious and active websites
Active
2
New (7d)
2
Trend (7d)
—
Suspicious sites — confidence is not always 100%. Use for Threat Hunting or watchlists.
Suspicious sites — confidence is not always 100%. Use for Threat Hunting or watchlists.
AIHow to verify a real Steam URL
- Legitimate Steam URLs always end in
store.steampowered.com(e.g.www.store.steampowered.com,account.store.steampowered.com). Anything else — including look-alike typosquats, hyphenated variations, or unfamiliar TLDs like.xyz/.top/.vip— is not Steam. - The padlock icon proves TLS is active, not that the site is safe. Free DV certificates are issued to attackers in minutes; every active site listed above has a valid TLS certificate.
- If you got the link from email, SMS, or social media, do not click it. Open
store.steampowered.comfrom your browser bookmark or type the domain manually. - Real Steam pages almost never ask for credentials immediately after clicking from a message — treat any such redirect as a phishing attempt until the domain is verified.

