August 4, 2021


Game CMD 368

CSGO: Fivetown is the Newest Scam


The new CSGO scam on Steam is making the rounds. The signs that users need to watch out for are here. It’s called “Fivetown,” and you can easily fall for it.


A user receives a message from someone on their list of friends saying “Hey, vote on fivetown for my csgo team – we just need two more votes.” Clicking on the link presents a website to users that asks them to log in to Steam, showing a convincing login page. They dodge the bullet if users don’t log in.

But if they do, they will send the username and password to a complete stranger on their Steam account.

Steam suggests that users immediately change their username and password to their Steam account and any connected accounts, if this sounds familiar. Steam recommends turning on Steam’s two-factor authentication after they do that.

How to avoid scams like Fivetown on Steam

It does not seem that the fivetown scam has reached the US, but people have all reported being targeted by the tactic in the Netherlands, Sweden, Denmark, and other countries in Europe. The site to which scammers have been linked was taken offline at the time of this publication. That said, in CSGO circles over the past two days, there is still a lot for players to learn from the scam that has been a hot topic.

As CSGO has gotten more popular, scammers have become more widespread. And while the profile messages and the “add me” comment spam may be annoying, it’s much less annoying than being hacked. Fivetown is not the first CSGO scam, and it will definitely not be the last, so users should take note of what it looks like and how it can be prevented from happening.

Step 1: Turn on two factor authentication

This is the easiest way to prevent trouble by far. The process is straightforward, run by Valve, and requires only a mobile phone number. There is also a less-secure email authentication option if players don’t have that. 

It works by requiring players, every time they log in, to enter a code. That code is only sent to players once their username and password are entered, and it is generated at random each time. Steam Guard is a failsafe, and you can find instructions here on how to configure it.

Step 2: Do not click the link – CSGO Scam

Links can be risky on Steam. Whenever they click the link that will take them away from the Steam client or the online site, Valve’s popular game client even gives users warnings. This is because creating a site that looks just like Steam’s login page is very easy.

Fortunately, there is a simple way to make sure that the site players are actually logging in to be the real Steam. As users click on the lock button beside the website url, Steam will always show a  valid certificate.

More information will be displayed by clicking on the certificate button itself. If any of this even seems a bit suspicious, players can just close the window. Most likely, scammers will not download anything to the machine of the user, the greatest defense against scammers is never entering a username and password into a website that you are unsure of.

It’s essential to remember that even if the Steam account of a user doesn’t have expensive skins or hundreds of games, scammers can still target it. Whereas the end goal is always money, one compromised Steam account can be the entry point to hundreds of others through Steam’s friends lists. 

t’s much easier to persuade someone to enter their login data if players think that the scammer is a trusted friend. Remember, the data must be requested by scammers and players must give it to them. The best way to avoid it is to remember that if it sounds too good to be true, it’s probably a scam.