Kinetrixa

Keeping a game account secure, and where to report problems

A security and reporting checklist for Australian players · Last reviewed 16 September 2026

Nothing on this page says anything about the state of your account or your computer, because this site cannot see either and does not try to. It describes how game accounts are generally lost, the settings that prevent most of it, and which Australian body handles which kind of report if something does go wrong.

Quick answer

A unique passphrase in a password manager, multi-factor authentication on both the game account and the mailbox behind it, and a firm habit of never entering credentials on a page you arrived at from a link. Those three cover most of what follows. If something does happen, the game publisher restores the account and an Australian agency takes the report — they are different steps and both are worth doing.

How game accounts are generally lost

Accounts in this category have resale value, which is the whole explanation for why anyone bothers. Four routes account for most losses, and none of them involve anything sophisticated.

Reused passwords. A password used on a game account and also on a forum that is later breached becomes a working password for both. Automated attempts to use leaked credentials across other services — credential stuffing — are cheap to run at scale, which is why reuse is the single highest-value habit to change.

Phishing. A message or page that imitates the publisher and asks for a login. These are often well made, and the reliable defence is procedural rather than visual: never log in from a link, and instead type the publisher's address into the browser yourself.

Software from the wrong place. Cheats, unofficial mod packs, "unlockers" and cracked launchers are distributed by people whose interest in you is not the game. Downloading and running one is granting a stranger's program the same access to your computer that you have.

Trade and gift scams. An offer that requires handing over a password, logging into a third-party site, or moving the conversation to an outside chat application. Publisher staff do not ask for passwords, and no legitimate in-game trade needs your credentials.

The Australian Cyber Security Centre publishes the government's own guidance on passphrases, multi-factor authentication and recognising phishing, at cyber.gov.au. It is written for a general audience and is a better first read than any advice on a site like this one.

The settings that do the work

  1. Multi-factor authentication on the game account. An authenticator app is generally preferable to SMS, because it does not depend on keeping the same phone number and is not affected if a number is transferred away from you.
  2. Multi-factor authentication on the mailbox. The mailbox can reset the game account, so protecting the game and leaving the mailbox open protects nothing.
  3. A unique passphrase per account, in a password manager. Length matters more than symbol substitutions, and a manager is what makes uniqueness practical across dozens of accounts.
  4. Recovery details you have actually checked. Confirm that the recovery address on file is one you can open, today, before you need it.

Reading the signals calmly

What a given signal usually means, and the proportionate response
What you seeWhat it usually meansWhat to do
An email saying your password was changed, which you did not changeEither a genuine notice of a change someone else made, or a phishing message imitating oneDo not use links in the message. Open the publisher's site directly and attempt a password reset from there
A login notification from an unfamiliar locationOften a data-centre location from a legitimate mobile connection; sometimes a genuine third-party loginChange the passphrase and enable multi-factor authentication if it is not already on
Items or currency missingEither a trade you authorised and misremember, or account access by someone elseContact publisher support through its own site, and keep any transaction records
A message from "support" asking you to verify a passwordPhishing, without exceptionDo not reply. Report it to Scamwatch and delete it
A card charge you do not recogniseA stored payment method being used, or an unrelated card problemContact your bank about the transaction, then remove stored cards from the account

Worked example: one password, two accounts

Worked example

A player in Hobart used the same password on a game account and on a hobby forum. The forum suffered a breach two years ago. Nothing happened for a long time, and then the game account was accessed and its items traded away.

What was and was not the cause. The game publisher was not breached. The password was correct when it was used, which is why nothing looked unusual to the publisher's systems. The delay is normal: leaked credential lists are traded and reused long after the original breach.

The sequence that followed. Password reset from the publisher's own site; multi-factor authentication enabled; the same password found and replaced on four other services using a password manager's reuse report; a support ticket opened with the publisher about the traded items; a report lodged with the Australian Cyber Security Centre. The items were partially restored, which is a publisher's discretion rather than an entitlement.

The change that would have prevented it. Not a better password — a different one on each account, which is a password manager rather than a feat of memory.

If an account has been accessed by someone else

Work in this order. The first three steps are about regaining control, and the rest are about limiting the consequences.

  1. Reset the mailbox password first, because the mailbox controls everything else.
  2. Reset the game account password from the publisher's own site, typed into the browser rather than followed from a link.
  3. Enable multi-factor authentication, and sign out other sessions if the publisher offers that.
  4. Remove any stored payment method, and contact your bank about any charge you did not make.
  5. Open a support ticket with the publisher, with dates and what changed. Publishers can sometimes reverse trades, and always need specifics.
  6. Find every other account using that password and change them, using a password manager's reuse report rather than memory.

Where each kind of report goes in Australia

These are separate routes with separate purposes, and using the right one gets a useful response faster.

Two categories to stay out of entirely

Cheat software and unofficial clients are a poor trade even on their own terms: they carry a real chance of a permanent ban and they require running an unknown program with full access to your computer. There is no version of this that is only a game question.

Currency "generators" and free-premium pages are also not what they appear to be. A page offering something a publisher sells, for nothing, is collecting either credentials or payment details. It does not need to be argued with; it needs to be closed.

Terms used above

Credential stuffing
Automated attempts to log in to many services using username and password pairs leaked from a breach elsewhere. It succeeds only where a password has been reused.
Phishing
A message or page imitating a legitimate organisation in order to capture a login or a payment detail.
Multi-factor authentication
A second proof of identity beyond the password, usually a code from an app. It makes a leaked password insufficient on its own.
Password manager
Software that generates and stores a different passphrase for every account, so that uniqueness does not depend on memory.

The checklist

What to read next