A stolen gaming account rarely announces itself with a dramatic screen. It looks like a login that suddenly fails, a friend asking why you sent them a link, a purchase email for something you never bought, or a Steam Guard prompt at three in the morning from a country you have never visited. What happens in the next hour decides how much of it you get back — and the instinct almost everyone has, which is to hammer the password reset on the game platform, is the one step that reliably fails. This guide is the order that actually works, the real recovery route for each of the five platforms people lose accounts on most, and an honest account of what support teams can and cannot undo.
The first hour, in order
The sequence below applies whatever the platform. It is deliberately boring: it removes the attacker’s footholds from the outside in, so that by the time you touch the game account there is nowhere left for them to stand.
- Secure the email account firstChange the password from a device you trust, turn on two-factor authentication or a passkey, sign out all other sessions, and delete any forwarding rule, filter or recovery address you do not recognise. Attackers routinely add a silent forward so they keep receiving your reset links after you have "fixed" everything.
- Check the device you play on for malwareSession-stealing malware is the other common entry point, and it makes 2FA irrelevant because it steals the session after you have already passed it. Run a full scan before you sign back in anywhere, or the new password leaks the same way the old one did.
- Reset the game account password from a clean deviceUse the platform’s own reset page, typed into the address bar — never a link from an email or a chat message. If the reset email arrives and works, you are in the easy case.
- If the sign-in address was changed, switch to the recovery formThis is the fork in the road. Once the attacker has moved the email on the account, no self-service reset can help you, and you need the platform’s identity-verification process instead. The per-platform sections below cover exactly where that lives.
- Contact your bank or card issuer if a card was on fileDo this in parallel rather than after. Fraudulent purchases are far easier to challenge in the first days, and a card that has been used once will be used again until it is stopped.
- Write down the timeline while it is freshDates, times, the last purchase you actually made, the last email you actually received. Every recovery form asks for some of this, and reconstructing it from memory a week later is much harder than it sounds.
Why it is nearly always the email
Steam says it plainly in its own support material: accounts are commonly compromised after the associated email address is compromised. The same is true everywhere else, because the email inbox is the master key that every platform hands back to whoever can read it. That is why "my Steam got hacked" is usually shorthand for "my email got hacked, and Steam was the first thing they found in it".
The practical consequence is that recovering the game account without recovering the inbox is temporary. It also means the damage is rarely limited to one platform — if the same email backs your PSN, Epic and Riot logins, assume all of them are exposed and check each one rather than waiting to find out. The prevention side of this is covered in our guide to <a href="/blog/secure-gaming-account-2fa-passkeys-2026">2FA and passkeys for gaming accounts</a>; this post is about the part that comes after.
Steam
Steam’s recovery is the most self-service of the five, and its item policy is the harshest. Start at help.steampowered.com and choose the stolen-account path; Steam explicitly asks you to scan your computer and change your email password before you attempt the reset, for the reasons above.
- Go to help.steampowered.com and pick "I can’t sign in" → account stolenType the address rather than following a link. The wizard walks you through identity checks using the phone number, email address or payment methods historically attached to the account.
- Prove ownership with a past purchaseThe strongest evidence Steam accepts is a payment method or purchase history you can produce — a card’s last digits, a wallet code you redeemed, or the receipt from a retail key. Have it ready before you start the form.
- Revoke the attacker’s access once you are back inChange the password, then deauthorise every other device from the Steam Guard management page, and revoke your Steam Web API key at steamcommunity.com/dev/apikey. A stolen API key lets an attacker keep intercepting and cancelling your trades even after the password has changed — this step is skipped constantly and it is the reason people get robbed twice.
- Re-enable the Steam Guard Mobile AuthenticatorThe mobile authenticator, not email codes. It also gates trades and market listings behind a hold, which is the single most effective brake on inventory theft.
PlayStation Network
If your PSN password was changed but the sign-in ID is still yours, the ordinary password reset on Sony’s site is all you need. The difficult case is a changed sign-in ID, where the normal reset path has nothing to send to — at that point PlayStation routes you to its Online Assistant and a human review rather than an automated form.
- Secure the email that was on the account first, even if the attacker has already replaced it on PSN — you will be asked to prove you control it.
- Try the standard password reset at Sony’s account site. If it works, stop here and go straight to the clean-up section.
- If the sign-in ID was changed, open PlayStation’s Contact Us page and start the Online Assistant chat, which escalates to the account-recovery team.
- Have your Online ID, the current and previous sign-in email, and proof of a past purchase ready before you begin. Requirements vary by region, so expect the agent to ask for something not on this list.
- Once restored, turn on two-step verification immediately and check the wallet balance, linked payment methods and the primary-console setting.
Xbox and Microsoft accounts
An Xbox account is a Microsoft account, which means recovery runs through Microsoft’s identity systems rather than anything Xbox-specific. If you can still sign in, use the security dashboard to change the password and review recent activity. If you cannot — because the email, phone or password were all changed — the route is the Microsoft account recovery form at account.live.com/acsr.
- Fill the form in from a device, browser and network you have signed in from before — Microsoft weighs that familiarity when it scores your answers.
- Give a working alternate email address it can send the result to.
- List previous passwords you have used on the account, oldest ones included; near-misses still count in your favour.
- Add billing details for past purchases: the last four digits of a card, approximate dates, and what you bought.
- Include your Xbox console hardware ID and gamertag history if you have them.
- Name email addresses in your contacts and subject lines of recent messages if the account is also your inbox.
- Expect a decision by email in roughly a day, and submit again with more detail if the first attempt fails.
If Game Pass or a stored balance was on the account, check the subscription and payment sections as soon as you are back in — a compromised Microsoft account is often used to buy and resell digital goods rather than to play anything. Our guide to <a href="/blog/how-to-redeem-xbox-game-pass-code-stack-convert-2026">redeeming and stacking Game Pass codes</a> covers what should be on that screen.
Epic Games
Epic’s official advice starts where ours does: secure the email, because it is the key to the Epic account. The useful wrinkle is that Epic accounts are frequently linked to a console or social login — PlayStation, Xbox, Nintendo, Google and others — and that link is a side door back in when the email has been changed.
- Try the linked account firstIf you ever connected a PlayStation, Xbox, Nintendo or social login, sign in with that instead of the email. It often works while the email path is dead, and it puts you back inside the account in seconds.
- Change the email and password from insideIf the linked login works but the account email is now one you do not control, change it back and reset the password before doing anything else.
- Otherwise, file a hacked-account requestGo to epicgames.com/help, choose the contact route, and select the "I can’t access my account" and hacked-account options. Supply your original email address, display name, approximate last login, purchase history and linked accounts.
- Turn on 2FA once you are restoredEpic has long tied cosmetic rewards to enabling it, which is a rare case of security being made attractive rather than mandatory. Take the reward and keep the protection.
Riot: Valorant and League
Riot consolidated its games behind a single Riot Account, and recovery moved with it: it no longer lives on the League site but at recovery.riotgames.com, which handles League, Valorant, Teamfight Tactics and the rest from one place.
- Secure the email on the account first, as everywhere else.
- Run the self-service recovery at recovery.riotgames.com, choosing the region the account belongs to.
- If self-service fails, open a single, well-organised Player Support ticket rather than several thin ones — duplicates slow the queue down.
- Include a purchase timeline: when you first spent money, what the first skin or pass was, and roughly when. Riot can match this against transaction records, and it is the strongest evidence a player usually has.
- List the suspicious changes with dates — email change, region transfer, name change — so support can see the takeover pattern.
If you top up regularly, note that where the currency came from is also evidence: a record of the codes or cards you used builds the same purchase history support is looking for. Our walkthroughs for <a href="/blog/how-to-buy-rp-league-of-legends-2026">buying RP in League of Legends</a> and <a href="/blog/how-to-buy-valorant-points-vp-2026">buying Valorant Points</a> cover the legitimate routes, all of which leave a receipt.
Where to go, per platform
| Platform | Where recovery starts | Strongest proof of ownership | Typical wait |
|---|---|---|---|
| Steam | help.steampowered.com → account stolen wizard | A payment method or purchase on the account | Minutes to a few days, mostly automated |
| PlayStation | Password reset, or the Online Assistant if the sign-in ID changed | Online ID, previous sign-in email, past purchase | Same day to several days, agent-handled |
| Xbox / Microsoft | Security dashboard, or account.live.com/acsr if locked out | Old passwords, billing details, console hardware ID | About 24 hours per submission |
| Epic Games | A linked console or social login, else epicgames.com/help | Original email, display name, purchase history, linked accounts | Days, ticket-based |
| Riot | recovery.riotgames.com, then Player Support | First-purchase timeline and spend history | Days, ticket-based |
Proving the account is yours
Every one of these processes reduces to the same question: can you show knowledge of the account that only its owner would have? Attackers can change the email, the password and the display name, but they cannot retroactively invent the eight years of history behind it. Gather this before you open a ticket, because a complete first submission is worth more than three follow-ups.
- The original email address the account was created with, even if it no longer works.
- Card details limited to what a receipt shows — issuing bank, last four digits, approximate dates. Never the full number, and no support agent will ask for it.
- Order numbers or receipt emails for past purchases, including gift card and wallet top-ups.
- Codes you have redeemed onto the account, and where you bought them.
- The approximate creation date, old display names, and the country the account was registered in.
- Linked console, social or platform accounts.
- A dated list of the changes the attacker made.
What gets restored, and what does not
This is where expectations need managing. Recovery is about the account, not its contents, and the platforms differ sharply on how much of the damage they will reverse.
| What was lost | Usually recoverable? | Notes |
|---|---|---|
| Access to the account itself | Yes | This is what every recovery process is designed to do |
| Games and licences already owned | Yes | Licences stay attached to the account and come back with it |
| Tradeable inventory items | No on Steam | Steam does not restore items that have left an account for any reason |
| Spent wallet balance | No | Treated as delivered once spent; PSN funds are explicitly non-refundable |
| Fraudulent card charges | Often, via the bank | A chargeback is the realistic route — but it can suspend the account it was spent on |
| In-game currency bought by the attacker | Sometimes | A few publishers reverse it on a compromised account; most treat it as consumed |
| Rank, progress and playtime | Yes | These live on the account and survive the takeover |
“Recovery gets the account back. It does not get the inventory back. Plan your security around that sentence rather than around the hope of an exception.”
— Virtwave Gaming Team, Editorial note
The clean-up after you are back in
Regaining access is the halfway point. An attacker who got in once has usually left something behind that lets them do it again, and these are the places it hides.
- Sign out all other sessions and deauthorise every device you do not recognise.
- Revoke API keys and connected third-party apps — on Steam this is the API key page, and it is the step most often missed.
- Re-check the email account for forwarding rules, filters and alternate recovery addresses added while they had control.
- Remove or re-add payment methods, and delete any address or payment detail that is not yours.
- Check subscriptions for anything new that will quietly renew next month.
- Turn on the strongest second factor available: an authenticator app or passkey, not SMS.
- Review friends, linked accounts and any group or family sharing the attacker may have joined.
- Change the password on any other account that shared the old one — assume it is now public.
Shrinking the blast radius next time
You cannot reduce the chance of a takeover to zero, but you can decide in advance how much a successful one is worth. The single biggest variable is what a stranger finds when they get in: a saved card with no limit, or a small prepaid balance and nothing else.
This is the same reasoning behind funding a young player’s account with codes rather than a card, which we cover in <a href="/blog/gaming-spending-limits-parental-controls-2026">gaming spending limits and parental controls</a>. Combine a prepaid balance with an authenticator app and a unique password on the email account, and the realistic worst case shrinks from "my card was drained" to "I lost an afternoon filing a form".
FAQs
The hacker changed my email — can I still get the account back?
Will Steam give me my items back?
How long does recovery take?
My recovery form was rejected. Is that the end?
Should I do a chargeback for the fraudulent purchases?
Does two-factor authentication actually stop this?
Can someone steal my account with just my gamertag or Steam ID?
The attacker enabled 2FA on my own account. What now?
Is it worth paying an "account recovery service"?
Console-first editors with combined 20+ years covering PlayStation, Xbox, Nintendo and PC gaming ecosystems. They write the practical guides our customers actually use to set up and troubleshoot their accounts.



