Guide · Account Security

Hacked Gaming Account? Recovery Steps for Steam, PSN, Xbox, Epic and Riot (2026)

A calm, ordered playbook for a compromised gaming account: why you fix the email before the game, the exact recovery route for Steam, PlayStation, Xbox, Epic and Riot, what proof of ownership each one wants, what does and does not get restored, and the clean-up that stops it happening twice.

  • Fix the email first — the game account is downstream of it
  • Every platform’s real recovery URL, in one place
  • Updated 21 August 2026
✍️ · Gaming Commerce Editors📅 Aug 21, 2026🕒 Updated Aug 21, 202613 min read✓ Fact-checked by Layla Farah
Abstract glowing blue steps on a dark background

A stolen gaming account rarely announces itself with a dramatic screen. It looks like a login that suddenly fails, a friend asking why you sent them a link, a purchase email for something you never bought, or a Steam Guard prompt at three in the morning from a country you have never visited. What happens in the next hour decides how much of it you get back — and the instinct almost everyone has, which is to hammer the password reset on the game platform, is the one step that reliably fails. This guide is the order that actually works, the real recovery route for each of the five platforms people lose accounts on most, and an honest account of what support teams can and cannot undo.

The first hour, in order

The sequence below applies whatever the platform. It is deliberately boring: it removes the attacker’s footholds from the outside in, so that by the time you touch the game account there is nowhere left for them to stand.

  1. Secure the email account first
    Change the password from a device you trust, turn on two-factor authentication or a passkey, sign out all other sessions, and delete any forwarding rule, filter or recovery address you do not recognise. Attackers routinely add a silent forward so they keep receiving your reset links after you have "fixed" everything.
  2. Check the device you play on for malware
    Session-stealing malware is the other common entry point, and it makes 2FA irrelevant because it steals the session after you have already passed it. Run a full scan before you sign back in anywhere, or the new password leaks the same way the old one did.
  3. Reset the game account password from a clean device
    Use the platform’s own reset page, typed into the address bar — never a link from an email or a chat message. If the reset email arrives and works, you are in the easy case.
  4. If the sign-in address was changed, switch to the recovery form
    This is the fork in the road. Once the attacker has moved the email on the account, no self-service reset can help you, and you need the platform’s identity-verification process instead. The per-platform sections below cover exactly where that lives.
  5. Contact your bank or card issuer if a card was on file
    Do this in parallel rather than after. Fraudulent purchases are far easier to challenge in the first days, and a card that has been used once will be used again until it is stopped.
  6. Write down the timeline while it is fresh
    Dates, times, the last purchase you actually made, the last email you actually received. Every recovery form asks for some of this, and reconstructing it from memory a week later is much harder than it sounds.

Why it is nearly always the email

Steam says it plainly in its own support material: accounts are commonly compromised after the associated email address is compromised. The same is true everywhere else, because the email inbox is the master key that every platform hands back to whoever can read it. That is why "my Steam got hacked" is usually shorthand for "my email got hacked, and Steam was the first thing they found in it".

The practical consequence is that recovering the game account without recovering the inbox is temporary. It also means the damage is rarely limited to one platform — if the same email backs your PSN, Epic and Riot logins, assume all of them are exposed and check each one rather than waiting to find out. The prevention side of this is covered in our guide to <a href="/blog/secure-gaming-account-2fa-passkeys-2026">2FA and passkeys for gaming accounts</a>; this post is about the part that comes after.

Steam

Steam’s recovery is the most self-service of the five, and its item policy is the harshest. Start at help.steampowered.com and choose the stolen-account path; Steam explicitly asks you to scan your computer and change your email password before you attempt the reset, for the reasons above.

  1. Go to help.steampowered.com and pick "I can’t sign in" → account stolen
    Type the address rather than following a link. The wizard walks you through identity checks using the phone number, email address or payment methods historically attached to the account.
  2. Prove ownership with a past purchase
    The strongest evidence Steam accepts is a payment method or purchase history you can produce — a card’s last digits, a wallet code you redeemed, or the receipt from a retail key. Have it ready before you start the form.
  3. Revoke the attacker’s access once you are back in
    Change the password, then deauthorise every other device from the Steam Guard management page, and revoke your Steam Web API key at steamcommunity.com/dev/apikey. A stolen API key lets an attacker keep intercepting and cancelling your trades even after the password has changed — this step is skipped constantly and it is the reason people get robbed twice.
  4. Re-enable the Steam Guard Mobile Authenticator
    The mobile authenticator, not email codes. It also gates trades and market listings behind a hold, which is the single most effective brake on inventory theft.

PlayStation Network

If your PSN password was changed but the sign-in ID is still yours, the ordinary password reset on Sony’s site is all you need. The difficult case is a changed sign-in ID, where the normal reset path has nothing to send to — at that point PlayStation routes you to its Online Assistant and a human review rather than an automated form.

  1. Secure the email that was on the account first, even if the attacker has already replaced it on PSN — you will be asked to prove you control it.
  2. Try the standard password reset at Sony’s account site. If it works, stop here and go straight to the clean-up section.
  3. If the sign-in ID was changed, open PlayStation’s Contact Us page and start the Online Assistant chat, which escalates to the account-recovery team.
  4. Have your Online ID, the current and previous sign-in email, and proof of a past purchase ready before you begin. Requirements vary by region, so expect the agent to ask for something not on this list.
  5. Once restored, turn on two-step verification immediately and check the wallet balance, linked payment methods and the primary-console setting.

Xbox and Microsoft accounts

An Xbox account is a Microsoft account, which means recovery runs through Microsoft’s identity systems rather than anything Xbox-specific. If you can still sign in, use the security dashboard to change the password and review recent activity. If you cannot — because the email, phone or password were all changed — the route is the Microsoft account recovery form at account.live.com/acsr.

  • Fill the form in from a device, browser and network you have signed in from before — Microsoft weighs that familiarity when it scores your answers.
  • Give a working alternate email address it can send the result to.
  • List previous passwords you have used on the account, oldest ones included; near-misses still count in your favour.
  • Add billing details for past purchases: the last four digits of a card, approximate dates, and what you bought.
  • Include your Xbox console hardware ID and gamertag history if you have them.
  • Name email addresses in your contacts and subject lines of recent messages if the account is also your inbox.
  • Expect a decision by email in roughly a day, and submit again with more detail if the first attempt fails.

If Game Pass or a stored balance was on the account, check the subscription and payment sections as soon as you are back in — a compromised Microsoft account is often used to buy and resell digital goods rather than to play anything. Our guide to <a href="/blog/how-to-redeem-xbox-game-pass-code-stack-convert-2026">redeeming and stacking Game Pass codes</a> covers what should be on that screen.

Epic Games

Epic’s official advice starts where ours does: secure the email, because it is the key to the Epic account. The useful wrinkle is that Epic accounts are frequently linked to a console or social login — PlayStation, Xbox, Nintendo, Google and others — and that link is a side door back in when the email has been changed.

  1. Try the linked account first
    If you ever connected a PlayStation, Xbox, Nintendo or social login, sign in with that instead of the email. It often works while the email path is dead, and it puts you back inside the account in seconds.
  2. Change the email and password from inside
    If the linked login works but the account email is now one you do not control, change it back and reset the password before doing anything else.
  3. Otherwise, file a hacked-account request
    Go to epicgames.com/help, choose the contact route, and select the "I can’t access my account" and hacked-account options. Supply your original email address, display name, approximate last login, purchase history and linked accounts.
  4. Turn on 2FA once you are restored
    Epic has long tied cosmetic rewards to enabling it, which is a rare case of security being made attractive rather than mandatory. Take the reward and keep the protection.

Riot: Valorant and League

Riot consolidated its games behind a single Riot Account, and recovery moved with it: it no longer lives on the League site but at recovery.riotgames.com, which handles League, Valorant, Teamfight Tactics and the rest from one place.

  1. Secure the email on the account first, as everywhere else.
  2. Run the self-service recovery at recovery.riotgames.com, choosing the region the account belongs to.
  3. If self-service fails, open a single, well-organised Player Support ticket rather than several thin ones — duplicates slow the queue down.
  4. Include a purchase timeline: when you first spent money, what the first skin or pass was, and roughly when. Riot can match this against transaction records, and it is the strongest evidence a player usually has.
  5. List the suspicious changes with dates — email change, region transfer, name change — so support can see the takeover pattern.

If you top up regularly, note that where the currency came from is also evidence: a record of the codes or cards you used builds the same purchase history support is looking for. Our walkthroughs for <a href="/blog/how-to-buy-rp-league-of-legends-2026">buying RP in League of Legends</a> and <a href="/blog/how-to-buy-valorant-points-vp-2026">buying Valorant Points</a> cover the legitimate routes, all of which leave a receipt.

Where to go, per platform

Recovery routes and evidence, August 2026
PlatformWhere recovery startsStrongest proof of ownershipTypical wait
Steamhelp.steampowered.com → account stolen wizardA payment method or purchase on the accountMinutes to a few days, mostly automated
PlayStationPassword reset, or the Online Assistant if the sign-in ID changedOnline ID, previous sign-in email, past purchaseSame day to several days, agent-handled
Xbox / MicrosoftSecurity dashboard, or account.live.com/acsr if locked outOld passwords, billing details, console hardware IDAbout 24 hours per submission
Epic GamesA linked console or social login, else epicgames.com/helpOriginal email, display name, purchase history, linked accountsDays, ticket-based
Riotrecovery.riotgames.com, then Player SupportFirst-purchase timeline and spend historyDays, ticket-based

Proving the account is yours

Every one of these processes reduces to the same question: can you show knowledge of the account that only its owner would have? Attackers can change the email, the password and the display name, but they cannot retroactively invent the eight years of history behind it. Gather this before you open a ticket, because a complete first submission is worth more than three follow-ups.

  • The original email address the account was created with, even if it no longer works.
  • Card details limited to what a receipt shows — issuing bank, last four digits, approximate dates. Never the full number, and no support agent will ask for it.
  • Order numbers or receipt emails for past purchases, including gift card and wallet top-ups.
  • Codes you have redeemed onto the account, and where you bought them.
  • The approximate creation date, old display names, and the country the account was registered in.
  • Linked console, social or platform accounts.
  • A dated list of the changes the attacker made.

What gets restored, and what does not

This is where expectations need managing. Recovery is about the account, not its contents, and the platforms differ sharply on how much of the damage they will reverse.

Realistic expectations after a successful recovery
What was lostUsually recoverable?Notes
Access to the account itselfYesThis is what every recovery process is designed to do
Games and licences already ownedYesLicences stay attached to the account and come back with it
Tradeable inventory itemsNo on SteamSteam does not restore items that have left an account for any reason
Spent wallet balanceNoTreated as delivered once spent; PSN funds are explicitly non-refundable
Fraudulent card chargesOften, via the bankA chargeback is the realistic route — but it can suspend the account it was spent on
In-game currency bought by the attackerSometimesA few publishers reverse it on a compromised account; most treat it as consumed
Rank, progress and playtimeYesThese live on the account and survive the takeover

Recovery gets the account back. It does not get the inventory back. Plan your security around that sentence rather than around the hope of an exception.

Virtwave Gaming Team, Editorial note

The clean-up after you are back in

Regaining access is the halfway point. An attacker who got in once has usually left something behind that lets them do it again, and these are the places it hides.

  • Sign out all other sessions and deauthorise every device you do not recognise.
  • Revoke API keys and connected third-party apps — on Steam this is the API key page, and it is the step most often missed.
  • Re-check the email account for forwarding rules, filters and alternate recovery addresses added while they had control.
  • Remove or re-add payment methods, and delete any address or payment detail that is not yours.
  • Check subscriptions for anything new that will quietly renew next month.
  • Turn on the strongest second factor available: an authenticator app or passkey, not SMS.
  • Review friends, linked accounts and any group or family sharing the attacker may have joined.
  • Change the password on any other account that shared the old one — assume it is now public.

Shrinking the blast radius next time

You cannot reduce the chance of a takeover to zero, but you can decide in advance how much a successful one is worth. The single biggest variable is what a stranger finds when they get in: a saved card with no limit, or a small prepaid balance and nothing else.

Card saved on the account
Prepaid gift card balance
Ceiling on the damage
Your card limit — spent in minutes, often across many small purchases
Whatever balance is on the account, and not a cent more
Getting money back
A chargeback, which can itself suspend the account
Nothing to reverse, because there was nothing extra to take
Exposure of your details
Billing address and card details visible in the account
No card on file to expose
Convenience
Highest — one tap to buy
One extra step: redeem a code when you want to spend
For a child’s account
Needs purchase approvals layered on top to be safe
A hard ceiling by design, which is why it works

This is the same reasoning behind funding a young player’s account with codes rather than a card, which we cover in <a href="/blog/gaming-spending-limits-parental-controls-2026">gaming spending limits and parental controls</a>. Combine a prepaid balance with an authenticator app and a unique password on the email account, and the realistic worst case shrinks from "my card was drained" to "I lost an afternoon filing a form".

FAQs

The hacker changed my email — can I still get the account back?
Yes, but not through the ordinary password reset, which has nothing left to send to. You need the platform’s identity-verification route instead: the stolen-account wizard on Steam, the Online Assistant on PlayStation, account.live.com/acsr for Microsoft, the hacked-account form at Epic, and Player Support after recovery.riotgames.com for Riot. All of them decide on evidence of ownership rather than on access to the inbox.
Will Steam give me my items back?
No. Steam Support does not restore items that have left an account, whether they were traded, sold on the market, gifted or deleted, and spent wallet balance is not restored either. The account itself and the games licensed to it come back; the inventory does not. The Steam Guard Mobile Authenticator and its trade holds are the protection that actually prevents this.
How long does recovery take?
Steam’s process is largely automated and can finish in minutes when you can prove a past payment. Microsoft reviews the recovery form and emails a decision in roughly a day per submission. PlayStation, Epic and Riot are agent-handled and typically take a few days, longer at busy times. A thorough first submission is the main thing under your control.
My recovery form was rejected. Is that the end?
No — you can submit again, and a second attempt with more detail often succeeds where the first failed. Add anything you left out: older passwords, more purchase dates, the console hardware ID, contacts and subject lines. Submitting from a device and network you have used before genuinely helps, because familiarity is one of the signals being scored.
Should I do a chargeback for the fraudulent purchases?
Talk to your bank early, but understand the trade-off: a chargeback against a platform can get the account suspended for the unpaid balance, which is awkward when you have just recovered it. Where the platform offers its own fraud process, try that first and keep the chargeback as the fallback.
Does two-factor authentication actually stop this?
It stops the overwhelming majority of it — credential stuffing and ordinary phishing both fail against an authenticator app or a passkey. What it does not stop is session-stealing malware, which takes the session after you have passed the check. That is why scanning the device is part of recovery and not an optional extra.
Can someone steal my account with just my gamertag or Steam ID?
No. Those are public by design and are all a legitimate top-up or a friend request ever needs. What is dangerous to share is a password, a one-time code, a screenshot of an unredeemed gift card PIN, or a login on a page you reached from a link.
The attacker enabled 2FA on my own account. What now?
Say so explicitly in the recovery request, because it changes which route applies — Microsoft’s recovery form, for instance, cannot be used on an account with two-step verification switched on, so that case has to go through support. Lead with the timeline showing the 2FA was added after the takeover.
Is it worth paying an "account recovery service"?
No. Every legitimate recovery route is free and runs on the platform’s own domain. Paid recovery offers that arrive by Discord, WhatsApp or game chat are a second theft aimed at people who have just proved they own something worth stealing — and they will ask for exactly the credentials no real agent ever requests.
Prevention is the companion piece to this one: locking down your gaming accounts with 2FA and passkeys covers the setup that makes most of the above unnecessary, and gift card scam statistics explains why gaming accounts and gift card codes are targeted together. If a card you were sent will not redeem, the cause is usually mundane rather than criminal — start with gift card regions and country locks explained. For funding an account without leaving a card on it, the Steam, PlayStation and Xbox product pages are the place to start, and the complete Steam gift card guide covers how the wallet behaves once the balance is on it.
Gaming Commerce Editors

Console-first editors with combined 20+ years covering PlayStation, Xbox, Nintendo and PC gaming ecosystems. They write the practical guides our customers actually use to set up and troubleshoot their accounts.

Gaming Commerce Editors

Console-first editors with combined 20+ years covering PlayStation, Xbox, Nintendo and PC gaming ecosystems. They write the practical guides our customers actually use to set up and troubleshoot their accounts.

Fund your account with a prepaid balance

All articles →
💬

FAQ Assistant

Click a question to see the answer

🤖

Select a question below
to get instant answers

🛒

Ordering & Purchasing

📧

Delivery & Activation

💰

Refunds & Returns

🔐

Account & Security

💬

Support

🔧

Technical Issues