{"success":true,"data":{"id":"steam-mobile-authenticator-migration-phish","label":"Steam Mobile Authenticator migration phishing — email claims Steam Guard is migrating to a new app and the recipient must re-link their phone/re-scan QR at a non-steam.com URL, harvesting Steam Guard TOTP + session cookies. Valve/Steam community phish reports; PC Gamer 2026.","description":"Email impersonating Valve/Steam claiming the recipient must migrate to the new Steam Mobile Authenticator (following Valve's April 2024 forced-upgrade policy) or face a 15-day trading hold and eventual revocation of Steam marketplace trading privileges. The phishing email leads to an Adversary-in-the-Middle (AiTM) credential-harvesting page. This attack exploits genuine user confusion: Valve's real policy change created a population of confused Steam users who received legitimate migration reminders, making fake reminders indistinguishable. Group-IB's January 2026 report documented a sustained 2025-2026 Steam authenticator phishing wave; ESET's Q4 2025 research traced AiTM chain attacks using the authenticator-migration lure. Distinct from the existing fake-steam-gaming-account-phish (account suspension/ban language without authenticator-migration specificity). The 15-day trading hold language and \"Steam Guard mobile authenticator migration\" keywords are highly diagnostic.","tier":"danger","category":"phishing","isThin":false}}