Skip to content
Innovate Hub

Innovate Hub Account safety

Checklist 6 of 8

Protecting a game account

A long-running collection RPG account represents months of play, and in this genre accounts are targeted for exactly that reason. The measures that protect one are short, free, and best applied on the day the account is created.

Short answer. Link the account to an email address you control, use a password that exists nowhere else, and turn on two-factor authentication if the publisher offers it. Then adopt one rule: account credentials are only ever entered in the publisher’s own client or on the publisher’s own site, and nowhere else, for any reason.

On this page

  1. Why these accounts are targeted
  2. The setup checklist
  3. The approaches used, described plainly
  4. One rule that covers most of it
  5. Account buying, selling and boosting
  6. If something has already gone wrong
  7. The title advertised here

Why these accounts are targeted

An established account in this genre has value that is easy to see from outside. It holds characters that took months to acquire, it may have had money spent on it, and it is attached to an email address that is probably used elsewhere. An account is also easier to take than it is to build, which is the whole of the incentive.

Nothing about this is specific to any one title, and none of it means a reader is currently at risk of anything. It means that a small amount of setup, done once, removes most of the opportunity — in the same way that locking a door is ordinary rather than alarming.

The setup checklist

Once, on the day the account is created

  • Link the account. An account still tied to the device cannot be recovered, cannot be moved to a new computer, and cannot be proven to be yours.
  • Use an address you will still control in five years. Not a work address, not one tied to an internet provider you might leave.
  • Use a unique password. Reuse is how a breach at an unrelated service becomes a lost game account. A password manager makes this practical rather than theoretical.
  • Turn on two-factor authentication where the publisher offers it. The Australian Cyber Security Centre publishes guidance on why this is the measure that most reduces the value of a stolen password.
  • Secure the email account itself. Whoever controls the email can usually reset everything attached to it, which makes it the more valuable target of the two.
  • Write down the recovery details. The address used, the linking method, the approximate registration date, and the platform receipts for any purchase. Support requests about a lost account ask for these.

The approaches used, described plainly

Scamwatch, operated by the National Anti-Scam Centre, collects reports of scams in Australia and publishes descriptions of what is currently circulating. The approaches aimed at players follow a small number of recognisable shapes.

Free currency and code generators

A site or a video offers in-game currency in exchange for signing in with the game account. There is no mechanism by which a third party can add currency to an account, so the sign-in form is the entire purpose of the page. What arrives is a credential harvest, not currency.

Imitation support contact

A message appearing to come from the publisher reports a problem with the account — a suspension, a security alert, a verification requirement — and links to a page asking for the login. Publishers resolve account matters inside the client or through their own support system, and a real publisher never needs a password typed into a link from a message.

Clan and group recruitment that moves elsewhere

Contact begins in the game or on a community server and moves to a private channel, where a request follows: a screenshot of account details for a verification, a linked account for a boost, or a login shared temporarily. The move off the official channel is the part worth noticing.

Modified clients and private servers

Software offering unlimited currency, unlocked characters or an early version is not published by the game’s publisher, and installing it means running code from an unknown source on the machine where the account lives. This is also a common route for credential theft, and it usually breaches the game’s own terms as well.

One rule that covers most of it

All four shapes above reduce to the same thing, which is why a single rule handles them without needing any of them to be recognised individually.

The rule

Account credentials are entered only in the publisher’s own client, or on the publisher’s own site reached by typing the address. Nowhere else, for any reason, however plausible.

This works because it does not require judging whether a page looks genuine, and looking genuine is the one thing an imitation page is designed to do. It also removes the pressure element entirely: a message that demands an urgent login is answered by opening the game normally and looking, which costs nothing and settles the question.

The same applies to anything asking for a one-time code. A code sent for two-factor authentication is for you to type into the publisher’s own login, never to read out, forward or paste anywhere else. A request for it is a request to defeat the protection it exists to provide.

Account buying, selling and boosting

Marketplaces offering finished accounts, and services offering to play an account up to a standard, exist in most large titles. Two things are worth knowing before engaging with either.

The first is contractual: publishers generally prohibit account transfer in their terms, and an account bought this way can be closed without recourse. The second is practical: handing over credentials means handing over the linked email relationship as well, and a seller who created the original registration retains a recovery path to it. Accounts sold and then recovered by the original creator are an established pattern.

These transactions also sit outside the platform’s payment system, which means outside the receipts and dispute mechanisms that ordinary purchases carry. Where money is lost this way, Scamwatch takes reports and sets out what to do next.

If something has already gone wrong

Speed matters more than diagnosis. Work through this in order rather than trying to establish what happened first.

  1. Change the email password first, not the game password

    Whoever controls the email controls every reset link. The email account is the one to secure before anything else.

  2. Then change the game password and end other sessions

    Most publishers offer an option to sign out everywhere, which is what removes an intruder rather than just changing the lock.

  3. Change the password anywhere else the same one was used

    This is the point at which reuse becomes expensive, and it is the reason for the unique-password rule.

  4. Contact the publisher’s own support

    Through the client or the official site, never through a link in a message. Have the recovery details and purchase receipts ready.

  5. Check for charges

    Review the platform account and the card statement, and contact the bank or card provider if anything is unfamiliar. They have their own dispute process.

  6. Report it

    Scamwatch takes reports of scams in Australia. The Australian Cyber Security Centre publishes guidance on securing accounts afterwards, and the eSafety Commissioner handles online harm including cyberbullying.

The title advertised here

Raid: Shadow Legends is the game this site is paid to link to. Its publisher’s description covers Champions, dungeons, Clan Boss fights and a fully-voiced campaign across twelve locations; it does not state what account linking options, two-factor authentication or recovery processes the game provides. Those are in the game’s own account settings and support documentation, and the checklist above is written to be worked through there.

Paid link. Registering and starting the tutorial after following it pays ITmatters s.r.o. a fixed fee from the game’s affiliate programme, at no cost to you. Everything on this page applies to that title exactly as it applies to any other.

Visit the Raid: Shadow Legends website

Sources

Scam types currently reported in Australia, and the reporting process, are published by Scamwatch, operated by the National Anti-Scam Centre. Guidance on passwords, multi-factor authentication and securing accounts is published by the Australian Cyber Security Centre. Online harm reporting is handled by the eSafety Commissioner. Account linking and recovery features vary by publisher and are documented by each one. Last reviewed 16 September 2026.

Other checklists on this site