Guide
Staying safe when you play online
Most trouble in online gaming does not come from the game. It comes from someone getting into your account, or from a message that tricks you into handing over a password. The good news is that a few durable habits prevent nearly all of it, and none of them takes long to set up.
Your account is the thing to protect
An online game account holds your progress, your settings, and any money you have spent inside the game. To someone else it can also have resale value. That combination is why accounts, rather than devices or the games themselves, are the usual target. If you secure the account well, most other risks shrink to something manageable.
The Australian Cyber Security Centre publishes plain, regularly updated guidance on securing online accounts and devices, and it is a good general reference alongside this page. You can read it at cyber.gov.au. What follows applies that thinking to the specific case of a gaming account.
Passwords that actually work
A strong password is long, unique to the account, and not something a stranger could guess or find. Length matters more than a scatter of symbols: a passphrase of several unrelated words is both harder to break and easier to remember than a short, complicated string. The single most important rule is not to reuse a password you already use somewhere else, because a leak on one site then unlocks the others.
A simple standard to aim for
- At least 14 characters, or a passphrase of four or more unrelated words.
- Not used for any other account, ever.
- Stored in a reputable password manager, not in a note or a browser you share.
- Changed promptly if you hear that a service you use has had a breach.
A password manager does the remembering for you, which is what makes a unique password per account realistic rather than aspirational. Most operating systems now include one at no cost.
Two-factor sign-in
Two-factor authentication, sometimes shown as 2FA or multi-factor, asks for a second proof of identity in addition to your password — usually a code from an app on your phone. Even if someone learns your password, they cannot sign in without that second factor. Where a game or its platform offers it, turning it on is the single most effective step you can take.
-
Find the security settings
Look in your account or platform settings for “two-factor”, “two-step”, or “multi-factor” authentication.
-
Prefer an authenticator app
An app that generates codes is generally more robust than codes sent by text message. Set one up if the option is offered.
-
Save your backup codes
Most services give you one-time backup codes when you enable 2FA. Store them somewhere safe and offline so you can still get in if you lose your phone.
Recognising phishing
Phishing is a message — an email, a chat, a post — designed to trick you into revealing a password or clicking a harmful link. In gaming it often arrives as a too-good offer (“free premium currency, just log in here”), a fake warning that your account is at risk, or a message that appears to come from a friend whose own account was taken over.
What to watch out for
- Any message that creates urgency — “act now or lose your account”. Genuine services rarely rush you.
- A link whose address does not match the game’s real website. Hover to check before clicking; on a phone, press and hold to preview.
- A request to enter your password on a page you reached through a link rather than by typing the address yourself.
- Offers of free currency or items in exchange for logging in somewhere unfamiliar.
The safe habit is simple: never sign in through a link you were sent. If a message claims there is a problem with your account, open a new browser tab, type the game’s address yourself, and check from there. If you think you have received a scam message, you can report it to Scamwatch, run by the National Anti-Scam Centre.
The device you play on
Because desktop online games run on your computer, ordinary computer hygiene protects your gaming too. Keep your operating system and your games updated, since updates often close security gaps. Download games and their updates only from the vendor’s own site or an official store — our guide to avoiding download scams explains how to tell a genuine source from a fake one. Nothing on this page suggests your device is currently at risk; it is general practice, the kind a public advisory recommends to everyone.
If your account is taken over
If you can no longer sign in, or you see activity you did not carry out, act calmly and in order.
-
Reset the password from the real site
Go to the game’s official website directly and use its password-reset process. If you still have access, change the password immediately and sign out other sessions.
-
Secure your email first
Your email account controls password resets everywhere. If it may also be compromised, secure it before anything else and enable two-factor sign-in on it.
-
Contact the vendor’s support
Use the official support channel to report the takeover and request recovery. Keep any receipts for in-game purchases; they can help prove the account is yours.
-
Report and seek help if money is involved
If you have lost money, report it to Scamwatch and, for account security guidance, see the Australian Cyber Security Centre.
Younger players
If a young person in your household plays online, the same habits apply, with a little more oversight. Set purchase confirmation on shared devices, talk about not sharing passwords even with friends, and agree on what to do if a stranger makes contact in a game. The eSafety Commissioner provides Australian-specific advice for parents and carers on online safety, including gaming, and is the right body to turn to if something goes wrong online.
Shared computers and public networks
Where you play matters as well as how. On a shared or public computer — a library, a friend’s machine, an internet café — avoid saving your password in the browser, and make sure you sign out fully when you finish rather than just closing the window. If you have used a shared computer to sign in, it is sensible to change your password afterwards from a device you control. On public Wi-Fi, prefer networks you recognise, and be aware that account activity is safest over a connection you trust. None of this means public networks are unsafe to use in general; it means the small habits of signing out and not storing passwords are worth keeping when the computer or the network is not your own.
Keep this to hand
If you play the desktop games we describe, including World of Tanks, apply the same account habits when you register: a unique password, two-factor sign-in where offered, and the confirmation email kept somewhere safe. The steps are the same whatever the game.