Videos
Edit: Ok, so probably its a real email from the real Steam support, but (I didn't know its possible, but looks like it is) it's from another account with the same email and similar username as my main account. I'm not entirely sure its mine, and if it is I'm certain I didn't logged in in years, so I have no idea how I can recover it.
Anyway, thanks for the help, and thanks for u/uniQArtworks [+1] to pointing thing out.
Original:
So this is weird. When I just woke up and saw that I have 3 email from "[email protected]". The first say someone added a phone number to my account (I already have phone number on my account), then 5 mins later that someone changed the password and email address.
So the first thing I check is the email adress. Sometimes I get fake steam emails from other email addresses, but not this time, it's the legit email address.
At this point, I start to panic a little because this email belongs to my main account with almost 700 games. But the same time I'm confused because I have mobile authenticator on that account and also sms authenticator on my Gmail, so no way someone even if found out my PW could log in everywhere and change stuff. So at this point I'm super cofused and just try to log in. And I can. And nothing changed, not the phone number, the name, the pw or the email.
At this point I go back and check 5 more times the mail that if its fake or not but its still the real seteam support eamil adress. So now I'm totally lost.
The weired thing is that the email greets me with "Sotyka". And I changed that name to "Sotyka94" years ago. The last time I got email from the official Steam adress with "Sotyka" in the title was in 2016.
TLDR: The real Steam support email just sent out emails that my account has been stolen, when it's not.
Note that it is trivial for someone to send an email that looks like it is 'from' someone. I can send you an email that looks like its from gabe, bill gates, steve jobs etc. Unless you look into the real nitty gritty details of the headers you can't use the 'from' field to authenticate
I just had a quick look at it turns out that both accounts exists (Sotyka and Sotyka94).
Only the latter has 2FA, the first one uses a gmail address.
All account security related emails will contain your account name (image from the wiki page), which is not your public username. You can also not change this account name. This means you probably created a new account at some point and forgot about the old one.
Also note that neither the sender's name nor the address within an email is reliable evidence that it came from this person. It can easily be faked and is essentially like writing White House and 1600 Pennsylvania Avenue as sender on a letter.