Step 3 of 7
Setting up a game account you will not regret
Registration is the moment a free game stops being anonymous. The address you use, the password you choose and whether you switch on a second factor decide how much trouble a future breach or a phishing message can cause — and all three take about as long to get right as to get wrong.
Short answer
Use an email address kept for gaming and other low-stakes sign-ups, not your work or primary personal address. Generate a unique password and store it in a password manager. Switch on multi-factor authentication if the publisher offers it. Confirm the address when the activation message arrives, then check the account's privacy and marketing settings once, before you start playing.
The email address decision
A game account's email address does three jobs: it proves the account is yours, it receives password resets, and it becomes a marketing channel. It may also, eventually, appear in a data breach notification, because game publishers hold large user databases and those databases are a target.
Separating gaming sign-ups into their own address keeps that blast radius small. If the address is exposed, the fallout is spam and phishing aimed at an address that holds nothing important, rather than at the mailbox your bank, your employer and your government services use. It also makes phishing easier to spot: a message about a gaming account arriving at your work address is wrong on its face.
The address still needs to be one you actually read and can keep. A throwaway or disposable mailbox defeats the purpose, because losing access to it means losing the recovery route for every account attached to it.
Passwords, done once
The only password advice that survives contact with reality is to make each one unique and to let software remember it. Reuse is what turns one publisher's breach into a problem with your email, your storefront account and anything else sharing that password, because credential-stuffing attacks simply try the leaked pair everywhere.
A password manager — the one built into your browser is far better than nothing, and dedicated managers offer more — removes the need to invent or recall anything. Where you do need a memorable password, a long passphrase of several unrelated words beats a short one with substitutions, and length does more work than complexity. The Australian Cyber Security Centre publishes the federal guidance on passphrases and account security, and it is a better reference than the folklore that circulates in game communities.
Multi-factor authentication
If the publisher offers a second factor, switch it on during setup rather than later. An authenticator app is stronger than SMS, because SMS can be intercepted through number porting, but SMS is still a large improvement over a password alone. Save any recovery codes the service gives you into the password manager at the same time — they are useless at the moment you need them if they are sitting in a screenshot on a phone you no longer have.
What the activation email is, and what it is not
After registration, publishers typically send a message containing a confirmation link. Following it proves the address exists and belongs to whoever registered, and it usually completes the account so it can sign in. That is the whole of its function.
What it is not is a place to enter your password, your payment details or anything else. A legitimate confirmation link takes you to the publisher's own domain and asks for nothing. Any message that asks you to "verify" by entering credentials on a page you reached from an email is the pattern that phishing relies on, and it is worth building the habit of navigating to the site yourself rather than following a link, even when the message is genuine.
What to watch out for
- Messages claiming your account will be deleted or suspended unless you act immediately. Urgency is the oldest lever in this category.
- Pages offering free premium currency, items or accounts in exchange for a login. Publishers do not distribute currency through third-party sites.
- Giveaways that ask you to sign in with your game account to "check eligibility", including ones promoted inside a game's chat.
- Buying, selling or sharing accounts. Most publishers prohibit it in their terms, the buyer has no recourse, and the original owner usually retains the recovery email.
- Software that promises unlocks, boosts or cheats. It is a straightforward route to both a ban and malware.
Current scam patterns are catalogued by Scamwatch, operated by the National Anti-Scam Centre, which is also where a scam can be reported.
The settings pass, before you play
- Marketing preferences: decide once whether you want the publisher's mail, rather than unsubscribing message by message for a year.
- Profile visibility: whether your name, statistics, friends list or activity are public, and whether that is what you want.
- Chat and invitations: whether strangers can message you, and whether voice chat is on by default.
- Linked accounts: whether the game is connected to a social account, and what that connection shares in each direction.
- Payment: avoid storing a card if the platform allows a per-purchase confirmation instead.
- Recovery details: confirm the email on file is the one you intended, and that you can still sign into it.
Personal information and Australian privacy law
A game account holds more than a username. It typically includes the email address, an approximate age, purchase history, in-game behaviour, IP addresses and device identifiers. How an organisation may handle that information, when it operates in Australia or handles the personal information of people in Australia, is governed by the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
The Office of the Australian Information Commissioner publishes the Australian Privacy Principles and handles privacy complaints. The practical route is the same as for most disputes: ask the organisation first, in writing, and take the matter to the regulator if the response is inadequate. It is also worth knowing that many game publishers are based overseas, which affects both where your information is stored and how straightforward a complaint is — a reason to read the privacy policy of the specific publisher rather than assume.
If an account is compromised
- Change the password on the email account first. Everything else can be reset from there, so it is the account that matters most.
- Change the game account password and sign out of all sessions if the publisher offers that control.
- Switch on multi-factor authentication if it was not already on.
- Check for changes an attacker may have made: the recovery email, linked accounts, and any stored payment method.
- Contact the publisher's support through its own site. This site cannot help with account recovery and neither can any third party claiming to.
- If money was lost or the incident is serious, report it through the Australian Cyber Security Centre, and contact your bank immediately where a payment method was involved.
Accounts for younger players
Where the account is for someone under 18, the settings above matter more, and the platform-level controls matter more than the game's own. The eSafety Commissioner is Australia's online safety regulator and publishes material for parents and carers on gaming, chat and parental controls, along with a route for reporting serious online abuse. Step six covers the classification side, which is the other half of that question.