Phishing is the starting point of almost every skin theft. The scammer does not break into Steam. They get you to hand over the keys. The usual bait is a link: a free case, a giveaway, a "your item was reported" warning, a fake marketplace, a request to vote for a team, or a trade check page. The link leads to a page that looks like Steam and asks you to log in.
Once you enter your password and Steam Guard code, the scammer can log in as you. From there they may trade your items out, list them on the Market, or plant a Web API key so they can hijack your future trades. Because your own phone approved the login, Steam sees nothing wrong.
How do I recognize a Steam phishing link?
Look at the address bar, not the page. Real Steam logins happen only on steamcommunity.com, store.steampowered.com and help.steampowered.com. Lookalike domains swap letters, add words or use a different ending, such as steamcommunlty or steamcomunity-trade. A pop-up login window that you cannot drag outside the browser tab is drawn by the page itself, not by Steam.
Other red flags: urgency ("your account will be banned in 24 hours"), rewards for doing nothing, and any request to "verify" by logging in through a link. Steam Support never contacts you by Discord or Steam chat and never asks for your code.
What should I do after a phishing attempt?
If you only clicked and did not log in, you are fine. If you entered your details, act now: change your password, deauthorize all devices, check steamcommunity.com/dev/apikey and revoke any key, and look at your trade history. CS2 trade protection lets you reverse the last 7 days of trades if items already left.
Before clicking anything sent to you, paste it into the scam link checker. Bookmark the real Steam pages and use those bookmarks to log in, so a link never gets the chance to fool you.