Security Guide
January 20, 202413 min read

The Complete Guide to OSRS Account Security in 2024

Everything you need to keep your Old School RuneScape account safe: authenticator setup, password hygiene, safe clients, and how to spot account-stealing malware like Storm Client.

Your OSRS account can represent years of progress and real value. This guide covers everything you need to keep it safe — and how to recognize account-stealing software like Storm Client before it costs you.

1. Enable the Jagex Authenticator

Two-factor authentication is the single most effective protection you can enable. Even if your password is stolen, an attacker cannot log in without your authenticator code. Set it up from the official Jagex account settings today.

2. Use a strong, unique password

  • Never reuse your RuneScape password on any other site.
  • Use a password manager to generate and store a long random password.
  • Change it immediately if you have ever used a third-party client.

3. Only use safe clients

Use official RuneLite, the Jagex client, or HDOS. Avoid closed-source "premium" clients. Storm Client's Allure plugins were found to contain credential-stealing malware — the exact threat this section exists to prevent.

4. Secure your email and Discord

Attackers often pivot from a stolen game account to your email or Discord. Enable 2FA everywhere, and be suspicious of any plugin or client that requests Discord access.

5. Know the warning signs

  • Missing items or gold you did not trade away.
  • Logins from unfamiliar countries in your account history.
  • Changed email or settings you did not make.

6. If you think you're compromised

  1. Change your password from the Jagex website immediately.
  2. Enable the authenticator and end all active sessions.
  3. Contact Jagex support to report the compromise.
  4. Run a full malware scan and remove any third-party clients.

Protect Your Account

If you've used Storm Client or Allure plugins, your account may be compromised. Take action now.