
What exactly is 'Account Phishing'? It's a pretty simple concept to understand if explained correctly. Account Phishing is when someone creates a 'fake' webpage and/or application that is design to steal your account information. Majority of account Phishing is done via websites that resemble the real one. Such as the website used in the recent SSFN Phishing attempts:

Upon logging into this phishing site, you will be prompted to sign in to your steam account. This is the first mistake; they now have your username and password. But wait! Steam Gaurd will protect my account!1!1 That's correct...until you get directed to the next page, which has a spiffy notifcation that tells you to run the 'steamgaurd.exe' that they just tried to download on your computer. Upon running this malicious program, the SSFN file from your Steam installation directory is uploaded to a remote site, in which the creators of the application can access.

Lord Gaben, protect us from the fishes!11! If you'd like to know more about how these Phishing scams for Steam were first found out, head over to http://blog.malwarebytes.org/
Source | Source