Hello everyone. 👋 Today, I want to highlight an important topic for the gaming industry and take a closer look at Steam’s history of data security incidents and leaks. This research has been prepared based on publicly available information and sources found online. While every effort has been made to verify the information and present it as accurately as possible, some details may change as new information emerges, and we cannot guarantee that all reported information is complete or definitive.
A New Leak Brings Old Security Issues Back

Reports that around 12 to 13 TB of old Steam game data has become accessible online have brought Valve’s previous security incidents back into the spotlight. According to Game Developer, users accessed roughly 13 TB of data through a publicly accessible endpoint associated with Steam’s old infrastructure. The data is reported to consist of content uploaded to Steam between 2003 and 2013. The archive is said to contain early versions, beta builds, prototypes, screenshots, and various development materials from Valve as well as EA, WB Games, and other publishers. Portal 2, Left 4 Dead 2, and previously unreleased Half-Life 2: Episode 3 content are also reported to be among the materials that surfaced. Based on the information publicly available so far, the incident appears to involve access to old game development and distribution data rather than a compromise of current Steam accounts.
Steam’s Previous Security Incidents

It is worth remembering that this is not the first time Steam has faced a security-related incident. In 2003, an attack on Valve’s internal network resulted in the source code of the then-unreleased Half-Life 2 being stolen and leaked online. In 2011, following an attack on the Steam forums, Valve confirmed that attackers had gained access to one of Steam’s databases. The database contained usernames, hashed and salted passwords, email and billing addresses, purchase information, and encrypted credit card information. However, Valve stated that there was no evidence that the attackers had obtained the encrypted credit card information or personal data. Therefore, rather than claiming that millions of users’ data was definitively stolen, it is more accurate to say that unauthorized access to a Steam database was confirmed.
The 2015 Christmas Incident

The incident during the 2015 Christmas period, on the other hand, was not a direct hacker attack but a technical caching error. According to Valve’s statement, information from the Steam Store pages of around 34,000 users was briefly displayed to other users. This information could include billing addresses, some digits of phone numbers, purchase history, the last two digits of credit card numbers, and email addresses. Valve stated that full credit card numbers and passwords were not exposed and that the incident did not allow users to access other accounts. The issue was resolved within a few hours, and the company issued an official statement. The incident demonstrated that, on large digital platforms, security and privacy risks can arise not only from external attacks but also from technical configuration errors.
The 2025 Data Leak Claims and 2026 Cyberattack

In 2025, claims emerged that the data of approximately 89 million Steam users had been leaked. Following its investigation, Valve stated that Steam’s systems had not been breached. The company said the data that surfaced was linked to old SMS messages and two-factor authentication codes that were no longer valid, and that the information did not provide access to Steam accounts, passwords, or payment information. In 2026, CEVA Logistics, a logistics partner involved in Steam hardware distribution in Europe, became the target of a cyberattack. In notifications sent to customers, Valve stated that some personal and delivery information may have been affected, while passwords, payment information, and Steam Guard codes were not affected. Although this incident does not mean that Steam’s own infrastructure was breached, it highlights the security risks that large digital platforms can face through third-party service providers.
Why Does This Matter for the Gaming Industry?

So why does all of this matter? Steam is by far the dominant platform in PC digital game distribution, with various industry estimates putting its share at around 75 percent. When data from a platform of this scale becomes accessible, the implications extend beyond Valve to the companies that develop and publish games on Steam. Unreleased prototypes, source files, and development materials can involve copyright, intellectual property, trade secrets, and contractual rights. Unauthorized copying, distribution, or use of such material may therefore create significant legal risks for those involved. At the same time, from a game preservation perspective, the data represents a potentially valuable digital archive that could provide insight into parts of gaming history that were previously thought to be lost.
Digital Preservation vs. Intellectual Property

More broadly, this incident shows that old data can retain significant value in the digital gaming industry. A prototype created years ago or an unused development file can have both historical and commercial significance today. However, the fact that content is technically accessible does not mean that it is free to use or redistribute. For material belonging to third-party developers and publishers in particular, copyright and intellectual property rights must be considered separately. The archive therefore highlights a delicate balance between preserving digital game history and protecting the intellectual property rights of its creators.
Don’t forget to follow us for more developments, data, and research from the gaming industry. 🔔







