Valve has debunked the alleged 89 million Steam account details leaked
The so called leaked has been clarified to be A leak of old text messages sent to Steam customers with one-time codes for logins and has been confirmed to “not a breach of Steam systems,”
Source:
Initial News
Summary
Leak Details:
89 million Steam account appeared for sale on the dark web
Source : Believed to be a "supply chain compromise" rather than a direct hack of Steam or Twilio (the company apparently handling Steam’s 2FA that Valve denies to be using)
Accounts with no 2FA are vulnerable to being victim to unauthorised access. If you have 2FA apparently you are considered safe. It is Highly recommend that all Steam users change their passwords immediately if you do not have 2FA (probably best to be safe and change anyway if you do have 2fa)
Be on the lookout for phising attacks using data contained.
Valve hasnt confirmed the source of the leak and advised caution while investigation is inprogress
If you havnt already enable Steam Guard (2FA) and change your password now
Update: Other sources with screenshots apparently from the same OP has posted SMS logs that make this seem less severe.
Twilio also confirmed they haven't suffered a breach. they are also not Valve's provider of 2fa. Its also likely just phone numbers leaked but this is still unconfirmed
The so called leaked has been clarified to be A leak of old text messages sent to Steam customers with one-time codes for logins and has been confirmed to “not a breach of Steam systems,”
Source:
Code:
https://www.anonymz.com/?https://steamcommunity.com/games/593110/announcements/detail/533224478739530146
Initial News
Code:
Source: https://www.xda-developers.com/89-million-steam-account-details-leak/
Leak Details:
89 million Steam account appeared for sale on the dark web
Source : Believed to be a "supply chain compromise" rather than a direct hack of Steam or Twilio (the company apparently handling Steam’s 2FA that Valve denies to be using)
Accounts with no 2FA are vulnerable to being victim to unauthorised access. If you have 2FA apparently you are considered safe. It is Highly recommend that all Steam users change their passwords immediately if you do not have 2FA (probably best to be safe and change anyway if you do have 2fa)
Be on the lookout for phising attacks using data contained.
Valve hasnt confirmed the source of the leak and advised caution while investigation is inprogress
If you havnt already enable Steam Guard (2FA) and change your password now
Update: Other sources with screenshots apparently from the same OP has posted SMS logs that make this seem less severe.
Twilio also confirmed they haven't suffered a breach. they are also not Valve's provider of 2fa. Its also likely just phone numbers leaked but this is still unconfirmed
Last edited: