Valve confirmed that the breach was contained within its third-party shipping partner’s systems. While internal Steam account credentials, passwords, and payment information remain secure, the exposed delivery data provides attackers with enough specific context to craft convincing fraudulent messages. These bad actors may cite genuine shipping addresses to solicit customs fees or pressure users into clicking malicious verification links.
Valve issued a strict warning for users to disregard any unsolicited communication claiming to be from the company or its shipping affiliates. The developer maintains that it handles all account-related support exclusively through its official portal, help.steampowered.com, and will never reach out via Discord, Steam chat, or direct email requests for payment or login credentials.

Comments (0)
No comments yet. Be the first!