Valve
Disclosed Nov 11, 201114 years agoConfirmed
Hackers access Steam user database holding encrypted card data
Valve found that attackers who breached the Steam forums used that access to reach a database with user and encrypted credit card information for the service, which had about 35 million users; Valve said it had no evidence of card misuse.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Nov 11, 2011 |
| Attack | Hacking |
| Data exposed | Names, Payment cards, Credentials and tokens |
| Sector | Gaming · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| California Attorney General breach notice: Valveoag.ca.gov · Official notice | Official notice |
| Valve's online game service Steam hit by hackersbbc.co.uk · News | News |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Nov 11, 2011 | |
| California AGresidents of CA | Feb 8, 2012 |
Other breaches at Valve
| Breach | Affected | ||||
|---|---|---|---|---|---|
| Valve warns European Steam hardware buyers of data theft at CEVAAug 106 weeks agoVendor breachUnverified | Aug 106 weeks ago | Vendor breach | Gaming | Unverified | Unknown |
History of this record
- 2026-09-25 · sector: other to gaming · seed source
- 2026-09-25 · attack: unknown to hacking · seed source
- 2026-09-25 · data_types: [] to ["names","payment-card","credentials"] · seed source
- 2026-09-25 · disclosed: 2012-02-08 to 2011-11-11 · seed source
- 2026-09-25 · summary: empty to Valve found that attackers who breached the Steam forums used that access to reach a database with user and encrypted credit card information for the service, which had about 35 million users; Valve said it had no evidence of card misuse. · seed source
- 2026-09-25 · title: empty to Hackers access Steam user database holding encrypted card data · seed source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.