← Valve

2026 Valve — ~12TB legacy Steam2 depot/game-asset dump circulating online (unverified; not customer PII)

2026 Unknown records affected Share on X

Data compromised

Unverified game-development assets and depot files (e.g. Portal 2, Left 4 Dead, CS:GO, F-Stop material per researchers) — not attested customer account, payment, or password data; separate Valve notice addressed old SMS one-time codes, not this archive

Technical writeup

Unverified legacy-data circulation — August 29, 2026. Researchers and gaming press reported a ~12TB archive reshared on social media, described as tied to Valve’s pre-SteamPipe “Steam2” content-delivery infrastructure (GCF-era depots). Community analysts highlighted alleged Portal 2 development builds (including a claimed 2009 beta), F-Stop assets, Left 4 Dead and Counter-Strike: Global Offensive material spanning roughly 2003–2013; Half-Life 2: Episode 3 connections remain speculative. Spilled.gg and Game Rant stressed provenance is unclear — it is unknown who obtained the files, when they were copied, or whether they came from live Valve infrastructure, mirrors, or private collections. Social posts variously claimed a publicly exposed endpoint; no major security outlet corroborated that mechanism at indexing time. This is distinct from Valve’s company-confirmed Aug 10 CEVA Logistics EU hardware-shipping breach (valve-ceva2026). On Aug 30 Valve posted that recent leak samples it reviewed did not breach Steam systems and did not tie phone numbers to accounts (addressing circulated SMS one-time-code messages); Valve had not confirmed the 12TB game-asset archive. recordsAffected 0 — no verified consumer census; companyConfirmed false for the depot dump.

Root cause

Unverified community archive (~12TB) said to originate from Valve legacy Steam2 content-server depots (2003–2013-era game builds/assets); provenance and access path unconfirmed — Valve says recent leak reports did not breach Steam systems

References