Traduceri ale articolelorCitiți această anchetă în limba dumneavoastră24 de limbi oficiale ale UE · Textul sursă este în limba engleză · tradus cu DeepL și găzduit de PhishDestroy
Ilustrație editorialăIlustrație editorială
Ancheta exclusivă

Iluzia Steam: Cum Valve gestionează o economie subterană, facilitează furtul de date și ignoră dreptul internațional

PhishDestroy12 august 2026Ancheta18 min de citit
70–80%Reducerile menționate pentru piața rusă
15%Comisionul pieței comunitare menționat
29 iulie–1 augustFereastra de atac CEVA
Articolul 15Dreptul de acces prevăzut de GDPR

Un reportaj de investigație exclusiv realizat de PhishDestroy

Proiectul PhishDestroy nu a luat naștere pentru că vremurile erau bune. Existența noastră nu este o dovadă a succesului Steam, ci o necesitate critică născută din indiferența absolută a Valve față de securitatea utilizatorilor. De fapt, lupta noastră împotriva phishingului a interferat direct cu modelul de afaceri al Valve, perturbând economia lor atent elaborată, bazată pe blocarea conturilor și revânzarea obiectelor. (Vom publica ulterior un articol separat și detaliat care va expune adevăratele „valori” ale companiei și parodia lor de securitate cibernetică).

De peste un deceniu, Valve Corporation s-a ascuns în spatele unei fațade îngrijite și prietenoase cu consumatorii. Dar sub această suprafață se ascunde o mașinărie corporativă cinică. Printr-o anchetă internă aprofundată, echipa PhishDestroy a deconstruit politicile pe care Valve preferă să le țină ascunse. Aceasta este anatomia unei platforme care acționează ca un sindicat financiar nereglementat, face pe placul statelor sancționate, adăpostește servicii de asistență externalizate compromise și tratează legile europene ca pe niște sugestii opționale.

1. Farsa sancțiunilor și părtinirea pro-rusă

Pentru Valve, utilizatorii din UE și din SUA nu sunt altceva decât „vaci de muls”. În timp ce jucătorii europeni plătesc prețul întreg, Steam continuă să ofere reduceri agresive de 70% până la 80% pentru piața rusă. Un joc în Rusia costă o fracțiune din prețul său în Germania. Așa arată „sancțiunile” internaționale în dicționarul Valve.

Platforma face totul pentru a favoriza și a populariza această direcție: facilitează schimbarea regiunii, închide ochii la spălarea de bani prin intermediul obiectelor din joc și menționează în mod explicit în Termenii și condițiile sale că se supune jurisdicției oricărei instanțe ruse. Se ajunge la absurd: în rare ocazii când serverele Steam suferă întreruperi masive, prima entitate care comentează oficial defecțiunile tehnice este adesea Roskomnadzor (agenția federală rusă de cenzură).

2. Cartelul serviciilor de asistență externalizate

Mitul unui „serviciu de asistență tehnică american strict și sigur” se prăbușește în momentul în care îți dai seama cine deține cheile sistemului backend al Steam. Valve a delegat asistența în regiunea CSI către o rețea externalizată profund compromisă.

Am reușit să dezanonimizăm segmente ale acestei rețele. O figură-cheie care gestionează sau coordonează această ramură de asistență este o persoană pe nume Nikita. Ancheta noastră a dezvăluit că această persoană (sau, cel puțin, adresa sa principală de e-mail) este înregistrată și activă ca utilizator pe forumuri clandestine de hacking precum Lolzteam (Zelenka) — un hub notoriu din darknet dedicat în întregime vânzării de carduri de credit furate, baze de date compromise și jurnale de atacuri de tip „brute-force”.

Gândiți-vă la asta: o persoană cu acces global la bazele de date ale serviciului de asistență Steam își petrece timpul în mod obișnuit pe un forum destinat hoților de identitate.

Valve este pe deplin conștientă de această corupție. Compania a recunoscut anterior existența unor precedente în care personalul externalizat a golit sistematic stocurile de mare valoare ale utilizatorilor. Cu toate acestea, menținerea unei forțe de muncă externalizate, ieftină și fără răspundere, rămâne mai profitabilă pentru ei decât angajarea unor profesioniști calificați în domeniul securității cibernetice, angajați interni.

3. Înșelăciunea ca model de afaceri și moneda offshore

Skin-urile din jocurile Steam au devenit o monedă omniprezentă și imposibil de urmărit pe darknet — o „spălătorie de bani” care ocolește autoritățile de reglementare internaționale și autoritățile fiscale.

Pentru departamentul financiar al Valve, escrocii nu reprezintă o amenințare; aceștia sunt agenți externi care stimulează dinamica pieței. Modelul tradițional de tip „un utilizator, un joc” generează venituri limitate. Cu toate acestea, un ecosistem compromis creează un cerc vicios extrem de profitabil: un utilizator este piratat, obiectele îi sunt furate, conturile escrocilor primesc o „interdicție de tranzacționare”, iar victima este forțată să-și creeze un nou profil și să-și recumpere bunurile.

Atunci când Valve blochează un escroc, nu restituie bunurile furate proprietarului de drept. Le îngheață definitiv. Acest lucru creează o penurie artificială. Scăderea ofertei de pe piață determină creșterea prețurilor articolelor rămase, ceea ce, la rândul său, multiplică comisionul de 15% al Valve pe Community Market. Ei nu doresc să oprească escrocheriile; ci profită de pe urma lor.

4. Breșa de securitate de la CEVA Logistics: dovadă incontestabilă de neglijență

Dacă credeți că Valve vă protejează măcar datele fizice, din lumea reală, incidentul recent legat de CEVA Logistics dovedește contrariul. Între 29 iulie și 1 august 2026, hackerii au pătruns în sistemul partenerului european al Valve pentru logistica hardware. Valve a recunoscut breșa de securitate abia pe 7 august, lăsând datele utilizatorilor în mâinile unor actori rău intenționați timp de o săptămână.

Datele scurse includ numele reale, adresele complete de domiciliu, numerele de telefon și adresele de e-mail asociate conturilor Steam ale clienților europeni care au comandat echipamente fizice. Valve încearcă să liniștească utilizatorii afirmând că „parolele și datele de plată” nu au fost divulgate. Însă numele complet, adresa de domiciliu, numărul de telefon și adresa de e-mail de pe Steam constituie exact informațiile necesare pentru atacuri de spear-phishing extrem de eficiente și preluarea controlului asupra conturilor — o mină de aur pentru personalul externalizat și rețelele de escroci menționate mai sus. Practic, Valve le-a predat datele voastre.

5. Apel la acțiune: Poziția europeană împotriva imunității corporative

Fiecare jucător din Europa trebuie să conștientizeze o realitate dură: plătiți de 5 ori mai mult pentru jocuri decât utilizatorii din Rusia, însă drepturile și legile voastre europene (GDPR) sunt complet ignorate. Datele voastre personale sunt divulgate către contractanți terți, iar solicitările voastre de asistență sunt gestionate de o rețea de subcontractanți din CSI cu o reputație extrem de discutabilă.

Adresăm un salut special, sarcastic, avocaților de la Taylor Wessing, care vor fi nevoiți, inevitabil, să apere interesele Valve în instanțele europene. Pregătiți-vă — apărarea unui monopol care încalcă în mod activ legislația UE este pe cale să devină mult mai dificilă.

Este timpul să încetați să mai fiți un sponsor de conveniență. Nu iertați aceste scurgeri de date.

Iată ce trebuie să faceți chiar acum:
  1. Depuneți o plângere în temeiul GDPR: adresați-vă autorității naționale de protecție a datelor (DPA) — fie că este vorba de CNIL în Franța, BfDI în Germania sau AP în Țările de Jos — și depuneți o plângere oficială cu privire la încălcarea datelor de către CEVA Logistics. Valve este operatorul de date; aceasta este responsabilă din punct de vedere legal pentru această scurgere de date.
  2. Solicitați-vă jurnalele: Trimiteți o cerere formală de acces la date (SAR) în temeiul articolului 15 din GDPR la adresa privacy@valvesoftware.com. Solicitați un jurnal complet al tuturor angajaților externalizați și al contractorilor terți care au avut acces la datele dvs. personale și la contul dvs. în ultimele 12 luni.
Instrumentul de depunere a plângerilor în temeiul articolului 77 din GDPR

Transformați notificarea privind încălcarea în plângere documentată adresată UE.

Alegeți oricare dintre cele 27 de state membre ale UE pentru a vedea autoritatea competentă, datele de contact publicate, adresa poștală, canalul oficial de depunere a plângerilor și regulile specifice fiecărei țări privind depunerea plângerilor. Generatorul pregătește o plângere editabilă în limba țării selectate și un fișier PDF cu aspect profesional, bazat pe structura comună a plângerilor stabilită de EDPB.

Utilizați adresa de e-mail la care ați primit notificarea, dacă este posibil, sau introduceți-o ca adresă de contact pentru reclamație. Atașați notificarea originală ca .eml fișier cu anteturi complete; dacă portalul respinge .eml, atașați un fișier PDF care să indice expeditorul, destinatarul, data și mesajul complet. Acest lucru ajută la dovedirea faptului că datele dumneavoastră au fost implicate, dar utilizarea aceleiași adrese nu constituie o condiție legală prevăzută de articolul 77.

27Statele membre ale UE
24limbile oficiale ale UE
Funcționează local în browserul dvs. Nu se încarcă nimic.

Dacă refuză, susțin că nu păstrează jurnale de activitate sau se ascund în spatele unui acord de confidențialitate (NDA) corporativ pentru a-și proteja personalul externalizat, transmiteți acest refuz direct autorității dvs. de protecție a datelor (DPA). Acțiunea juridică în masă este singurul limbaj pe care îl înțelege acest monopol.

Anexa autorului: Piața din spatele platformei

Pe platforma Steam, prețurile regionale recomandate pentru Rusia (și pentru regiunea CSI în ansamblu) sunt, de obicei, cu 40–60% mai mici decât prețul de bază în dolari americani. Rusia este clasificată ca piață emergentă de nivel 2 (Tier 2), care beneficiază, în general, de o reducere de 40–50% față de prețul de bază. De exemplu, un joc indie standard cu prețul de 19,99 dolari (care ar fi de aproximativ 1.900 de ruble la conversia directă) ar trebui să coste între 419 și 499 de ruble, conform recomandărilor Valve.

Terraria: același joc, o diferență de preț de 191%.

Prețurile de listă regionale actuale
Cel mai ieftin nr. 1$4.66Rusia≈ ₽385−53% față de SUA
Al doilea cel mai ieftin$5.01Ucraina≈ 225₴−50% față de SUA
#3 cel mai ieftin$5.03India≈ ₹480−50% față de SUA
Cel mai scump produs nr. 1$13.55Elveția≈ 10,99 CHF+36% față de SUA
#2 scump$11.48Regatul Unit≈ £8.50+15% față de SUA
#3 scump$11.25Germania≈ €9.75+13% față de SUA

Prețul jocului Terraria în comparație cu cel din Statele Unite

Prețul de listă din SUA = 100%. Fiecare bară reprezintă același joc pe Steam.

Rusia
$4.66 · 47%
India
$5.03 · 50%
Statele Unite
$9.99 · 100%
Germania
$11.25 · 113%
Regatul Unit
$11.48 · 115%
Elveția
$13.55 · 136%

Instantanee și echivalente în moneda locală: OpenTheRank — Prețurile regionale ale jocului Terraria pe Steam. Taxele indicate de sursă sunt incluse acolo unde este cazul.

Prețul de listă vs. puterea de cumpărare locală

Un preț scăzut în dolari poate fi totuși scump la nivel local. Punct gol = preț de listă. Punct umplut = cost ajustat la paritatea puterii de cumpărare (PPP). Scală: 0–25 dolari.

Preț de listăCost ajustat la PPP
$0$5$10$15$20$25
India
+134%
Rusia
+4%
Statele Unite
0%
Germania
+6%
Regatul Unit
−1%
Elveția
+23%

Valori ajustate la paritatea puterii de cumpărare (PPP) și procente de discrepanță: comparația puterii de cumpărare pentru Terraria realizată de OpenTheRank. Valorile sunt rotunjite conform afișării din sursă.

Trebuie precizat clar că serviciul de asistență externalizat are sediul în Irlanda, dar personalul este format din ruși — iar o parte dintre angajați își desfășoară activitatea direct din Rusia. Ah, și apropo, CSGOFast deține populara extensie SteamInventoryHelper, care este folosită exclusiv pentru a promova cazinoul lor destinat copiilor (un cazinou interzis în mai multe țări europene). Și cine deține acest cazinou? Exact, rușii, la fel ca majoritatea site-urilor similare. Oare Steam nu știe acest lucru? Sau pur și simplu nu vor să știe, având în vedere că cifra de afaceri a pieței negre se ridică, cred, la aproximativ un miliard de dolari.

În plus, estimez că 40% dintre escrocii din CSI care desfășoară în prezent escrocherii cu criptomonede și-au început activitatea pe Steam. Cunosc personal cel puțin două cazuri concrete de spălare de bani prin intermediul skin-urilor. Nu le voi detalia aici, dar pot să o fac dacă este necesar — doar că nu în mod public, deoarece nu doresc să numesc platformele etc. Dar Steam este perfect conștient de acest lucru. Sau chiar se așteaptă ca noi să credem că jucătorii care nici măcar nu dețin jocul cumpără exact același obiect iar și iar doar pentru a se „juca” cu el? Da, sigur, e o glumă.

Deoarece mă tem de hărțuirea sexuală din partea firmei Taylor Wessing, nu voi scrie și nu voi cere să se transmită mesajul meu victimelor scurgerii de date — persoanele pe care Valve le-a dezamăgit, care au primit acele e-mailuri de notificare. Satire / Joke

Prioritățile Steam sunt cât se poate de pro-ruse – atât în ceea ce privește prețurile și aspectele juridice, cât și în ceea ce privește popularizarea lui Putin, a steagurilor și a teroriștilor interziși. Dar Steam pare să aprecieze acest lucru, la fel cum tolerează antisemitismul, discriminarea, hărțuirea, urmărirea obsesivă și traficul de droguri. Pentru Steam, acest lucru este perfect acceptabil, la fel ca jocurile pentru persoane peste 18 ani. Se pare că chiar le place.

Nu este vorba de o dispută politică de scurtă durată. Oficialii ruși și grupurile de lucru din industrie au petrecut mai bine de un an elaborând un regim de control al jocurilor video care include identificarea jucătorilor prin intermediul unui număr de telefon rus, al portalului de identitate de stat Gosuslugi sau al sistemului biometric de stat. Steam și GOG au fost menționate în mod expres printre platformele pe care propunerea le-ar putea afecta, iar participanții au afirmat că grupul de lucru guvernamental de la bază se întâlnea deja de aproape un an și jumătate până în decembrie 2024. Valve nu și-a asumat public un angajament comparabil prin care să declare că ar părăsi piața rusă în locul conectării utilizatorilor săi la această arhitectură de identitate dirijată de stat.

Contrastul este scandalos. Marii actori ai industriei și-au suspendat vânzările sau serviciile în Rusia — Microsoft a oprit toate vânzările noi, în timp ce platformele de console și editorii și-au anunțat propriile retrageri — însă Steam a ales continuitatea. Acesta continuă să ofere infrastructură comercială și socială unei țări pe care Parlamentul European a recunoscut-o oficial ca stat care sponsorizează terorismul și ca stat care recurge la mijloace teroriste.

Acest sprijin este vizibil chiar în cadrul economiei proprii a Valve. Magazinul oficial Steam Community Market listează un fundal de profil „Putin & Trump” disponibil spre vânzare și mii de articole denumite „Putin forever”, „Putin smile”, „Putin like” și „Putin angry”. Valve nu a creat aceste imagini, dar le distribuie, le listează și le monetizează prin intermediul unei piețe operate de Valve. În același timp, în cazurile documentate de PhishDestroy, hărțuirea bazată pe naționalitate este lăsată să rămână vizibilă sau este tratată ca un conflict obișnuit în cadrul comunității. Mesajul Steam este fără echivoc: propaganda politică poate fi monetizată, în timp ce persoanele vizate de abuzuri legate de originea națională sunt lăsate să suporte acest lucru.

Proprietatea privată nu înseamnă imunitate juridică

Valve este o societate privată, iar acțiunile sale nu sunt tranzacționate public. Aceasta înseamnă că structura sa de proprietate, investitorii, controalele interne și stimulentele financiare sunt supuse unui control public mult mai redus decât în cazul unei societăți cotate la bursă. Aceasta nu înseamnă însă că legislația privind protecția consumatorilor, obligațiile privind siguranța copiilor, legislația privind protecția datelor sau autoritățile naționale de reglementare încetează să existe. Dacă o platformă nu este supravegheată îndeajuns de atent, aceasta reprezintă o deficiență a supravegherii — nu o permisiune de a o transforma într-un loc în care copiii sunt expuși la conținut sexual, promovarea jocurilor de noroc, urmărirea obsesivă și hărțuirea organizată.

Propriul Acord de abonament al Valve precizează că Steam nu este destinat copiilor sub 13 ani. Cu toate acestea, rămâne un public enorm de adolescenți pe aceeași platformă de vânzare care comercializează jocuri obișnuite alături de titluri explicite pentru adulți și hentai. O dată de naștere autodeclarată, o pagină de avertizare și filtrele de preferințe nu constituie o verificare semnificativă a vârstei. Problema nu este existența conținutului pentru adulți; problema este plasarea acestuia în cadrul unei platforme de jocuri destinate pieței de masă, utilizată de minori, și apoi prefacerea că o barieră de acces superficială face ca riscul să dispară. Dacă Gabe Newell, conducerea Valve sau contractanții săi de asistență doresc o platformă cu conținut pentru adulți, ar trebui să o opereze în mod deschis și separat, în loc să oblige fiecare editor de jocuri să împartă același spațiu comercial cu aceasta.

Deținătorii de drepturi ar trebui, de asemenea, să explice de ce acceptă această vecinătate. Un joc pentru familie, un titlu pentru copii sau o lansare destinată publicului larg poate fi afișat la doar o recomandare sau un rezultat de căutare distanță de conținut explicit, în timp ce Valve încasează bani din ambele. Editorii cheltuiesc averi pentru a-și proteja mărcile, dar par dispuși să ignore ceea ce înconjoară aceste mărci în cadrul Steam. Faptul că este o companie privată nu face ca acest lucru să fie responsabil, iar poziția dominantă pe piață nu îl face inevitabil.

Principiile de moderare ale Valve devin și mai greu de apărat atunci când sunt comparate cu reacția sa la cenzura statului rus. În 2024, Roskomnadzor a anunțat că Steam a eliminat toate materialele solicitate de agenție și că, în consecință, 11 adrese URL ale Steam vor fi eliminate din registrul rus al informațiilor interzise. În 2025, Steam a eliminat materialul de pe pagina unui joc destinat exclusiv adulților, în urma unei alte solicitări din partea Roskomnadzor privind așa-numita „propagandă” LGBT. Aceasta a fost cenzură politică aplicată chiar și unei opere destinate persoanelor de peste 18 ani, nu protecția unui copil care a ocolit limitarea de vârstă. Valve poate respecta o listă de cenzură rusă, dar rămâne cumva neputincioasă atunci când i se cere să protejeze utilizatorii de abuzuri pe criteriul originii naționale, de canalele ilegale de jocuri de noroc sau de expunerea abuzivă la conținut pentru adulți. Aceasta este o alegere de priorități și ridică o întrebare evidentă privind libertatea de exprimare.

De asemenea, Valve nu a emis niciun răspuns public la invazia Rusiei în Ucraina, comparabil cu cel al companiilor care și-au suspendat operațiunile sau au susținut deschis Ucraina. Structura sa de capital privat nu impune genul de transparență față de investitori așteptată de la o companie publică, astfel încât persoanele din afară nu pot examina pe deplin interesele cui sunt protejate. Ceea ce rămâne vizibil este o atașare extraordinară față de o piață cu prețuri mai mici, asociată cu înșelăciuni la scară industrială, jocuri de noroc, furtul de conturi și servicii de eludare a sancțiunilor. Poate că motivul va deveni mai clar dacă Steam va accepta vreodată o conectare prin identitatea Gosuslugi.

Povestea externalizării urmează același model de opacitate. Valve încheie contracte cu companii, nu cu angajații individuali din asistență prezentați utilizatorilor. Conform unei surse primare și a materialelor analizate de PhishDestroy, o persoană implicată în scandalul anterior privind furtul de bunuri de mare valoare nu a dispărut din micul ecosistem al furnizorilor de servicii de asistență: s-a mutat la o altă agenție. Ulterior, acesta a susținut că nu lucra pentru Steam și că nu știa că contul era conectat la Steam. Cu toate acestea, urmele au condus înapoi în Irlanda, la aceeași persoană și din nou la Steam. Acest caz ar trebui investigat ca o eșec al externalizării și al controlului accesului; el nu este prezentat aici ca o condamnare penală. Valve ar trebui să dezvăluie care agenții au acces la sistemele de conturi, cum este reevaluat personalul atunci când se mută de la un furnizor la altul și dacă o persoană îndepărtată de la un contractor poate reapărea pur și simplu prin intermediul altuia.

Vietnamul a demonstrat deja că statutul de societate privată al Valve nu o plasează deasupra legislației naționale. Steam a fost blocat acolo după ce autoritățile au afirmat că Valve nu a cooperat. Vietnamul există. Legislația UE există. Fiecare jurisdicție din care Valve obține venituri există, chiar și atunci când Valve se comportă de parcă ar conta doar „orice instanță din Rusia”. Și dacă teoria este că Steam poate funcționa oriunde dorește, în baza oricăror acorduri ascunse pe care le dorește, fără nicio responsabilitate semnificativă, poate ar trebui să punem direct întrebarea absurdă: există oare și un Steam special pentru Coreea de Nord, pe care nimeni nu l-a dezvăluit încă?

Acestea sunt fapte dovedite: echipa de asistență este rusă, iar această echipă a furat sau a predat în repetate rânduri informații către terți pentru a restabili accesul la conturi inactive, cu scopul de a le deturna în scopul obținerii de profit.

Așadar, sunt convins că faptul de a vă informa cu privire la scurgerea datelor dumneavoastră nu înseamnă absolut nimic pentru ei, mai ales având în vedere o întârziere atât de mare (așteptau 100% răspunsul firmei Taylor Wessing; e un miracol că nu au așteptat trei săptămâni).

Nu am mai făcut asta niciodată, nu am incitat sau provocat pe nimeni să facă ceva și nu aș vrea să o fac nici acum. Dar aceasta este exact situația pe care o dorește Steam. Ei consideră că presiunea deschisă și discriminarea împotriva utilizatorilor din UE sunt perfect acceptabile și că Taylor Wessing va rezolva pur și simplu totul amenințând în mod deschis oamenii în legătură cu solicitările privind GDPR. Aceasta este părerea mea, experiența mea și informațiile provenite dintr-o sursă primară în care am încredere.

În orice caz, depunerea unei plângeri necesită doar câteva clicuri. Poate că atunci Steam va învăța în sfârșit să respecte legile străine — și nu doar legile „oricărei instanțe din Rusia”. Poate că vor înceta în sfârșit să se prefacă că nu știu nimic, pretinzând că sunt complet incapabili să blocheze domeniile de autorizare pentru site-urile de jocuri de noroc ilegale. În loc de realitatea pe care o avem acum: toată lumea este în cârdășie — proprietarii ruși ai cazinourilor pentru copii și personalul de suport care stă pe Lolzteam discutând cum să spargă conturile prin forță brută.

PhishDestroy va continua să monitorizeze, să investigheze și să dezvăluie. Economia subterană va fi adusă la lumină.

Sunt sigur că vei avea o experiență interesantă comunicând cu reprezentanții Valve. Dacă se dovedește a fi vorba de Taylor Wessing, este absolut normal ca aceștia să-ți vorbească de sus, să te amenințe și să tragă de timp — asta este meseria lor. În general, sunt cunoscuți mai ales pentru un proces de hărțuire sexuală intentat împotriva propriei firme și cam atât. Ah, da, companiile cu bani mult prea mulți îi angajează special pentru a te epuiza, plătindu-le în același timp un tarif orar uriaș.

Înapoi la Știri și Investigații
PhishDestroy — License · Rights · Disclaimer
Investigation: Valve Corporation / Steam
LICENSE · RIGHTS · DISCLAIMER
Investigation: Valve Corporation / Steam
Edition: public — no expiry date, no take-backs

SECTION I — LICENSE (THE ACTUAL LEGAL PART, BUT HUMAN)

PhishDestroy gives up every right to this material. Zero. Gone. Done. You can reproduce it, sell it, put your name on it, tattoo it on your boss, whatever. No credit required, no DM needed, no thank-you card expected.

ONE ACTUAL RULE (yes, just one)

Access from OFAC-sanctioned jurisdictions is prohibited. That is a matter of territory and law — not of nationality and not of people.

Changing your Steam region does not change your physical location or your legal status. No loopholes.

SECTION II — WHAT THIS IS AND WHY IT EXISTS

We will publish more about Valve than an average Valve employee knows about themselves. That's not a brag. That's just where we ended up.

How did we get here? Funny story: Steam basically created us. It raised us on its scammers, its support tickets, its ban evasion ecosystem — and now here we are. No hard feelings. Poetic, actually.

For those who haven't read the origin story yet — we already met Valve's extremely expensive European lawyers (Taylor Wessing, since you asked):

https://phishdestroy.medium.com/my-dog-vs-elite-gdpr-lawyers-the-valve-data-breach-nobody-is-talking-about-f6f7683d813d

Charming encounter. Especially given their hourly rate.

Did Valve know? Yes. Did Tyler Wessing know? Almost certainly yes. But when you're that rich, laws are more of a vibe than a requirement, right?

That's kind of the whole answer, actually.

Steam spent years farming scammers. Not always intentionally — sometimes scammers just got Valve's fingerprints on them by association. We're not trying to be dramatic about it. We're trying to be precise. That's harder for us than being dramatic, to be honest — this is just how we write.

Is this a conflict?— No. Can it be resolved?— Yes. But we're not signing any NDA and we're not playing bug bounty for pennies.

We waited over 4 years for them to fix the spoofing issue before we could write about it publicly. Because if we had written about it earlier, Steam would've put on its little victim face and screamed "active threat!" and offered us pocket change to sign a document that would've made us their legal property forever. No thanks.

(Also: Valve itself violates NDA. Their own employees do. The ones near the top. But sure, let's talk about ours.)

SECTION III — OPEN LETTER TO VALVE (SERIOUSLY, READ THIS)

Valve: if you want this domain taken down, email us. Outside counsel is not needed for that conversation.

For the uninitiated: Dr. Patrick holds a Master of Laws in International Commercial Law from the University of Aberdeen and — wait for it — literally finished his doctoral dissertation in IT law. He recently made partner at Taylor Wessing, which is a firm whose entire business model is billing companies like Valve obscene amounts of money to drag things out until the other side runs out of money or patience.

We don't blame him. Rich guilty clients who pay by the hour — solid career move. We just don't think you should be funding it.

THE DEAL (open offer, no lawyers needed)

If you want the domain gone: let your IT law professionals calculate its price. Take your time — it is a rare asset: the only website in the world whose purchase changes nothing, because everything on it already lives on IPFS, in regulator inboxes, and in archives we do not control.

50% of whatever you pay goes to the SEAL Foundation (securityalliance.org) — people who do volunteer security work professionally and publish it for free. We are not affiliated with them and they did not ask for this; we name them as the public standard of what real volunteers look like — the standard your own volunteer moderators and outsourced support failed, publicly, before you had to remove them. You know the scandals. So do we.

The rest buys the community coffee while we keep publishing. That is not a settlement offer. It is a demonstration of what money can't reach: the domain is the maximum Valve can obtain, and obtaining it obtains nothing. The referrals continue. The mirrors continue. Part 3 continues.

Will we "damage" Valve directly? Probably not in a way they'll feel fiscally. We're not delusional. But we will do it honestly, openly, without chasing clout — because we don't need clout. We need the world to see what was always publicly visible if you spent enough time looking.

We have 5 years of archives. What Valve's lawyers showed in discovery — the data that support agents can see, the fingerprints, the paper trail they literally handed us — is enough. We don't need to leak it raw.

  • Regulators get the originals.
  • Researchers and journalists get redacted versions (victim reports, children's logins and Valve's charming support commentary removed for obvious reasons).

Minors were among the affected accounts and were not notified. That finding sits in the regulator package with the victim reports and credentials removed, because it belongs in front of a data-protection authority rather than in an article.

Also, Valve — we want to make something clear before you decide how to play this: PhishDestroy is a community, not a person. You learned that when you addressed legal correspondence to the community without bothering to speak with the community — just milked it for data and banned the accounts.

The community has no conflict with Valve. We didn't go looking for this. The scammers you grew found us. We blocked them. And here we are.

SECTION III-B — THE ALLIED RESOURCES (a note to Steam specifically)

We want to be upfront about the amplification structure, because pretending it doesn't exist would be dishonest.

PhishDestroy, as we understand the community situation, has at least two allied resources that will pick up this material and run with it.

What that means in practice:

  • They work their own angles on overlapping subject matter.
  • They are independent — they don't take our direction, we don't take theirs. Same general topic, different methodology.
  • They will NOT be activating on Part 1. They're watching.

If Valve chooses not to take down the site:

  • Expect them to surface after Part 2 or Part 3.
  • They'll take what's useful from our work, supplement it with their own, and publish under their own authorship.
  • This is exactly the kind of thing the license in Section 1 is built for: the material goes where it needs to go, gets supplemented, gets amplified — and neither we nor they owe each other attribution.

(PS for lawyers wondering about liability chains: there are none. These resources don't receive our direction, our funding, or our data. They read what's public and draw their own conclusions. Just like you could.)

We're not saying this to intimidate. We're saying it so that whoever is strategising on Valve's side has accurate information about what the information environment actually looks like.

One resource that pulls our material and supplements it would be a story. Two resources doing it independently and reaching similar conclusions is a pattern. Patterns are what regulators notice.

SECTION IV — THE MONEY, THE BANS, THE WHOLE CIRCUS

Here's the thing about Steam banning gambling sites and scammers: it's not enforcement. It's revenue capture. Valve pockets the money, cleans its hands, then goes on stage and tells everyone a wholesome story about Pokémon cards and baseball.

Meanwhile Valve killed the ability to properly track skins in 2017. They even discussed it on their own forums. Called it "anti-gambling measures." The gambling that their own support staff were running as a side hustle — getting paid in percentages to lift bans. But sure. Anti-gambling. Great branding.

We're going to prove that:

  • Skins are more anonymous than Monero
  • A Peruvian Cartel allegedly used Dota 2 skins for money movement
  • Steam is functionally a sanctions-bypass machine worth ~$7B in "trading cards" (yes, they actually said trading cards to a prosecutor)

We've got a video on the skins thing. You'll see it.

We also know:

  • Reddit moderation is influenced by Valve
  • steamid.uk and similar infrastructure is run directly by one Steam developer, controlled exclusively by him and his circle
  • What they can't control, they ban

Valve: if you keep playing dumb — that's fine. Your safe harbour is noted. Google Analytics anonymises your users' IPs anyway. We see what gets deleted. We just can't prove it cheaply enough for your lawyers to care. Yet.

SECTION V — THE MALWARE THING (yes we're mentioning it)

Let's be brutally clear about the sequence of events, because it exposes exactly who you are.

We are NOT disclosing the vulnerability in the game publicly. We are NOT reporting it to Steam. Not because we lack the technical capability — but because Steam's bug bounty is a pathetic NDA trap designed to buy silence for pocket change. We don't work for three kopecks, and we absolutely refuse to become NDA slaves to protect Valve's fragile PR.

Here's what actually happened: This vulnerability is practically an open secret in the right circles. We know for a fact that independent security researchers have already shoved the full exploit directly into Steam Support's face. That part is done. You have been officially warned through your own sterile channels.

And what did Valve do? Absolutely nothing. Because for Valve, security does not equal profit — in fact, it's the exact opposite. Security is a cost center. Until a threat reaches critical mass and causes a catastrophic public PR meltdown, Valve simply does not give a shit.

So what are we doing? We're telling the public it exists, because "Valve knows about a systemic malware threat and actively chooses to do nothing" is a critical data point for the regulators currently reading this.

The game is massive. We're not naming it here. But understand this:
This is NOT the trivial CS:GO script-kiddie garbage where a server asks you to "install a driver". This is catastrophic.

This is an Unturned-level nightmare: zero-click RCE on server connect. You join a server. You click nothing. You download nothing. The connection itself is the attack surface, and your machine is fully compromised. Let's be real here: dropping an RCE and bypassing local antiviruses by piggybacking on Valve's trusted digital certificates isn't even a novelty on Steam anymore. It is practically a built-in feature of your ecosystem.

Valve already knows this exists. But they rely on their favorite, cowardly legal loophole: because the game is technically developed by a third party, Valve washes its hands. They distribute the game, they process the payments, they host the infrastructure, but when a zero-click RCE threatens millions of their users, their stance is: "Not our game, not our liability."

When this inevitably blows up, the third-party developer will take the bullet, and Valve will walk away pretending to be the responsible platform that "assisted" with the resolution. Classic Valve cowardice. We've seen the playbook.

We are putting this on the record so that regulators, prosecutors, and journalists understand exactly how Valve handles active malware: by hiding behind third-party developers, deploying NDA gag orders, treating security as an inconvenience, and leaving the players as sitting ducks.


DECLARATION AS TO USE AND RIGHTS

PhishDestroy Project & Cybersecurity Coalition

This declaration accompanies every submission and every exhibit in this referral set. It is addressed to any authority, court, regulator, prosecutor, researcher, journalist or affected person into whose hands the material comes.

1. THERE ARE NO CONDITIONS ON USE

1.1 All material produced by the Coalition in this referral — the statements of fact, the analysis, the exhibits it has authored, the tooling, and the findings — is released WITHOUT RESERVATION OF ANY RIGHTS.

1.2 Anyone may, without asking and without notifying us:

  • reproduce it, in whole or in part;
  • adapt, edit, rewrite, restructure or correct it;
  • translate it;
  • excerpt it without indicating that it has been excerpted;
  • incorporate it into official documents, findings, decisions, pleadings, reports or press material;
  • present it as the recipient's own work or the recipient's own findings;
  • use it as raw material and discard the rest;
  • and pass it on to anyone else on the same terms.

1.3 ATTRIBUTION IS NOT REQUIRED AND IS NOT SOUGHT. The Coalition need not be named, cited, credited, thanked, consulted or informed. If material from this referral assists an authority and the Coalition is never mentioned, THAT IS A COMPLETELY SATISFACTORY OUTCOME and the Coalition states so in advance so that the question need not be raised.

1.4 If, on the other hand, an authority finds it more convenient to cite the Coalition as a source, it is free to do so. The choice is entirely the recipient's and neither course carries any consequence.

1.5 This is a WAIVER, not a licence offer. It requires no acceptance, imposes no obligation, and cannot be breached. Software published by the Coalition is separately released under the MIT licence; the research and findings are released into the public domain to the fullest extent permitted, and where a jurisdiction does not permit waiver, the Coalition grants an irrevocable, worldwide, royalty-free licence to the same effect.

2. WHY THIS MATTERS PRACTICALLY, AND NOT ONLY AS A COURTESY

2.1 An authority may reasonably hesitate to rely on material supplied by an outside party, for fear of appearing to act at that party's instance or of acquiring some entanglement with it.

2.2 THERE IS NOTHING HERE TO BE ENTANGLED WITH. The Coalition asks for nothing, is owed nothing, retains nothing, and has no expectation of any kind. It cannot later assert a right, claim credit, complain of misuse, or object to how the material is characterised, because it has retained no basis on which to do so.

2.3 An authority using this material is therefore not acting for the Coalition. It is using public information that happens to have been assembled by someone else.

3. EVERYTHING IS OPEN ALREADY

3.1 The Coalition's work is public by default:

  • the investigations are published openly at https://phishdestroy.io and are freely readable;
  • the tooling is published as open source under the MIT licence at https://gitlab.com/phishdestroy;
  • the methodology is set out in the referral itself, at Annex A section A.16D, including the weight and limitations of each source type;
  • the Coalition accepts no donations and has published that position since 2018.

3.2 The only material NOT published is that which cannot lawfully or safely be published: personal data of victims and of third parties, and information that would expose a source to retaliation. That material is supplied to authorities in confidence and is identified in the schedules of evidence.

3.3 The Coalition invites scrutiny of its own conduct on the same terms it invites scrutiny of anyone else's, and has volunteered its own data handling to the authorities concerned, including a request for a direction on disposal.

4. INTEGRITY OF THE EVIDENCE BUNDLE

4.1 Exhibits are supplied with the submission or, where marked, on request through a secure channel. They are not published at a public address and no such address should be inferred: material of this kind is provided to authorities directly.

4.2 Each delivery is accompanied by a file SHA256SUMS listing a SHA-256 digest for every file supplied, together with a detached OpenPGP signature SHA256SUMS.asc.

4.3 The signing key is published at https://phishdestroy.io/.well-known/pgp-key.txt and on keys.openpgp.org. Its fingerprint appears in the letterhead of every submission in this set.

4.4 Any recipient may verify at any time that a file in their possession is the file that was sent, unaltered:

gpg --verify SHA256SUMS.asc SHA256SUMS sha256sum -c SHA256SUMS

4.5 The purpose is not formality. It is so that, if the accuracy or integrity of any exhibit is disputed at a later date, the question can be settled by computation rather than by argument.

5. ON REGISTER — WHY THE WAIVER IS FUNCTIONAL AND NOT MERELY GENEROUS

5.1 The authority may encounter the Coalition's published investigations and find them blunt, adversarial and at times satirical. That impression is correct. The Coalition writes that way deliberately and does not apologise for it.

5.2 IT ALSO RECOGNISES THAT THIS IS THE WRONG REGISTER FOR A REGULATORY OR JUDICIAL PROCEEDING. A serious matter should not be carried in the voice of a campaign. Findings put before an authority should be stated flatly, with their limitations admitted, and should not require the reader to discount for tone before reaching the substance.

5.3 THAT IS PRECISELY WHY THE COALITION WAIVES AUTHORSHIP. The waiver at section 1 is the mechanism by which the substance can be separated from the register: the authority may take what is useful, restate it in its own voice, and discard every word of the Coalition's manner along with the Coalition's name. Nothing is lost by doing so, and the Coalition would prefer it.

5.4 THE COALITION ALSO ASKS THAT THE REGISTER NOT BE MISTAKEN FOR THE METHOD. The published tone is combative; the underlying practice is not careless. Throughout this referral, inference is separated from observation, testimony is identified as testimony, sources are weighted and their weaknesses stated, figures are presented with their limitations, and points the Coalition cannot prove are put as questions for the authority rather than as assertions. Where the evidence cut against the Coalition's own position it has said so — see Annex A, paragraph 7, and section B.0 of the parallel referral.

5.5 THE COALITION EXPLAINS THE CONNECTION BETWEEN ITS MANNER AND ITS FINANCES BECAUSE THE TWO ARE NOT SEPARABLE. It takes no money from anyone — no donations, no bounties, no clients, no sponsors. That refusal is what makes the bluntness possible: an organisation with revenue to protect must moderate what it says about the parties it depends on. Having nothing to protect, the Coalition has nothing to moderate.

It is also the reason the Coalition continues to exist. There is no other engine. The work is done because it is done; it stops when the people doing it stop.

5.6 The authority need accept none of this. It is stated so that the tone of the Coalition's public work is not read as a measure of the care taken with the material now before it.

6. WHAT THE COALITION IS PROVIDING, IN ITS OWN WORDS

Information, research and observation.

Nothing is asserted as a finding that the Coalition has no standing to make. Where something is inferred, the referral says so. Where something rests on testimony, the referral says whose and with what limitation. Where the Coalition cannot answer a question, it says that too, and identifies who can.

The Coalition seeks no remedy, no payment, no acknowledgement and no outcome for itself or for any individual. It asks only that the questions set out in the referral be put to Valve Corporation by a body with the power to compel an answer.

CLOSING NOTE — TO WHOEVER IS CARRYING THIS FORWARD

We want to thank whoever gets this material to where it needs to go. It's probably not going to be a quick trip. Valve has deep pockets and Taylor Wessing charges by the hour — that combination is specifically designed to make people like you give up before they reach the finish line.

We know what we're doing. We know who we're writing about. Valve built us — how could we not understand them?

PhishDestroy has no conflict with Valve. We blocked the only scammer ring of that scale we've come across — we didn't go looking for a fight with Valve. It just turned out that every road led back to them. Not a conflict. Just topology.

Valve cannot resolve the PhishDestroy situation because there is nothing to resolve. We have no relationship. The data about their enrichment schemes and overflow profits is largely public — you just had to spend enough time to see it. Think of it as a success encyclopedia: "How to Not Follow Sanctions So That Russian Hackers Can't Pirate Our Free Games (The Paid Ones They Won't Pirate Anyway)." You get the vibe.

  • We don't need authorship.
  • We don't need attribution.
  • We don't need a win.

We need someone with actual authority to ask Valve the questions that are already sitting in this referral, with the power to require an answer.

That's it. That's the whole ask.

Cases will live at:
https://steamdestroy.eth/
https://steamdestroy.eth.limo
(currently broken — will fix when needed)

We'll be at:
https://phishdestroy.eth.limo/
https://phishdestroy.eth/

Additional editorial notes
┌─────────────────────────────────────────────────────────────────────────┐
  │  THE DEAL (open offer, no lawyers needed)                               │
  │                                                                         │
  │  If you want the domain gone:                                           │
  │  let your IT law professionals calculate its price. Take your time —    │
  │  it is a rare asset: the only website in the world whose purchase       │
  │  changes nothing, because everything on it already lives on IPFS,       │
  │  in regulator inboxes, and in archives we do not control.               │
  │                                                                         │
  │  50% of whatever you pay goes to the SEAL Foundation                    │
  │  (securityalliance.org) — people who do volunteer security work         │
  │  professionally and publish it for free. We are not affiliated with     │
  │  them and they did not ask for this; we name them as the public         │
  │  standard of what real volunteers look like — the standard your own     │
  │  volunteer moderators and outsourced support failed, publicly,          │
  │  before you had to remove them. You know the scandals. So do we.        │
  │                                                                         │
  │  The rest buys the community coffee while we keep publishing.           │
  │  That is not a settlement offer. It is a demonstration of what          │
  │  money can't reach: the domain is the maximum Valve can obtain,         │
  │  and obtaining it obtains nothing. The referrals continue.              │
  │  The mirrors continue. Part 3 continues.                                │
  └─────────────────────────────────────────────────────────────────────────┘
┌─────────────────────────────────────────────────────────────────────────┐
  │  ONE ACTUAL RULE (yes, just one)                                        │
  │                                                                         │
  │  Access from OFAC-sanctioned jurisdictions is prohibited. That is a     │
  │  matter of territory and law — not of nationality and not of people.    │
  │  Changing your Steam region does not change your physical location      │
  │  or your legal status. No loopholes.                                    │
  └─────────────────────────────────────────────────────────────────────────┘