{
  "compartment_id": "section-14",
  "number": "Section 14",
  "title_local": "Support access and the theft ledger",
  "title_english": "Support access and the theft ledger",
  "source_url": "https://phishdestroy.io/steam_dossier/#insider-threat",
  "source_document": "index.html",
  "content": {
    "html": "<section class=\"border-t border-gray-800 pt-6 accountability-section print-break\" id=\"insider-threat\">\n<div class=\"max-w-7xl mx-auto space-y-8\">\n<div class=\"part-divider ds-dbad1b87743a\"><span class=\"part-label\">Part C — Legal frameworks</span></div>\n<div class=\"case-section-heading section-head section-head-balanced\"><div class=\"section-head-primary\"><span class=\"kicker\">Part C — Legal frameworks · Section 14 · Personnel access</span><h2>Who can reset the safeguards?</h2>\n<section class=\"dossier-note chapter-context\"><div class=\"dossier-note-title\">Context &amp; source limits</div><p class=\"chapter-context-text\">Account security also depends on the people who can recover an account, inspect private records or reset its safeguards. The investigation must follow those privileged actions as closely as it follows API abuse.</p></section></div><div class=\"section-head-intro\"><p class=\"lede\">Account recovery hands a support agent the power to move an account away from its owner. <strong class=\"text-white\">Valve has confirmed in writing, twice — February 2023 and November 2025 — that this power was used to hand accounts to the wrong people.</strong> Thirty-three months apart, through the same channel. Below: what that access is worth, six sourced cases, and the log Valve holds for every one of them and has produced to nobody.</p></div></div>\n<div class=\"case-spread\">\n<div class=\"case-prose\">\n<span class=\"case-kicker\">Preserved testimony / 9 May 2025</span><h3>A recovery ticket that disabled the account's security, and a reported $10,000 loss</h3>\n<p>A user in the collected support archive reports that Steam Support reset the password and disabled account protection after another person submitted a recovery ticket. The author says the account had been inactive for years, held items since 2016–2017 and had Steam Guard, a linked phone and stored recovery codes.</p>\n<blockquote>\"Steam Support still gave someone else access to my account.\"</blockquote>\n<p class=\"case-source\">First-person allegation, preserved in <code>steam_support_tickets_MEGA.json</code>, record 110. <a href=\"steam_enforcement_evidence#case-support-recovery\">Read the complete captured post ↗</a></p>\n<p>This is not one user's bad luck. The same door — a help request that moves an account to whoever supplies the older data — is the documented way in for every case in the ledger below, and Valve has twice put that in writing.</p>\n<p><strong class=\"text-white\">The owner cannot win that argument.</strong> Recovery asks for the first CD key, the first email, the first card, the first phone number. Those facts are in Valve's database, and support-side access reads them — reported as reaching back fifteen years. A person who has a copy of your file will always produce more of your history than you can. Targets were picked to fit: dormant for years, high-value, and often bought second-hand, so the holder never knew the original key. Afterwards the accounts were deleted outright, breaking the item-history trail the community uses to trace a skin — a deletion an ordinary user cannot perform without the standard waiting period.</p>\n<div class=\"case-legal-note\"><span class=\"case-kicker\">Least privilege / OWASP A01</span><p>Recovery privileges should be limited to the task, independently reviewed and logged. Audit who could reset credentials, remove Steam Guard, read billing records or export account data. <a href=\"https://top10.owasp.org/2025/A01_2025-Broken_Access_Control/\" rel=\"noopener noreferrer\" target=\"_blank\">OWASP access-control guidance ↗</a> <a class=\"archived-link\" href=\"https://web.archive.org/web/20260920212535/https://top10.owasp.org/2025/A01_2025-Broken_Access_Control/\" rel=\"noopener noreferrer\" target=\"_blank\">archived 2026-09-20 ↗</a></p></div>\n</div>\n<div class=\"surveillance-panel\">\n<div class=\"surveillance-heading\"><span class=\"case-kicker\">Broad support access</span><span class=\"case-status\">Access-scope risk</span></div>\n<h3>Beyond the inventory.</h3><p>If broad support access is abused, private telemetry can become a tool for profiling, targeted phishing and surveillance. Potential victims include ordinary users, military personnel, public figures and their families. This is a threat model; the exact permissions require access-control records.</p>\n<dl class=\"surveillance-capabilities\">\n<div><dt><span>01</span> IP history &amp; location</dt><dd>IP logs can expose network history and approximate location. They do not, by themselves, establish precise physical movements.</dd></div>\n<div><dt><span>02</span> Device fingerprinting</dt><dd>Device identifiers, where collected and accessible, can connect sessions and accounts.</dd></div>\n<div><dt><span>03</span> Activity telemetry</dt><dd>Login timestamps and session records can reveal routines, including activity invisible on a public profile.</dd></div>\n<div><dt><span>04</span> Communications &amp; contacts</dt><dd>Access to retained messages or contact information would increase the scope for profiling and social engineering.</dd></div>\n<div><dt><span>05</span> Identity unmasking</dt><dd>Original email, phone and payment records can connect a pseudonymous account to a person.</dd></div>\n<div><dt><span>06</span> Data resale &amp; accountability</dt><dd>Exported target lists could support targeted scams. Establish the actor, access location, recipients and transfers; location alone establishes neither access nor legal immunity.</dd></div>\n</dl>\n<p class=\"case-source\">Valve describes IP logging, device information, payment records and third-party support providers in its <a href=\"https://store.steampowered.com/privacy_agreement/\" rel=\"noopener noreferrer\" target=\"_blank\">Privacy Policy §§ 3, 5.2</a> <a class=\"archived-link\" href=\"https://web.archive.org/web/20260921021648/https://store.steampowered.com/privacy_agreement/\" rel=\"noopener noreferrer\" target=\"_blank\">archived 2026-09-21 ↗</a>. The policy authorises third-party support access — the audit trail that would show which contractor accessed which category, when, and under what authorisation has not been disclosed.</p>\n</div>\n</div>\n<section aria-labelledby=\"theft-ledger-title\" class=\"thf\" id=\"theft-ledger\">\n<div class=\"thf-head\"><span class=\"thf-kicker\">Section 14.1 · the register · June 2022 → November 2025 · every figure sourced</span><h3 id=\"theft-ledger-title\">Valve admitted the door twice, thirty-three months apart. It never closed.</h3><p>Six reported cases in which accounts were taken through Steam's own help-request channel, or through the credentials that channel protects. Each amount is the figure the cited source published, and each source is named. Two of the six were made whole. The difference between them and the rest was not what happened — it was who was watching.</p></div>\n<div class=\"thf-rule ds-13f76ddef10c\"><span class=\"ds-c5c0fe07c7cf\">Valve, in writing — February 2023</span><q class=\"ds-37655f3b24a3\">\"The items in question were removed from your account because they were received from an account that was compromised through a support help request, for which the CS:GO team takes responsibility. We have reversed the trades and removed them from any account which received them.\"</q><cite>Steam Support reply to a recipient of HFB's items, reproduced by <a href=\"https://www.dexerto.com/csgo/csgo-skins-worth-millions-allegedly-stolen-with-help-from-steam-support-staff-2066939/\" rel=\"noopener noreferrer\" target=\"_blank\">Dexerto, 21 February 2023 ↗</a> <a class=\"archived-link\" href=\"https://web.archive.org/web/20250818113925/https://www.dexerto.com/csgo/csgo-skins-worth-millions-allegedly-stolen-with-help-from-steam-support-staff-2066939/\" rel=\"noopener noreferrer\" target=\"_blank\">archived 2025-08-18 ↗</a></cite></div>\n<div class=\"thf-rule ds-13f76ddef10c\"><span class=\"ds-c5c0fe07c7cf\">Valve, in writing again — November 2025 · 33 months later</span><q class=\"ds-37655f3b24a3\">\"A support technician that handled the help request failed to follow our process which resulted in your account restored to someone else. I apologize for this error.\"</q><cite>Steam Support reply to Hawkeye337, quoted in <a href=\"https://www.dexerto.com/counter-strike-2/valve-saves-hacked-cs2-player-threatened-with-ransom-over-300000-of-rare-stickers-3283135/\" rel=\"noopener noreferrer\" target=\"_blank\">Dexerto, 14 November 2025 ↗</a></cite></div>\n<div class=\"thf-filter-bar no-print ds-1f438fe64ac0\">\n<div class=\"ds-250dad817dae\">\n<span class=\"ds-cf941142bab9\">Filter cases:</span>\n<button class=\"thf-tab active ds-411344ed24d6\" data-thf-filter=\"all\" type=\"button\">All 6 Cases</button>\n<button class=\"thf-tab ds-4368828c4ece\" data-thf-filter=\"restored\" type=\"button\">Restored (Social Media Trending) [2]</button>\n<button class=\"thf-tab ds-4368828c4ece\" data-thf-filter=\"refused\" type=\"button\">Refused / Ordinary Users [4]</button>\n</div>\n<div class=\"ds-7d004a1bac49\">\n<span class=\"ds-6637e5b9c8fd\"></span>Restitution: 100% viral vs 0% non-viral\n  </div>\n</div>\n<ol class=\"thf-ledger\">\n<li class=\"thf-case\" data-outcome=\"restored\"><span class=\"thf-when\">21 Jun 2022</span><div><b class=\"thf-who\">HFB — the largest inventory in the game</b><span class=\"thf-sum\">$2,000,000+ <i>· raised to $3,000,000+ in the February 2023 follow-up</i></span><p>Seven Souvenir AWP Dragon Lores and the #1 Blue Gem Karambit, that knife alone valued at about <strong>$1.26 million</strong>. The account had been dormant three years with the mobile authenticator still active; the email and password were changed anyway, through the support recovery route.</p><p><strong>The money left before the items did.</strong> A reported <strong>$200,000+</strong> of sale proceeds was already withdrawn through market.csgo.com — a marketplace that settles in cash and crypto. Reversing a trade returns a skin. It does not return the cash somebody already banked.</p><p><strong>And the fix broke.</strong> One buyer moved his Souvenir Dragon Lore into an in-game Storage Unit. Valve's rollback script could not see inside its own container, so it issued the owner a fresh copy and left the hidden one standing — Valve duplicated a <strong>$130,000</strong> item while trying to undo a theft. It was caught by matching item IDs and community reporting, and deleted a month later, in July 2022. The buyer was refunded by BUFF, not by Valve. Emergency remediation this brittle is not a control; it is what a platform does when it has no control.</p><p class=\"thf-src\"><a href=\"https://www.dexerto.com/csgo/over-2-million-in-csgo-skins-stolen-from-hacked-steam-account-1853092/\" rel=\"noopener noreferrer\" target=\"_blank\">Dexerto, 21 Jun 2022 ↗</a> <a class=\"archived-link\" href=\"https://web.archive.org/web/20220702042821/https://www.dexerto.com/csgo/over-2-million-in-csgo-skins-stolen-from-hacked-steam-account-1853092/\" rel=\"noopener noreferrer\" target=\"_blank\">archived 2022-07-02 ↗</a> · <a href=\"https://www.kaspersky.com/blog/cs-go-two-million-usd-inventory-hack/44697/\" rel=\"noopener noreferrer\" target=\"_blank\">Kaspersky ↗</a> · cash-out figure per <a href=\"https://esportfire.com/article/the-2-million-usd-csgo-hack-22062022\" rel=\"noopener noreferrer\" target=\"_blank\">Esportfire, 22 Jun 2022 ↗</a> <a class=\"archived-link\" href=\"https://web.archive.org/web/20260515110250/https://esportfire.com/article/the-2-million-usd-csgo-hack-22062022\" rel=\"noopener noreferrer\" target=\"_blank\">archived 2026-05-15 ↗</a>, attributed there to multiple Twitter sources · duplication and deletion per <a href=\"https://esportsbetting.com/valve-deletes-130000-stolen-dragon-lore/\" rel=\"noopener noreferrer\" target=\"_blank\">Esportsbetting, 14 Jul 2022 ↗</a></p></div><div class=\"thf-out\"><b>Restored</b><i>Trades reversed. Items pulled back out of the inventories of people who had paid full price for them.</i></div></li>\n<li class=\"thf-case\" data-outcome=\"refused\"><span class=\"thf-when\">14 Aug 2022</span><div><b class=\"thf-who\">CS.Money — the platform's own bots</b><span class=\"thf-sum\">$6,300,000 <i>· 19,000+ skins · first estimate $1.6M</i></span><p>Attackers took the mobile-authenticator files of the marketplace's trading bots and emptied them, then sent part of the haul to well-known traders to blur the trail. Community researchers mapped <strong>55 attacker accounts within hours</strong> and published them.</p><p>Valve reversed nothing. The reason given was that a third-party site sits outside Steam — the same Steam whose inventory, trade API and account system the theft ran on end to end.</p><p class=\"thf-src\"><a href=\"https://esportfire.com/article/the-biggest-hack-in-csgo-history-csmoney-14082022\" rel=\"noopener noreferrer\" target=\"_blank\">Esportfire, 14 Aug 2022 ↗</a> <a class=\"archived-link\" href=\"https://web.archive.org/web/20251115173120/https://esportfire.com/article/the-biggest-hack-in-csgo-history-csmoney-14082022\" rel=\"noopener noreferrer\" target=\"_blank\">archived 2025-11-15 ↗</a></p></div><div class=\"thf-out\"><b>Refused</b><i>No reversal. Loss stayed with the platform and its users.</i></div></li>\n<li class=\"thf-case\" data-outcome=\"refused\"><span class=\"thf-when\">Reported<br/>21 Feb 2023</span><div><b class=\"thf-who\">Qkss — same door, same actor</b><span class=\"thf-sum\">$1,000,000+</span><p>Reported as taken the same way HFB was, by the same actor, through the same support help request. HFB was made whole eight months earlier. Qkss was not.</p><p><strong>One route. Two answers.</strong> Nothing in the published record distinguishes the two cases except the size of the audience.</p><p class=\"thf-src\"><a href=\"https://www.dexerto.com/csgo/csgo-skins-worth-millions-allegedly-stolen-with-help-from-steam-support-staff-2066939/\" rel=\"noopener noreferrer\" target=\"_blank\">Dexerto, 21 Feb 2023 ↗</a> <a class=\"archived-link\" href=\"https://web.archive.org/web/20250818113925/https://www.dexerto.com/csgo/csgo-skins-worth-millions-allegedly-stolen-with-help-from-steam-support-staff-2066939/\" rel=\"noopener noreferrer\" target=\"_blank\">archived 2025-08-18 ↗</a></p></div><div class=\"thf-out\"><b>Refused</b><i>Not restored.</i></div></li>\n<li class=\"thf-case\" data-outcome=\"refused\"><span class=\"thf-when\">Reported<br/>Feb 2023</span><div><b class=\"thf-who\">The insider trade itself — a year of it</b><span class=\"thf-sum\">≈ $320,000 <i>· proceeds over roughly one year, not an inventory valuation</i></span><p>Support-side access reached account history up to <strong>15 years old</strong> — the first CD key, the first email, the first card. That is exactly the evidence the recovery process asks for, which is why the person holding the database always wins the argument against the person holding the account.</p><p>Blogger Mzkshow exposed how insider operator \"Steam Help\" and collaborator \"Alexander\" targeted dormant accounts holding over $100k in skins. One stolen M4A4 Howl carrying iBUYPOWER and Titan Katowice 2014 holos sold for <strong>$35,000</strong> and ended up with NAVI's Valerii \"b1t\" Vakhovskyi, who had no way of knowing. After Valve intervened, the contractor dismissed its entire Steam support desk.</p><p class=\"thf-src\"><a href=\"https://vkplay.ru/media/news/bloger-rasskazal-kak-podderzhka-steam-vorovala-akkaunty-igrokov/\" rel=\"noopener noreferrer\" target=\"_blank\">VKPlay ↗</a> · <a href=\"https://lis-skins.com/ru/blog/krupneisaia-mosenniceskaia-sxema-v-istorii-steam/\" rel=\"noopener noreferrer\" target=\"_blank\">Lis-Skins ↗</a> · <a href=\"https://escorenews.com/ru/csgo/news/44056-sotrudniki-podderjki-steam-zanimalis-krajey-skinov-s-akkauntov-za-god-oni-zarabotali-svyshe-300-tysyach-dollarov\" rel=\"noopener noreferrer\" target=\"_blank\">Escorenews (RU) ↗</a> · <a href=\"https://www.dexerto.com/csgo/csgo-skins-worth-millions-allegedly-stolen-with-help-from-steam-support-staff-2066939/\" rel=\"noopener noreferrer\" target=\"_blank\">Dexerto (EN) ↗</a></p></div><div class=\"thf-out\"><b>No register</b><i>Valve has never published how many accounts this touched, or told the people it touched.</i></div></li>\n<li class=\"thf-case\" data-outcome=\"refused\"><span class=\"thf-when\">Reported<br/>2 Dec 2024</span><div><b class=\"thf-who\">\"Matvey\" — after the sackings</b><span class=\"thf-sum\">$13,000</span><p>Recovery was granted to someone who supplied account data the owner himself could not match. Two years after the contractor cleared out its Steam support desk, the same route produced the same result.</p><p class=\"thf-src\"><a href=\"https://www.reddit.com/r/cs2/comments/1h53qp3/steam_support_is_stealing_accounts_again/\" rel=\"noopener noreferrer\" target=\"_blank\">Preserved post, 2 Dec 2024 ↗</a> <a class=\"archived-link\" href=\"https://web.archive.org/web/20250805141942/https://www.reddit.com/r/cs2/comments/1h53qp3/steam_support_is_stealing_accounts_again/\" rel=\"noopener noreferrer\" target=\"_blank\">archived 2025-08-05 ↗</a> · <a download=\"\" href=\"steam_tos_assets/outsourcing-archive-records.json\">source rows &amp; hashes ↓</a></p></div><div class=\"thf-out\"><b>Refused</b><i>Not restored.</i></div></li>\n<li class=\"thf-case\" data-outcome=\"restored\"><span class=\"thf-when\">13 Nov 2025</span><div><b class=\"thf-who\">Hawkeye337 (Mark Spurlock) — and the second admission</b><span class=\"thf-sum\">≈ $300,000–$500,000 <i>· full Katowice 2014 holo collection</i></span><p>The attacker demanded <strong>1 bitcoin</strong> and began scraping the collection onto Negevs to destroy it. Steam Support's written reply is the second admission above: a technician handled the help request, did not follow the process, and gave the account to someone else.</p><p><strong>What produced the fix was the feed.</strong> Hours after the posts tagging Valve went up on X, the account was taken back and every sticker restored. Qkss did not have that audience.</p><p class=\"thf-src\"><a href=\"https://community.skin.club/en/news/collector-has-steam-inventory-returned-after-bold-hack\" rel=\"noopener noreferrer\" target=\"_blank\">Skin.club ↗</a> · <a href=\"https://www.dexerto.com/counter-strike-2/valve-saves-hacked-cs2-player-threatened-with-ransom-over-300000-of-rare-stickers-3283135/\" rel=\"noopener noreferrer\" target=\"_blank\">Dexerto ↗</a> · <a href=\"https://esportfire.com/article/300k-scam-full-katowice-2014-holo-collection-hacked\" rel=\"noopener noreferrer\" target=\"_blank\">Esportfire ↗</a> <a class=\"archived-link\" href=\"https://web.archive.org/web/20251217072445/https://esportfire.com/article/300k-scam-full-katowice-2014-holo-collection-hacked\" rel=\"noopener noreferrer\" target=\"_blank\">archived 2025-12-17 ↗</a></p></div><div class=\"thf-out\"><b>Restored</b><i>Reversed within hours of the story trending.</i></div></li>\n</ol>\n<div class=\"thf-foot\"><h4>What the ledger says that no single case does.</h4><p><strong>The route never closed.</strong> The first admission is dated February 2023 and the second November 2025 — <strong>thirty-three months apart</strong>, with the contractor's mass dismissal, a documented recurrence and a $6.3 million platform breach in between. Counting from the first theft in this ledger, the channel stayed open for <strong>three years and five months</strong>. Whatever was fixed in 2023, the help request still moved an account to the wrong person in November 2025 — Valve's own sentence.</p><p><strong>Restitution tracked attention, not harm.</strong> Restored: the biggest inventory in the game, and the collector whose thread trended. Refused: $1,000,000, $6,300,000, $13,000. Valve has never published the rule it applies, because a published rule would have to explain those three.</p><p><strong>Nobody was told.</strong> Not the users whose account histories were read out of the database, not a supervisory authority, not the market that bought the items in good faith and had them clawed back. There is no breach notice, no incident report, no count of affected accounts — <strong>and the proceeds left as money</strong>, through marketplaces that pay in cash and crypto. A trade reversal cannot follow money out of Steam.</p><p>Valve holds the support audit trail, the recovery-ticket log and the transaction record for every line above. None of it has been produced. <a href=\"#dsar-playbook\">Ask for your own copy →</a></p></div>\n</section>\n<div class=\"case-bottom-line\"><div><span class=\"case-kicker\">The NDA question</span><h3>Confidentiality must come with technical accountability.</h3><p>Compare confidentiality agreements with actual permissions, export controls, reset approvals and access logs. A canned response cannot resolve an allegation that the recovery process itself was abused.</p></div><div class=\"case-legal-note\"><span class=\"case-kicker\">GDPR Articles 28, 32–34</span><p>Art. 33 gives a controller 72 hours to notify the supervisory authority of a personal-data breach; Art. 34 requires telling the affected people when the risk to them is high. Valve has confirmed in writing, twice, that its support channel handed accounts to the wrong people — account history, billing records and all. <strong class=\"text-white\">No notification under either article has been published, and no affected user has reported receiving one.</strong> <a href=\"https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng\" rel=\"noopener noreferrer\" target=\"_blank\">Read the regulation ↗</a> <a class=\"archived-link\" href=\"https://web.archive.org/web/20260920024236/https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng\" rel=\"noopener noreferrer\" target=\"_blank\">archived 2026-09-20 ↗</a></p><a class=\"case-text-link\" href=\"#dsar-playbook\">Include support access in your request →</a></div></div>\n<nav aria-label=\"Where the support-access evidence continues\" class=\"xlink\">\n<p class=\"xlink-t\">Section 14 continues on these pages</p>\n<div class=\"xlink-row\">\n<a href=\"investigation_part2#outsourcing-case\"><b>Part II — Account access &amp; accountability</b><em>The outsourced support desk, the API-key route and the full loss register behind the six cases above, case by case with sources.</em><i>Open Part II →</i></a>\n<a href=\"valve_scandals_registry\"><b>Valve Scandals Registry</b><em>160 sourced records of support collapse, censored threads, platform flaws and documented incidents. Every row links to its original source.</em><i>Open the registry →</i></a>\n<a href=\"social_graph\"><b>Follow the recorded connections</b><em>Collected Steam moderator profile and comment relationships — a research graph of who is adjacent to whom, not proof of contact.</em><i>Open the graph →</i></a>\n</div>\n</nav>\n</div>\n</section>"
  },
  "original_content_sha256": "47ab765d79b8cae2c5cb2a197b4d0d6a7ef72128a6af9afb92c48ca8b6c2bcf0",
  "author_pseudonym": "Agent Tom",
  "schema": "phishdestroy.macro-fact.v1",
  "language": "en",
  "aggregator": "PhishDestroy",
  "exports": {
    "pdf": "/steam_dossier/exports/agent-protocol/files/en/steam_dossier_section_14_agent_tom.pdf",
    "json": "/steam_dossier/exports/agent-protocol/files/en/steam_dossier_section_14_agent_tom.json",
    "signature": "/steam_dossier/exports/agent-protocol/files/en/steam_dossier_section_14_agent_tom.json.asc"
  },
  "integrity": {
    "signed_object": "steam_dossier_section_14_agent_tom.json",
    "signature_file": "steam_dossier_section_14_agent_tom.json.asc",
    "signing_key_fingerprint": "129FC7F39C40C69D2EF3C329BFCF9E8DD295EE01",
    "scope": "Exact JSON bytes, including macro-fact author and corresponding PDF SHA-256. PhishDestroy is the integrity signer; original evidence attribution is unchanged."
  },
  "pdf": {
    "filename": "steam_dossier_section_14_agent_tom.pdf",
    "sha256": "be4485a465d3e0f4c68c9c114708bf2228c11e426b005d78a99686326b98b727",
    "pages": 7
  }
}
