Skip to investigation
PHISHDESTROY / STEAM DOSSIERPrivacy & enforcement
EXISTING DATA / ACCESS / REMEDYREVIEWED 11 OCT 2026 · UTC

THE INFORMATION IS ALREADY THERE.

Existing data.
Selective privacy.

Valve must account for the power it already uses.

Location signals, device records, payment restrictions and moderation decisions all sit inside the same platform. Invoking privacy against regulation leaves a central question unanswered: how does Valve use that existing control to protect people, and how can a person challenge its use?

01

THE BASELINE VALVE’S RESPONSE LEAVES OUT

A VPN does not erase
the account’s history.

Valve describes additional location checks as a new worldwide intrusion. Assessing that claim requires an inventory of the information already collected and the decisions already made with it.

The existing record—not a hypothetical new surveillance system
LayerPublicly documented capabilityThe question it raises
Account & networkThe privacy policy lists SteamID, country of residence and logged IP addresses. How are historical account and location signals used when access rules change?
Device & activityThe same policy lists unique device identifiers, operating-system information, settings and application use. Which identifiers persist between sessions and connect accounts or devices?
Authorised devicesSteam Guard distinguishes unrecognised devices and provides an authorised-device review. What protection uses this continuity when the network address changes?
Country detectionSteamworks exposes GetIPCountry, using an IP-to-location database. What additional precision is needed, for which decision, and with what error rate?
THE LAYERS THAT ALREADY EXIST

A VPN changes the route, not the record.

Name the layers. The browser session that registered the account. The game client that still phones home from the same machine. The CDN and ASN fingerprints Valve’s own servers log on every request.

A player who registers on the web in New York, connects through a VPN and launches the same client leaves a chain Valve already records: one machine, one client build, one account history, requests crossing Valve’s own network edge at every step. Local transfers move installations between machines; they do not delete the download and authorisation events already logged.

Publish that chain — device, client build, network trace, account history — before claiming that only new, total collection can establish location.

THE TECHNICAL POINT

Changing a network route does not inherently reset an application’s device identifier. A long account history followed by a VPN connection can therefore be evaluated alongside existing device and authorisation records. Valve should disclose how those signals are assessed, what they can establish and which less intrusive options it tested.

IP intelligence can classify known VPN and hosting infrastructure. MaxMind documents such classifications and their limits. Valve should publish the location signals it actually uses, the decision thresholds, the treatment of account history and the procedure for correcting a mistaken restriction.

THE INVESTIGATION’S TESTS / REGISTRATION

Registration was refused behind a VPN.

In the investigation’s own tests, account registration was refused while connected through a VPN. That is an observation, not a statistic: the dated reproduction — connection conditions, time, displayed refusal and the resulting account decision — belongs beside the registration and connection records Valve already keeps, which can state the rule that fired and its error rate.

THE OPEN LEAD / NORDVPN

What share of New York users arrive through NordVPN?

The author’s lead, stated as a question and not as a finding: what share of New York Steam users reach the platform through NordVPN? It is measurable, and Valve’s own connection records can answer it — connection counts by exit network for New York accounts, beside the location decisions those connections produced. No market share is asserted here; the record is the demand.

Device records, network history and Valve’s disclosure duty+

Valve should identify the device fields its clients collect, including whether hardware and network identifiers enter its account-security or location decisions. Publish their purpose, retention, cross-account use and correction process. The relevant records are held by the platform operating the client.

Name the fields behind the generalisation. “Hardware and network identifiers” has specific candidates: MAC address, motherboard serial, disk serial. The demand is field-level — for each field, whether Steam’s clients collect it, where it is retained, and which account-security or location decisions it enters. Universal collection is not established on this record; field-level disclosure is what would establish or refute it.

Downloads, authorisations and later account access leave a sequence of dated events. Steam also supports local-network installation transfers. Valve should explain which of those records enter its regional checks, how they are combined and why additional collection is necessary when an established account changes its network route.

The CS2 client download and its network trace are the concrete case: downloads, authorisations and later account access leave a sequence of dated events across Valve’s own CDN and ASN. That sequence is logged by Valve’s own infrastructure; it should be published with the account decisions it can inform, not folded into a claim that only new collection can locate a user.

The investigation’s VPN and registration tests belong beside that disclosure: connection conditions, time, displayed restriction and the resulting account decision. This makes Valve’s existing regional controls inspectable and gives users a concrete basis for challenging an inconsistent result.

THE EARLIER DISCLOSURE RECORDOne device. Multiple accounts. Years of retained history.The dossier’s counsel-correspondence account and its source trail ↗
02

VALVE’S OWN PRODUCT HISTORY

The regional switch
already exists.

Country-specific container rules are a documented part of Counter-Strike. Valve’s privacy argument must explain what the proposed controls add to this existing system.

25 APR 2018 / BELGIAN MINISTER OF JUSTICE

Belgium named CS:GO explicitly.

The minister’s release reports the Gaming Commission’s finding that paid loot boxes in CS:GO, FIFA 18 and Overwatch fell under Belgian gambling law. It called for their removal and highlighted the lack of player protection. This is a directly identified Valve game in a primary regulatory record.

The source is a ministerial account of the Commission’s position. The subsequent Valve restriction is documented separately in the July release notes.

NETHERLANDS / 11 JUL 2018Trading & Market: restored.

The ability to exchange was brought back.

THE SAME RELEASEContainer opening: restricted.

Valve changed access to the paid opening separately.

Netherlands & Belgium: container opening restricted.

Valve’s release notes restored Trading and Market for Dutch customers while restricting container opening in both countries. This was a product-access decision tied to territory.

France: X-Ray Scanner introduced.

Valve introduced a preview mechanism that consumes the container. Advancing to another reveal requires claiming the previous result.

Netherlands & Germany: the scanner becomes the route.

Valve announced X-Ray Scanner access for these players, with an exception for keyless containers such as Souvenir Packages. The Netherlands record therefore changes in 2026; the announcement does not name Belgium.

REGIONAL CONTROL / THE DEMONSTRATED CAPABILITY

Valve can change the product by territory.

Valve should disclose the architecture and effectiveness of the regional control it already operates, including its handling of VPN connections, existing account history and contested decisions. The company owes users an explanation of the alternatives it considered and the remaining gaps.

X-RAY / THE ECONOMIC QUESTION

What does the next unknown result cost?

The current FAQ requires purchase and receipt of the revealed item before another scan. Analysis must follow the paid sequence, including the cost of advancing, rather than stop at the presence of a preview.

The Dutch record: the ruling and Valve’s own response+

The Dutch regulator’s April 2018 study found four of ten examined implementations inconsistent with its gambling-law analysis; it linked transferable prizes to economic value. The games were anonymised.

The Council of State’s 9 March 2022 ruling overturned the penalty in the EA FIFA/FUT case. Valve’s own Dutch record is the regional product change documented above: it altered trading access and container opening separately. Those are the mechanisms that its present defence must explain.

PUBLIC COMPLAINT / PRIVATE NEGOTIATIONS

Publish the demand being denounced.

The filed NYAG complaint alleges an age-confirmation checkbox rather than age verification (¶144). Its requested relief does not prescribe universal VPN detection, biometrics or worldwide identity-document collection. Valve’s account of proposed additional collection describes pre-litigation discussions.

Release the proposals: required data, affected users, retention periods and alternatives considered. The public cannot audit a sweeping privacy objection from one party’s summary of unpublished negotiations.

THE OBJECTION / 11 MAR 2026

“Beyond what we normally collect.”

Valve’s own words, quoted before they are dismantled: the NYAG proposal would gather additional information “beyond what we normally collect in the course of processing payments” — collection that “would have involved implementing invasive technologies for every user worldwide.”

“Normally collect” sets a baseline; “invasive technologies for every user worldwide” sets a fear. Both halves are testable against a record Valve itself has already produced.

THE PRODUCTION / OCT 2025

830 pages about one account.

Months before that statement, Valve answered a single user’s Article 15 access request with an 830-page appendix: 902,270 covered characters still extractable beneath the failed masking. No payment processor handed Valve that file — Valve’s own systems produced it, hold it, and disclosed it only under statutory compulsion.

Publish what “normally collected” already covers before it is accepted as a narrow baseline. Inspect the 830-page production and its audit trail ↗

03

PAYMENT IDENTITY IS NOT PLAYER AGE

Who funded it?
Who opens it?

Valve invokes age checks built into most payment methods used by its New York customers. That does not establish the age of the person spending an already funded Wallet. The system itself separates funding from use.

01
RETAIL CASH / THE HISTORICAL ROUTE

Physical cards put money into Wallet.

The complaint expressly describes retail gift cards bought with cash (¶29). That route cannot be answered solely by referring to a bank’s checks on a cardholder.

The historical record: the cash route is not hypothetical. Valve’s own current FAQ dates the retail programme to 2012 ; GameStop’s 14 May 2012 partnership announcement, preserved in a contemporary reprint, described cash-funded Steam Wallet at physical stores; and a 2019 archival capture of Valve’s gift-card page described the physical cards as suiting cash-in-hand purchases. Valve itself marketed physical cards to buyers without bank instruments — years of its own record, not an invented funding route.

2026 policy change: Valve is ending its retail gift-card programme. Stores will not be restocked; Valve expects stock to run out by the end of 2026. Existing cards remain redeemable, subject to local law. The FAQ attributes the decision to persistent gift-card scams.

02
DIGITAL GIFTS / DIFFERENT PEOPLE

The person paying can fund someone else.

Valve sells digital gifts that credit a recipient’s Wallet. Checking the buyer’s payment method does not identify the recipient currently using the game. Existing Wallet funds cannot buy these digital gift cards.

03
TF2 ITEMS / THE MARKET BRIDGE

A tradable key can become spending balance.

Valve’s Mann Co. Supply Crate Key listing marks the TF2 item as tradable and marketable. Eligible Community Market sales produce Wallet funds. An externally acquired item can therefore reach the spending balance without the player’s own card funding that sale.

Market access has separate eligibility conditions, and sales proceeds alone do not remove limited-account status. These are separate gates; neither is a documented verification of the current player’s age.

THE FAILURE IN THE RESPONSE

A check on one funding route cannot stand in for a check at the paid random outcome. Valve must identify the control that connects the person opening a container to a verified age, across gifts, item-sale proceeds and pre-existing balances.

A CONCRETE REGIONAL FUNDING RECORDThe Russian top-up question now has a named provider.Official MTS service, territorial statements and linked card-transfer terms ↗

Inspect the original service and its linked terms:

External funding, cryptocurrency and regional top-ups+

An outside item purchase may be settled in money or cryptocurrency while the subsequent Steam sale credits Wallet. The payment, item delivery and Wallet credit are separate records. This page establishes the Steam leg; the fee, hold period and restriction risk for each outside seller are records held by that seller and by Valve, and they must be published beside the Community Market’s own fee schedule and hold periods.

The Russia, Crimea and Donetsk top-up record now names its provider and settlement centre . The contracting entities, transaction dates, settlement path, turnover totals and any Valve agreement are records held by MTS Payment, the settlement bank and Valve; they must publish them, and any sanctions finding rests on those disclosures. Continue through the original Steam Dossier ↗

The routes establish an age-linkage problem. Valve holds the registered ages of the accounts using each route, and each retailer holds the age checks it applied; those records, not an invented minors statistic, must answer the question.

FOLLOW THE VALUE AFTER AN ACCOUNT COMPROMISEA protected trade is not protection for every route.Market sales, inflated-price purchases, Wallet proceeds and game gifts ↗
04

RESTRICTION FIRST / EXPLANATION AFTERWARDS

If the payment failed,
show the evidence.

Steam’s chargeback policy restricts associated accounts and purchases. Its standard remedy sends the payment-method owner to the bank to reverse the dispute; return of funds restores the purchase and removes the restriction. If reversal is impossible, the user is directed to Support.

29—31 AUG2026AMERICAN EXPRESS
FIRST-PERSON REPORTS

Users reported restrictions after payments they said they had not disputed.

In a Steam forum thread, users described removed purchases and payment restrictions involving AmEx. A 31 August account said Support lifted the restriction as an exception and warned about recurrence. These are direct user accounts of the incident; a confirmed cause from Valve, AmEx or the processor was not found.

The unresolved issue is concrete: what can the user challenge when Steam says “dispute” and the bank cannot supply the corresponding record?

The reports share a concrete shape: real card owners, transactions that failed or were cancelled outright, account locks that followed — and template support text in reply.

The transactions behind the restrictions.

Users dated the disputed charges to 17—18 August 2026 — purchases they denied ever disputing. One user’s card issuer confirmed two approved authorisations of $8.23 on 17 August, only one of which Steam’s processor captured and posted; the second expired uncollected. That account of an issuer conversation is relayed testimony, not an audited finding.

Another user reported the charge never reached AmEx at all: four days of processing attempts visible in Steam’s purchase history, nothing in the cardholder’s AmEx statement. A charge that never completed leaves the card owner nothing to produce — the evidentiary impossibility at the centre of the episode.

Removed game, locked account, no route out.

The thread’s opening report: a game removed after twelve days of play over a charge the bank said it never disputed, with repurchase refused and new payment methods rejected.

The exception, the warning, the re-lock.

Support lifted one user’s restriction “as an exception,” warning the account could be permanently locked if it happened again — while the disputed purchase stayed removed. Another user reported a second 17 August transaction re-triggering restrictions after an earlier unlock. A third reported Support giving “the same stock responses,” repeating “call American Express” and refusing to supply a Transaction ID or escalate to a payment specialist.

Records removed. Games still not restored.

A user reported the chargeback records had been removed from the account — but AmEx still declined, and the disputed games were still not restored. Removing the flag did not return the purchase, and the basis of the original restriction was never supplied.

THE RECORD

Identify the payment event.

Distinguish authorisation failure, settlement failure, reversal and a customer-initiated dispute. Supply a transaction reference and the restriction’s actual basis.

THE REVIEW

Provide a route out of a mistaken restriction.

State who reviews conflicting records, what evidence is accepted, which functions are restricted and when a decision can be expected.

Valve’s restriction policy includes chargebacks under payment fraud and permits restrictions across an individual’s accounts. It also distinguishes account locks, Community Bans, trade bans, VAC bans and suspensions. The relevant notice and effect must be recorded; “banned account” is not a sufficient classification.

THE DEMAND

Valve and its payment processor should publish the transaction event records behind these account actions. Authorisation, capture, settlement, reversal and dispute status for each transaction, tied to the restriction it produced and the account decision that followed. The parties whose systems generated the events can produce the record; the user cannot produce a statement for a charge that never completed. “Call your bank” is not evidence — it is the absence of one.

THE ENFORCEMENT QUESTION

Valve can make a payment event immediately consequential for the user. The corresponding obligation is a usable explanation and correction process. Calling a remedy an exception does not explain whether the original classification was right.

05

THE STANDARD OF PROOF MUST TRAVEL BOTH WAYS

Valve can document abuse.
Apply that standard consistently.

Valve’s discussion of media and real-world violence does not answer the question of threats and abuse inside its own reporting and support systems. The relevant record is what people submitted, how Valve assessed it and what decisions followed.

SMIRNOV v. VALVE / NEVSKY DISTRICT COURT

A documented litigation trail.

Case № 2-5519/2022 · UID 78RS0015-01-2021-007838-13

The claim was dismissed.

The Nevsky District Court decision dates to 1 September; final form followed on 2 September. The requested RUB 74,598,433 penalty and RUB 50 million moral-damage award were separate demands. The widely circulated 13 September date concerns reporting of the case.

Valve’s side commissioned a linguistic examination.

The 66-page GLADIS report, published by its authors, identifies an 8 June contract with the Baker & McKenzie CIS branch. It examines the claimant’s correspondence with Steam Support, using submitted screenshots and translated printouts. This was a party-commissioned specialist report.

The cassation court upheld the refusal.

The court describes escalating Community restrictions and the expert findings on insults, discriminatory statements and threats. It records that the claimant declined the opportunity to seek a court-appointed examination or submit contrary evidence. Case № 88-10528/2024.

THE SUBMITTED FILE / A MATERIAL DIMENSION

Audit the evidentiary package itself.

The record has a material dimension this page has not audited: the PDF Valve’s side submitted. The report, the translated printouts and the screenshots were filed as evidence — and how that package was assembled and edited shows what Valve’s counsel treats as an acceptable evidentiary file.

Reproduce the submitted materials, with third-party identifiers protected, and audit the file itself: who compiled it, what was cut, and whether the court received the same text the reports contained. The standard Valve demands of a sanctioned user’s words applies to the file its own side carried into court.

THE LITIGATION RECORD

Language was examined as evidence.

Valve’s side obtained an extended analysis to support a sanction. This demonstrates that its enforcement position can be particularised and tested against a record.

THE DOSSIER’S DISCLOSURE RECORD

Abusive reports require the same scrutiny.

The Steam Dossier describes nationality-based abuse and death wishes in retained reports. Its public audit establishes failed masking across 830 pages and 902,270 extractable covered characters.

ONE RULE / AN AUDITABLE APPLICATION

Which reports were used against their target, and what happened to abusive reporters? Publish anonymised decision records showing the allegation, assessment, rule applied, sanction and appeal result. Evidence submitted to justify a sanction must be distinguished from material merely retained in a file.

Follow the report from submission to sanction+

The aggregate audit counts 177 occurrences of the heading “Abuse Reporter Account Name”. That is a document-label count, not a count of unique complainants, abusive reports or proven violations. It does not record the moderation outcome for each report.

For the reported pornographic link, Valve should produce the processing history and an appropriately redacted exhibit: who assessed it, whether it was relied upon, which rule applied and what decision followed. The audit should expose the handling of the report while protecting third-party identifiers.

Steamworks documents text-filtering functions. Valve should identify the filters and rules actually applied to threats, discriminatory abuse and links submitted through its reporting systems, and release the corresponding decision traces. The same scrutiny it applies to a sanctioned user’s language must reach abusive submissions used against that user.

Publish comparable sanctions and appeals alongside inventory value, violation category and final remedy. That record would show how consistently Valve applies its rules when the account contains a valuable collection.

THE ORIGINAL MATERIAL REMAINS IN PLACEClient inspection. Retained data. Failed disclosure.Read the 2014–2026 record and the September access-request closure ↗
06

A CONCRETE TEST OF VALVE’S POSITION

Account for the system
that already operates.

The investigation calls for access to existing decision records, minimised and protected where necessary. Expanding data collection is not a prerequisite for examining how Valve exercises its present power.

  1. 01

    Show the proposed privacy intrusion.

    Release NYAG’s actual proposals and Valve’s alternatives: data categories, affected users, necessity, retention and safeguards.

  2. 02

    Map the data already used.

    Identify location and device fields, cross-account matching, retention, error rates and the decisions they inform.

  3. 03

    Explain the age gate at the transaction.

    Account for existing balances, gift funding and Market proceeds; identify how the current player’s age is established.

  4. 04

    Make restrictions reviewable.

    Provide the reason, evidence reference, scope, reviewer and correction route for payment and commercial-use restrictions.

  5. 05

    Audit moderation in both directions.

    Trace reports to findings, sanctions and appeals, including abusive submissions and any relationship to inventory value.

THE FINDING

Valve’s existing control is documented. The adequacy and accountability of its use remain the issue. A privacy slogan, a payment-method generalisation and an aggregate ban count do not supply the missing decision record.

07

THE PUBLIC RECORD

Inspect the evidence.

Sources cited in this article appear first. Select “All records” to inspect the complete 107-record register shared by the investigation; the dedicated evidence files retain their own detailed registers.

E13The Steam Dossier — rules, routes and accountabilityPhishDestroy / contextRelated investigation↗E14About the New York Attorney General lawsuit against ValveValve / primary11 Mar 2026↗E15Steam Community Market FAQ — Wallet proceeds and market limitsValve / Steam Support / primaryLive FAQ · reviewed 10 Oct 2026↗E21Disclosure audit — 830-page appendixPhishDestroy / exhibitPublished audit · reviewed 20 Sep 2026↗E38People of New York v. Valve Corporation — filed complaintNew York Attorney General / NYSCEF / primary25 Feb 2026↗E66Limited User AccountsValve / Steam Support / primaryLive FAQ · reviewed 10 Oct 2026↗E71Steam Privacy Policy — existing collectionValve / primaryCurrent policy · §§3.1–3.8↗E72Account Security Recommendations — authorised devicesValve / Steam Support / primaryCurrent guidance↗E73ISteamUtils — country and text-filtering functionsValve / Steamworks / primaryCurrent developer documentation↗E74GeoIP Anonymous IP — VPN and hosting classificationsMaxMind / primaryCurrent technical documentation↗E75Release Notes for 7/11/2018 — Netherlands and BelgiumValve / Counter-Strike / primary11 Jul 2018↗E76France — introducing the X-Ray ScannerValve / Counter-Strike / primary30 Sep 2019↗E77X-Ray Scanner for Germany and the NetherlandsValve / Counter-Strike 2 / primary16 Mar 2026↗E78Counter-Strike 2 — X-Ray ScannerValve / Steam Support / primaryCurrent FAQ↗E79Steam Wallet — retail gift-card phase-outValve / Steam Support / primaryFAQ v18 · metadata 10 Jun 2026↗E80Digital Gift Cards — funding another accountValve / Steam Store / primaryCurrent gift-card FAQ↗E81TF2 — Mann Co. Supply Crate KeyValve / Steam Community Market / primaryCurrent official item listing↗E82Payment Disputes and ChargebacksValve / Steam Support / primaryCurrent policy · metadata 15 May 2024↗E83STEAM payment system broken? — AmEx incident reportsSteam Community users / exhibit29–31 Aug 2026↗E84Smirnov v. Valve — case 2-5519/2022Nevsky District Court, Saint Petersburg / primary1 Sep 2022 · final form 2 Sep 2022↗E85Specialists’ report on Smirnov’s Steam Support correspondenceGLADIS / Guild of Linguistic Experts / primary28 Jun 2023 · 66 pages↗E86Smirnov v. Valve — cassation 88-10528/2024Third Cassation Court of General Jurisdiction / primary22 May 2024↗E87Restricted Steam Account — reasons and restriction typesValve / Steam Support / primaryCurrent policy · metadata 22 May 2025↗E88Onderzoek naar loot boxes — Een buit of een last?Kansspelautoriteit / primary19 Apr 2018↗E89EA / FIFA-FUT — ECLI:NL:RVS:2022:690Raad van State / primary9 Mar 2022↗E90Steam Local Network Game TransfersValve / Steam Support / primaryCurrent technical guidance↗E91Belgian loot-box findings expressly name CS:GOKoen Geens / Belgian Minister of Justice / primary25 Apr 2018↗E92Russia-facing Steam top-ups — published service and territorial statementsMTS Payment / primaryRetrieved 11 Oct 2026↗E93Public offer — bank-card money-transfer serviceMTS Payment / Murmansk Settlement Bank / primary2026 document · retrieved 11 Oct↗
Research method and source status+

Reviewed 11 October 2026 UTC. Official policies and product announcements establish documented capabilities and rules. The public complaint states the plaintiff’s allegations. Court dates and findings are tied to the cited acts; user incident reports remain attributed testimony.

The analysis connects existing account and device data, territorial product changes, payment restrictions and moderation records. It asks Valve to account for the decisions already made with that information, the consequences for users and the remedies provided.

Download source register ↓
AUTHOR / INVESTIGATION / EDITORIAL

Agent Noel

Published by PhishDestroy as part of The Steam Dossier.

Find this case in the dossier map →
Agent NoelFOLLOW THE EVIDENCE.
CONTINUE THE INVESTIGATIONThree games & security

CS2, Dota 2 and TF2: unequal remedies, security choices and commercial farming.

What this record supports

Source context

Open original record ↗
EXHIBIT A / ORIGINAL SUBMITTED CROP
Original submitted RWT warning screenshot

Undated, user-supplied image. Site origin was not independently verified.