{
  "reviewed_on": "2026-09-20",
  "archive_build": "2026-09-17",
  "scope": "Six editorial selections from the supplied archive. Issue states describe the saved build; reports are attributed to their authors. These records do not establish the prevalence or cause of all account losses.",
  "records": [
    {
      "id": 484,
      "source": "GitHub",
      "collections": [
        "GitHub JSON"
      ],
      "copies": 1,
      "title": "U2F support for steam's 2 factor authentication",
      "excerpt": "Dear Valve, you have been supporting 2 factor authentification via mobile phone so far. I think this is a security problem because smartphones are stolen very often. If someone steals my phone, he will have access to my steam account. To prevent that scenario ",
      "url": "https://github.com/ValveSoftware/steam-for-linux/issues/4521",
      "author": "",
      "date": "2016-06-27",
      "related": true,
      "removed": false,
      "state": "open",
      "repository": "steam-for-linux",
      "comments": 27,
      "updated": "2022-12-24",
      "labels": [
        "Feature Request",
        "reviewed"
      ],
      "category": "Issue",
      "key": "gh-01",
      "archive_id": 484,
      "label": "Hardware keys, requested in 2016",
      "kind": "Feature request",
      "context": "ValveSoftware / steam-for-linux · #4521",
      "summary": "A user asked Valve to support U2F hardware keys as an alternative second factor. The saved issue carries both Feature Request and reviewed labels, with its state recorded as open.",
      "quote": "I request U2F usb dongle support in steam as an alternative.",
      "establishes": "A dated request for an additional account safeguard, published in Valve’s own issue tracker and labelled reviewed.",
      "question": "Where is the product decision, and what protection was delivered in response? The issue alone does not establish the features in today’s client.",
      "chapter": "consent-analysis",
      "chapter_label": "Account safeguards",
      "source_row": 76,
      "reference_check": "The retrieved GitHub page shows the same title, opening date, labels and open state. Current client behavior was not tested.",
      "body": "Dear Valve,\n\nyou have been supporting 2 factor authentification via mobile phone so far. I think this is a security problem because smartphones are stolen very often. If someone steals my phone, he will have access to my steam account.\nTo prevent that scenario I request U2F usb dongle support in steam as an alternative. That will be more secure because you can store your usb stick in a safe place. A cell phone is something that people will always have with them so it is vulnerable for theft.\n",
      "source_file": "valve_ignored_bugs.json",
      "body_sha256": "1733d414960ba23e44f3dffc248a2f76804ae69e7dc501f739d201320aafec83",
      "archive_url": "steam_evidence_archive.html?source=GitHub&record=484"
    },
    {
      "id": 467,
      "source": "GitHub",
      "collections": [
        "GitHub JSON"
      ],
      "copies": 1,
      "title": "Privacy violation in CEF crash reporter, possibly also GDPR-relevant",
      "excerpt": "#### Your system information * Steam client version (build number or date): latest, 12 August 2019 * Distribution: Ubuntu 16 * Opted into Steam client beta?: No * Have you checked for system updates?: Yes #### Please describe your issue in as much detail as po",
      "url": "https://github.com/ValveSoftware/steam-for-linux/issues/6459",
      "author": "",
      "date": "2019-08-18",
      "related": true,
      "removed": false,
      "state": "open",
      "repository": "steam-for-linux",
      "comments": 2,
      "updated": "2019-08-28",
      "labels": [],
      "category": "Issue",
      "key": "gh-02",
      "archive_id": 467,
      "label": "Crash reports without an effective opt-out",
      "kind": "Privacy report",
      "context": "ValveSoftware / steam-for-linux · #6459",
      "summary": "The reporter describes a Steam client from 12 August 2019 on Ubuntu 16. They say disabling the crash-upload destination did not persist after a restart, and include the relevant configuration.",
      "quote": "If I disable the `ServerURL`, it gets overwritten after every reboot.",
      "establishes": "A specific privacy complaint with a client date, operating system and configuration excerpt. The saved issue is open.",
      "question": "Was the reported behavior reproduced and changed? A current build test and its data flow are needed to establish whether it still occurs.",
      "chapter": "dsar-playbook",
      "chapter_label": "Request the underlying records",
      "source_row": 59,
      "reference_check": "The retrieved GitHub page matches the saved title, opening date, reported environment and open state. No current client reproduction was performed.",
      "body": "#### Your system information\r\n\r\n* Steam client version (build number or date): latest, 12 August 2019\r\n* Distribution: Ubuntu 16\r\n* Opted into Steam client beta?: No\r\n* Have you checked for system updates?: Yes\r\n\r\n#### Please describe your issue in as much detail as possible:\r\nThe Steam client is constantly uploading crash reports. The issue here are not the crashes themselves, but the fact that user cannot disable this behaviour.\r\n\r\nThe file in `~/.local/share/Steam/ubuntu12_64/crash_reporter.cfg` contains:\r\n\r\n```\r\n[Config]\r\n# Product information.\r\nProductName=cefwebhelper\r\nProductVersion=[redacted]\r\n\r\n# Required to enable crash dump upload.\r\nServerURL=http://crash.steampowered.com/submit\r\n\r\n# Disable rate limiting so that all crashes are uploaded.\r\nRateLimitEnabled=true\r\nMaxUploadsPerDay=5\r\n\r\n[CrashKeys]\r\nVendor=small\r\nUserID=small\r\nBuildID=small\r\nSteamUniverse=small\r\n```\r\n\r\nIf I disable the `ServerURL`, it gets overwritten after every reboot.\r\n\r\nThis means it is currently not possible to stop the Steam client from uploading the crash dump files, **which do contain** sensitive information.",
      "source_file": "valve_ignored_bugs.json",
      "body_sha256": "625a5adb9f1c5d240211475930593a982d364ce2eab775e88123074297916820",
      "archive_url": "steam_evidence_archive.html?source=GitHub&record=467"
    },
    {
      "id": 768,
      "source": "GitHub",
      "collections": [
        "GitHub JSON"
      ],
      "copies": 1,
      "title": "[All source games] Steam auth exploit/harvest by scammers",
      "excerpt": "Since now 1 year, there is an en-masse scam operation taking place on all Source based games platforms. The server is called Fastpath They have found a way to exploit players steam auth tickets, keeping them long after the players have disconnected. Making the",
      "url": "https://github.com/ValveSoftware/Source-1-Games/issues/3857",
      "author": "",
      "date": "2022-02-26",
      "related": true,
      "removed": false,
      "state": "open",
      "repository": "Source-1-Games",
      "comments": 32,
      "updated": "2025-09-13",
      "labels": [],
      "category": "Issue",
      "key": "gh-03",
      "archive_id": 768,
      "label": "Auth-ticket abuse reported to Valve",
      "kind": "Abuse report",
      "context": "ValveSoftware / Source-1-Games · #3857",
      "summary": "The author alleges that a server operation retained Steam authentication tickets after players disconnected and used misleading server listings. The post asks Valve to address the behavior.",
      "quote": "Making their servers look packed.",
      "establishes": "A public abuse report lodged in Valve’s tracker on 26 February 2022. Its saved state is open; the report includes links to screenshots.",
      "question": "What investigation or mitigation followed? The author’s server counts and proposed mechanism need independent verification; an open issue is not proof of an active exploit.",
      "chapter": "github-graveyard-section",
      "chapter_label": "Public issue record",
      "source_row": 360,
      "reference_check": "The retrieved GitHub page matches the saved title, opening date, core allegation and open state. The alleged exploit was not reproduced.",
      "body": "Since now 1 year, there is an en-masse scam operation taking place on all Source based games platforms.\nThe server is called Fastpath\n\nThey have found a way to exploit players steam auth tickets, keeping them long after the players have disconnected.\nMaking their servers look packed. \nOn each game platform they have created over 1000 fake silent redirect servers. Rendering this a mass scale operation.\nThis on repeat is emptying all legitimate servers. Making the few real ones impossible to find, lost in a sea of fake servers.\n\nThis operation has many facets, \nI will list a few here:\n- All players names are copied and re assigned to bots once they leave\n- All their fake servers have names copied from other servers\n- They ban players and demand money to unban\n- Threats of shutting down servers if monies are not received\n\nCould the exploit of steam auth tickets be patched. (I guess an extra timeout method must be added)\nCould the scammer's IP addresses be banned from Source games\n\n\n![stolenservernames](https://user-images.githubusercontent.com/66415427/155857368-0fe6ba16-47a0-490b-8a54-c545fd677ef5.jpg)\n\n![website](https://user-images.githubusercontent.com/66415427/155857020-b459c60c-bb10-4b49-8e11-822a97ec1a51.jpg)\n\n",
      "source_file": "valve_ignored_bugs.json",
      "body_sha256": "d3dcb33cdf4e70501d6f1aeee35722b1682ef58f1df018789a8ae2c673755932",
      "archive_url": "steam_evidence_archive.html?source=GitHub&record=768"
    },
    {
      "id": 4533,
      "source": "Reddit",
      "collections": [
        "Master CSV"
      ],
      "copies": 1,
      "title": "Funds stolen through steam market. Disappointed with Steam response.(or lackthereof)",
      "excerpt": "On 6th July 2022, 44 unauthorized transactions were made on the steam market using my steam wallet funds totalling roughly $500+ USD to buy worthless 1 cent Dota 2 items. This happened during the wee hours in the morning and i contacted them first thing when i",
      "url": "https://www.reddit.com/r/DotA2/comments/vt76ov/funds_stolen_through_steam_market_disappointed/",
      "author": "fearedhouse3",
      "date": "2022-07-07",
      "related": true,
      "removed": false,
      "category": "Support Ticket Dispute: \"steam support\" copy paste",
      "original_source": "Reddit Submission (r/DotA2)",
      "key": "rd-01",
      "archive_id": 4533,
      "support_id": "market-loss",
      "label": "44 disputed Market purchases",
      "kind": "First-person account",
      "context": "r/DotA2 · u/fearedhouse3",
      "summary": "The author reports 44 unauthorized Market purchases on 6 July 2022 and roughly $500+ in losses. They say two-factor authentication was enabled and describe repeated template replies from support.",
      "quote": "2nd ticket in and I have still yet to receive a non robotic copy paste template response from Steam.",
      "establishes": "A dated account of disputed purchases, with links to transaction screenshots and a support response. The amounts and events are the author’s report.",
      "question": "What do the transaction and session logs show, and how did support assess them? The post does not determine how access was obtained.",
      "chapter": "enforcement-standard",
      "chapter_label": "Support and enforcement",
      "reference_check": "The retrieved Reddit page contains the matching post and links to the submitted screenshots. Those linked images were not independently authenticated.",
      "body": "On 6th July 2022, 44 unauthorized transactions were made on the steam market using my steam wallet funds totalling roughly $500+ USD to buy worthless 1 cent Dota 2 items. This happened during the wee hours in the morning and i contacted them first thing when i woke up.   I have 2FA enabled all the time, and always thought this would not happen to me as I do not go on betting sites/click sketchy links. My account password + emails were not changed, nor did they take my inventory, just that my funds were used illicitly. Also when I went to disable other APIs, it says there are no other APIs to disable. Shows that it wasn't through me clicking sketchy links and leaving my account details there. Would have lost the whole account if i did so.  What baffles me is how did they bypass my 2FA to login my account? Why doesn't steam market purchases go through 2FA as well? First time in 9 years that this happened to me. My acc was logged in 'BY' 'Vitebsk' during the illicit purchases but I'm based in Asia I gathered all the screenshots and provided in the ticket to steam support.   All i got was the standard copy paste template reply by Steam Support. Lost $500+ and was not even worthy of having a proper person to look into this. I dont think they even read or take a look at the screenshots cause if they did, they would have come to the realization that what happened was clearly fraud, and with a few clicks, reverse the unauthorized transactions, refund my wallet and ban the hijacker.    Over the years, i've spent quite a fair bit on steam but really, this is the kind of recourse we get when our account is compromised? They just don’t care, sigh. I only expect the bare minimum from Steam and looks like even that is quite far-fetched.  SS: https://imgur.com/a/67frcls   Hijacker: https://steamcommunity.com/profiles/76561199141246495  Steam Response: https://imgur.com/a/V6v4maM  I could think of a few ways on how to Improve:  1) Add 2FA to market transactions. (even if its bulk posting or selling of items, just 1 2FA notif is required)  2) Enable accounts to be region locked. (if you are migrating, then have to go through steam support etc)  3) Additional Lock on Steam Wallet. (Another password perhaps?)  EDIT: 2nd ticket in and I have still yet to receive a non robotic copy paste template response from Steam.",
      "source_row": 45,
      "source_file": "steam_support_tickets_MEGA.json",
      "body_sha256": "5a3d6a42b59c80774b006981b1ee182edc8e6954b8ad5af9e109710e3b3a3c41",
      "archive_url": "steam_evidence_archive.html?source=Reddit&record=4533"
    },
    {
      "id": 4766,
      "source": "Reddit",
      "collections": [
        "Master CSV"
      ],
      "copies": 1,
      "title": "Permanently banned Steam account without a clear explanation, need help!",
      "excerpt": "Hey everyone, I’m in a really frustrating situation, and I’m hoping someone here can help me or offer advice. My Steam account was just permanently banned for allegedly violating the Steam Subscriber Agreement, and I have no idea why. # What Steam Support told",
      "url": "https://www.reddit.com/r/ohnePixel/comments/1hahqx2/permanently_banned_steam_account_without_a_clear/",
      "author": "Hopeful_West7911",
      "date": "2024-12-09",
      "related": true,
      "removed": false,
      "category": "Support Ticket Dispute: \"steam support\" ticket",
      "original_source": "Reddit Submission (r/ohnePixel)",
      "key": "rd-02",
      "archive_id": 4766,
      "support_id": "ban-review",
      "label": "A permanent ban and closed appeals",
      "kind": "First-person account",
      "context": "r/ohnePixel · u/Hopeful_West7911",
      "summary": "The author disputes a permanent ban and says support cited suspected account transfer and community reports. They describe closed tickets and plans to request their personal data.",
      "quote": "I explained my situation and asked for more details, but they’re sticking to their decision and closing my tickets.",
      "establishes": "A preserved appeal account, including the reasons the author says support supplied and links to four images. The post date comes from the selected support export.",
      "question": "What evidence supported the ban, and what review was available? The post alone cannot establish whether the sanction was justified.",
      "chapter": "dsar-playbook",
      "chapter_label": "Request the underlying records",
      "reference_check": "The retrieved Reddit page matches the author, title, appeal account and four image links. The author’s claims were not independently adjudicated.",
      "body": "Hey everyone,  I’m in a really frustrating situation, and I’m hoping someone here can help me or offer advice. My Steam account was just permanently banned for allegedly violating the Steam Subscriber Agreement, and I have no idea why.  # What Steam Support told me:  The support message said my account was banned due to:  * Suspicious activities related to transferring or attempting to sell/trade the account. * Community reports and other unspecified factors.  They added that the ban is permanent and that they can't help me further. They also warned that future support requests regarding this ban might be ignored. 😞  # Why I’m contesting this ban:  * I have never sold, traded, or transferred my account. I’ve been the legitimate owner since the beginning. * On the day the ban occurred, I did nothing noteworthy that could have triggered such a sanction. * I received no prior warning, which feels incredibly unfair.  # What I’ve tried so far:  * Contacting Steam Support: I explained my situation and asked for more details, but they’re sticking to their decision and closing my tickets. * I’m preparing a request based on my Right of Access (GDPR) to get all the data related to my account.  # Questions for the community:  1. Has anyone successfully had a permanent ban lifted on Steam? 2. Are there steps I can take to prove I’m the legitimate owner of the account? 3. Any advice on how to word my request to convince support to reconsider my case? 4. Would it be helpful to contact the CNIL (I’m based in France) to force Steam to provide more information?  I’m really desperate at the thought of losing all my games, purchases, and years of playtime. Thanks in advance for any help and advice you can give!  https://preview.redd.it/jk9qv0gmhv5e1.png?width=1289&amp;format=png&amp;auto=webp&amp;s=b3a333ebb08ea133e2c8747ba126f5a68283d9f7  https://preview.redd.it/4sopt0gmhv5e1.png?width=1022&amp;format=png&amp;auto=webp&amp;s=56195d5336118faf9413f1514ead7e8d24c788c3  https://preview.redd.it/eqrxw0gmhv5e1.png?width=996&amp;format=png&amp;auto=webp&amp;s=ff3539d28ab754e513ad471822c5de652920101d  https://preview.redd.it/728xz0gmhv5e1.png?width=1034&amp;format=png&amp;auto=webp&amp;s=bc5335673509929669af785aa244bf8d2dc58da8  ",
      "source_row": 294,
      "source_file": "steam_support_tickets_MEGA.json",
      "body_sha256": "b4d22d96cedada1ac44932b33943eac6897ff90d5d96c48fcf9d39ab98d6e46d",
      "archive_url": "steam_evidence_archive.html?source=Reddit&record=4766"
    },
    {
      "id": 4592,
      "source": "Reddit",
      "collections": [
        "Master CSV"
      ],
      "copies": 1,
      "title": "Got $10k stollen from steam inventory due to steam' support fault.",
      "excerpt": "Location: Quebec, Canada. Last year, someone hacked my Steam account and stole items worth about $10,000 USD. I only noticed this last week. When I talked to Steam Support, they admitted that someone submitted a ticket to make changes on the account and Steam ",
      "url": "https://www.reddit.com/r/legaladvice/comments/1kipjde/got_10k_stollen_from_steam_inventory_due_to_steam/",
      "author": "victornb",
      "date": "2025-05-09",
      "related": true,
      "removed": false,
      "category": "Support Ticket Dispute: \"steam support\" recovery",
      "original_source": "Reddit Submission (r/legaladvice)",
      "key": "rd-03",
      "archive_id": 4592,
      "support_id": "support-recovery",
      "label": "A recovery reset and a reported $10,000 loss",
      "kind": "First-person account",
      "context": "r/legaladvice · u/victornb",
      "summary": "The author alleges that support reset credentials and disabled account protections after someone else submitted a recovery ticket. They report a loss of about US$10,000 from an inactive account.",
      "quote": "Steam Support reset my password and turned off all my account security.",
      "establishes": "A preserved allegation about the recovery process overriding account safeguards. The saved post records what the author says support told them.",
      "question": "Who authorized the reset, on what ownership evidence, and with which audit trail? The support transcript and reset logs are not included in this post.",
      "chapter": "support-corruption-case-study",
      "chapter_label": "Account-recovery powers",
      "reference_check": "A fresh Reddit page could not be retrieved during this review. This selection relies on the supplied saved text; the fetch failure is not evidence that the post was deleted.",
      "body": "Location: Quebec, Canada.  Last year, someone hacked my Steam account and stole items worth about $10,000 USD. I only noticed this last week. When I talked to Steam Support, they admitted that someone submitted a ticket to make changes on the account and Steam Support reset my password and turned off all my account security.  I asked Steam Support about getting my items back, but they said there was nothing they could do. They told me I should follow their security recommendations.  The problem is, I did everything they \"suggested\" to protect an account:  * I had two-factor authentication. * My phone number was connected to my account. * I used Steam Guard. * I printed recovery codes and kept them in a safe.  Even though I did all these things, Steam Support still gave someone else access to my account. The stolen items had been in my account since around 2016-2017. Also, I had not logged in for a few years, so I didn’t accidentally give my information to a fake website.  Is there anything I can do, or do I just have to accept losing $10,000 USD?  Thanks for your help.",
      "source_row": 110,
      "source_file": "steam_support_tickets_MEGA.json",
      "body_sha256": "c9465d7fce0e160e549b99d96b978dbaaac4d93a7a30764e0fc3789284b526fc",
      "archive_url": "steam_evidence_archive.html?source=Reddit&record=4592"
    }
  ]
}