Valve apologizes for "Steam's troubled Christmas"

Steam

After almost a week of silence, Valve has issued an apology for the leak of private user information on Steam that took place just prior to Christmas, along with an explanation of what went wrong. The problem, which affected approximately 34,000 users, was the result of a caching error that arose out of a denial of service attack against Steam.

“Early Christmas morning (Pacific Standard Time), the Steam Store was the target of a DoS attack which prevented the serving of store pages to users. Attacks against the Steam Store, and Steam in general, are a regular occurrence that Valve handles both directly and with the help of partner companies, and typically do not impact Steam users. During the Christmas attack, traffic to the Steam store increased 2000% over the average traffic during the Steam Sale,” Valve explained in a statement posted on Steam.

“In response to this specific attack, caching rules managed by a Steam web caching partner were deployed in order to both minimize the impact on Steam Store servers and continue to route legitimate user traffic. During the second wave of this attack, a second caching configuration was deployed that incorrectly cached web traffic for authenticated users. This configuration error resulted in some users seeing Steam Store responses which were generated for other users. Incorrect Store responses varied from users seeing the front page of the Store displayed in the wrong language, to seeing the account page of another user.”

The leaked information varied by page request but included users' billing address, the last four digits of Steam Guard phone numbers, purchase history, the last two digits of credit card numbers, and/or email addresses. Full credit card numbers, passwords, or “enough data to allow logging in as or completing a transaction as another user” were not included among the erroneous cache requests, and users who weren't browsing the Steam store during that specific time frame were not affected.

Valve said it is continuing to work with the involved web caching partner to identify users impacted by the leak and improve its processes to ensure this doesn't happen again. “We apologize to everyone whose personal information was exposed by this error, and for interruption of Steam Store service.”

TOPICS
Andy Chalk
US News Lead

Andy has been gaming on PCs from the very beginning, starting as a youngster with text adventures and primitive action games on a cassette-based TRS80. From there he graduated to the glory days of Sierra Online adventures and Microprose sims, ran a local BBS, learned how to build PCs, and developed a longstanding love of RPGs, immersive sims, and shooters. He began writing videogame news in 2007 for The Escapist and somehow managed to avoid getting fired until 2014, when he joined the storied ranks of PC Gamer. He covers all aspects of the industry, from new game announcements and patch notes to legal disputes, Twitch beefs, esports, and Henry Cavill. Lots of Henry Cavill.

Latest in Platforms
midnight murder club
Five new Steam games you probably missed (March 17, 2025)
Screenshot of Children of Clay showing a mysterious clay model
Five new Steam games you probably missed (March 10, 2025)
discord
Brace yourself for Discord to get worse: Reports swirl that the company is in talks with bankers about opening itself up to shareholders
The Spy from Team Fortress 2 holds up a folder with an accusatory expression.
Steam users react ecstatically to update that lets them access their heaving game notes via the web, also it fixes Monster Hunter Wilds video recording
HasanAbi
Twitch streamer Hasan Piker suspended after saying Republicans would 'kill Rick Scott' if they really cared about Medicare fraud
Screenshot from Faceminer showing a PC desktop with several windows open
Five new Steam games you probably missed (March 3, 2025)
Latest in News
Uplifted chimp Penn and cyber-rat Trip in the key art for Animal Use Protocol
Animal Use Protocol's dysfunctional chimp-rat alliance drags the Stasis series into a horrible new first-person era
A woman with short hair stands next to a pot plant, provocatively
GOG's version of Silent Hill 4 has been updated with missing content from the original console game
A blue dragon rises into storm clouds
Wizards of the Coast throws a bone to players who miss vanilla Magic: The Gathering with a dragon-themed set called Tarkir: Dragonstorm
Lonely Mountains: Snow Riders
Lonely Mountains: Snow Riders is getting a new mountain next month and a whole bunch more throughout the year, including a game editor
Lady smiling with the sun in her face
Clair Obscur: Expedition 33's director was 'starving for new turn-based RPGs,' and figured if he wanted them, there would be others out there who'd want to play his game
farcana
'The Middle East's answer to Marvel Rivals' is an 'AI-powered', crypto-infused hero shooter that looks like hot garbage