Short answer: Valve said Steam itself was not breached. Its May 14, 2025 clarification described older SMS messages containing Steam one-time codes and destination phone numbers—not Steam passwords, payment data, or a confirmed list of 89 million accounts. The codes were valid for only 15 minutes, and Valve said users did not need to change their Steam password or phone number because of this event.
- Enable Steam Mobile Authenticator.
- Secure the email account linked to Steam.
- Review authorized devices and recent account activity.
- Treat unexpected “Steam leak” messages as likely phishing.
What the “89 million Steam accounts leaked” headline gets wrong
The alarmist headline refers to reports and Valve’s response from May 14, 2025, not a new August 2026 breach. The available evidence does not establish that 89 million valid Steam accounts, passwords, or complete account records were exposed.
Valve said its examination of a sample found older SMS messages containing Steam one-time codes and the phone numbers to which those messages were sent. It said the material did not come from a breach of Steam systems, while noting that SMS messages pass through multiple external providers and are unencrypted in transit. Read Valve’s clarification at Steam News.
That distinction matters: a leak of messages that Steam previously sent is not the same as an intrusion into Valve’s account database, and “89 million account details” implies evidence that has not been established.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
What Valve said was in the exposed sample
| Material | What Valve’s statement establishes |
|---|---|
| SMS records | Older text messages containing Steam one-time authentication codes. |
| Phone numbers | The numbers that received those messages. |
| Steam-account links | Valve said the examined data did not associate the numbers with Steam accounts. |
| Passwords and payment data | Valve said the sample contained neither Steam passwords nor payment information. |
| Other personal data | Valve said it found no other personal data in the examined sample. |
Valve also said the information was insufficient to identify which Steam account, if any, belonged to a particular phone number. The exact size of the alleged dataset, its original source, and whether every record was genuinely connected to Steam remain unverified.
Could old leaked codes be used to access your account?
Valve said Steam’s SMS codes were valid for only 15 minutes. A historical message containing an expired code does not provide a usable current login code.
A normal login still requires the account password, and Steam’s account-change process adds confirmation through email and/or Steam secure messages when someone attempts to change an email address or password. The reported material therefore does not establish that attackers obtained the credentials needed for a normal login or bypassed Steam Guard.
That does not make every account safe from every attack. A current phishing page, a compromised email account, malware, an exposed browser session, or an attacker who obtains and uses a password can create a separate risk.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Should you change your Steam password?
Not because of this incident alone. Valve explicitly said users did not need to change their Steam passwords or phone numbers as a result of the event. That advice is specific to the reported SMS exposure, not a claim that password changes are generally unnecessary.
Change it when the credential has another problem
- You reuse the password on email or another service.
- It is short, predictable, old, or shared with anyone else.
- You clicked a suspicious Steam-related link or entered credentials into an unfamiliar page.
- Your password manager reports that the credential appeared in another breach.
- You see an unfamiliar device, changed account email, unauthorized trade, suspicious purchase, or other sign of takeover.
Use a unique password generated and stored in a reputable password manager if that fits your setup. A password change cannot replace multifactor authentication, email security, malware cleanup, or session revocation.
Five-minute Steam security checklist
1. Enable the Steam Mobile Authenticator
Valve recommends the Steam Mobile Authenticator for confirming logins, trades, and Steam Community Market listings. It adds a second-device approval requirement, making unauthorized access substantially harder even if someone learns your password. Details are on Valve’s Steam Guard Mobile Authenticator page.
Install the official Steam app through your device’s normal iOS or Android app store. Do not follow an app-install link sent in an unsolicited message.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
2. Secure the email account connected to Steam
Valve identifies compromised email accounts as a common route to Steam takeover: an attacker can use email access to reset the Steam password and replace the account email address. On your email account:
- Set a unique password that is not your Steam password.
- Enable the provider’s strongest available multifactor authentication.
- Review recent sign-ins, connected devices, recovery addresses, and forwarding rules.
- Remove unfamiliar sessions, apps, or forwarding destinations.
Valve also lists password reuse, malware, fake updates or game tools, and browser or operating-system exploits among common attack routes. The same guidance appears on its Steam security page.
3. Review authorized Steam devices
Open Valve’s authorized-devices page directly: https://store.steampowered.com/account/authorizeddevices. Revoke or sign out any device you do not recognize. If one appears, change the Steam password from the official Steam client or website, secure your email account, and contact Steam Support through its official site.
4. Check account activity
Look for trades, Community Market listings, purchases, Wallet changes, and account-email changes you did not initiate. Keep screenshots and transaction details if you need to contact Support.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
5. Reject unexpected approvals
Never approve a Steam login or mobile-authenticator prompt you did not start. An unexpected prompt is a warning that someone may be trying to use your password or session.
Why the phone-number angle still matters
A leaked phone number can attract spam, scam calls, and targeted phishing. It does not, by itself, prove that the number was matched to a Steam account; Valve said the examined records did not make that association.
SMS authentication depends on the phone network and is more exposed to telecom and social-engineering risks than an authenticator app. Do not remove a recovery number impulsively if doing so could make account recovery harder. Instead, follow Steam’s current recovery guidance and add the stronger authenticator where available.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How follow-up phishing may look
The publicity around a supposed breach gives scammers a convincing pretext. Be suspicious of messages claiming:
Best Value
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
- “Your Steam account was in the 89-million leak.”
- “Verify your password to stay protected.”
- “Your inventory will be locked unless you act now.”
- “Contact a Steam administrator on Discord.”
- “Install this security tool or recovery app.”
Navigate to Steam manually instead of clicking unsolicited links. Valve’s announcement advises treating account-security messages you did not request as suspicious. Steam will not ask you to send a password, Steam Guard code, recovery code, or payment details to a supposed moderator.
If you already clicked a suspicious link
- Close the page and stop entering information. Disconnect the device from the network if malware may have run.
- From a trusted device, change the Steam password through the official Steam site or client.
- Change the password anywhere else that reused the same credential.
- Secure the associated email account and remove unknown sessions, forwarding rules, and connected apps.
- Revoke unfamiliar Steam authorized devices.
- Check trades, Market listings, purchases, Wallet activity, and the account email address.
- Scan the device if you downloaded or installed software, including a fake update or game tool.
- Contact Steam Support through the official Steam support site if you are locked out or see unauthorized activity.
- Warn contacts if the compromised account sent them messages or links.
Do not send credentials or security codes to anyone offering “recovery” through Discord, social media, or a chat message.
What Steam Guard protects—and what it does not
Mobile authentication materially reduces the chance that a stolen password alone will complete a protected login, trade, or Market action. It is not an invulnerability switch. Attackers can still target the email account, phone number, device, browser session, or the user through a convincing phishing page. Multifactor prompts you did not initiate should be treated as evidence of a possible attack, not approved as a nuisance.
Tools that can help
The first-line protection is free and first-party: Steam Mobile Authenticator. A password manager can help you create a unique Steam password and prevent reuse. Free browser- or device-integrated managers may be sufficient for one person; paid services can add cross-platform sharing, recovery, monitoring, or family features. No paid manager is required because of this incident, and no service can prove that a particular user appeared in the unverified dataset.
The Bottom Line
The “89 million Steam accounts leaked” headline was not confirmed by Valve. Its May 2025 statement described older SMS records and expired one-time codes, not a Steam-system breach or exposed password database. You do not need an emergency password reset solely for this event; secure your email, enable Steam Mobile Authenticator, review authorized devices, and ignore urgent leak-themed messages.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




