Valve said on May 14, 2025, that the reported leak involving approximately 89 million Steam-related records did not come from a breach of Steam’s systems. Valve said the sample it examined consisted of older SMS messages containing phone numbers and one-time codes that were valid for only 15 minutes—not Steam passwords, payment information, or data linking those phone numbers to Steam accounts. Read Valve’s statement.
What was the alleged Steam leak?
The alarm began with reports that a threat actor was offering roughly 89 million records for about $5,000. The seller and some early headlines described the material as Steam account details, creating the impression that Steam usernames, passwords, payment data, or two-factor authentication records had been stolen from Valve.
As an Amazon Associate I earn from qualifying purchases.
However, the size and contents of the full dataset were not independently established. Subsequent reporting described a sample that appeared to contain SMS-based Steam Guard messages and related delivery metadata. That is materially different from a verified dump of 89 million Steam accounts.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →The phrase “account details” is also ambiguous. It can refer to account IDs, usernames, phone numbers, SMS contents, one-time codes, email addresses, passwords, payment details, public profile information, or internal messaging metadata. The evidence described by Valve supports the narrower category of older SMS records, not a confirmed exposure of Steam credentials.
#1 Best Overall
- [AI Smart Speaker] You can use tozo pm1 speaker to AI Chat by connect with TOZO APP, you can literally Talk to it like a real person, rather than just typing and reading on a screen. It’s perfect for hands-free assistance, learning, and entertainment.
- [Intelligent Meeting Assistant] Recording + real-time transcription: one-click recording, stopping as you go, AI real-time conversion of voice messages into text recordings, and automatically analyzing the recording/text content, intelligently refining the key points, action items, and conclusions, and also translating into multiple languages with one click.
- [Excellent Sound Quality] Experience studio-grade clarity with our precision-engineered 28mm dynamic driver. Delivering 30% louder output and deeper bass resonance, it captures every nuance—from crisp highs to rich mid-ranges, ensuring vibrant, distortion-free sound whether you’re streaming music, or voice call.
- [Up to 20H Playtime] Bluetooth speaker has a built-in robust rechargeable battery. Up to 20 hours playtime, ensuring continuous, uninterrupted playback, whether you use the speaker for lectures, work conversations, or listening to music while running outdoors, etc.
- [Unleash Your Hands] Clip-On Convenience make it secure the rugged built-in clip to jackets, backpacks, or belts, room-filling music or take calls hands-free, perfect for hiking, cycling, or busy workdays.
Windows Central’s contemporaneous report is useful for the original sale allegation and chronology, but the seller’s claims should not be treated as independent confirmation of the entire database.
What Valve actually confirmed
Valve said it examined a sample of the material and concluded that it was not a breach of Steam systems. According to Valve, the sample consisted of older text messages previously sent to Steam users. Those messages included:
- Phone numbers to which the messages were sent
- One-time authentication codes
- Information associated with SMS delivery
Valve said the codes were valid for only 15 minutes. It also said the sample did not associate phone numbers with Steam accounts and did not contain Steam passwords, payment information, or other personal data.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemsValve further said that old messages could not be used to breach Steam accounts. If someone attempted to use SMS-based recovery to change a Steam email address or password, Valve said the change would require confirmation through email and/or Steam secure messages.
That assessment is specifically about the sample Valve examined. It does not authenticate every record allegedly offered for sale, and it does not identify the precise source of the leaked SMS material. Valve’s public statement did not name a carrier, messaging provider, contractor, or other vendor as the cause.
Was Steam breached?
Based on Valve’s May 14, 2025 assessment, there is no confirmed evidence that Steam’s own systems were breached in the incident described by the reports.
Rank #2
- Your favorite music and content – Play music, audiobooks, and podcasts from Amazon Music, Apple Music, Spotify and others or via Bluetooth throughout your home.
- Alexa is happy to help – Ask Alexa for weather updates and to set hands-free timers, get answers to your questions and even hear jokes. Need a few extra minutes in the morning? Just tap your Echo Dot to snooze your alarm.
- Keep your home comfortable – Control compatible smart home devices with your voice and routines triggered by built-in motion or indoor temperature sensors. Create routines to automatically turn on lights when you walk into a room, or start a fan if the inside temperature goes above your comfort zone.
- Do more with device pairing – Fill your home with music using compatible Echo devices in different rooms, or create a home theatre system with Fire TV.
- Say goodbye to drop-offs and buffering - With eero Built-in, Echo Dot doubles as a mesh wifi extender, adding up to 1,000 sq. ft. of wifi coverage to your existing eero network.
The most accurate description is:
A leak of Steam-related SMS records was reported, but Valve said its investigation found no breach of Steam systems and no exposure of Steam passwords, payment information, or account-linked personal data in the sample it examined.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
This distinction matters because SMS messages can pass through multiple telecommunications and messaging systems. Valve acknowledged that SMS messages are unencrypted in transit and routed through multiple providers. That makes a third-party messaging or telecommunications exposure consistent with Valve’s explanation, but the official statement did not establish exactly where the exposure occurred.
| Claim | What the available evidence supports |
|---|---|
| “89 million Steam accounts were breached” | Unverified allegation rejected by Valve’s assessment of the sample |
| Steam-related records were offered for sale | Reported, with an alleged price of approximately $5,000 |
| Older Steam-related SMS messages leaked | Consistent with Valve’s description of the sample |
| Steam passwords or payment details leaked | Valve said the sample did not contain them |
| Phone numbers were linked to Steam accounts | Valve said the sample did not make that association |
| The precise source was identified | Not identified in Valve’s cited statement |
Could the leaked codes take over Steam accounts?
Valve said the old codes were valid for only 15 minutes and could not be used to breach Steam accounts. A stale one-time code is not equivalent to a current login credential, particularly when the associated Steam password and account mapping are absent.
A phone number alone also does not prove which Steam account it belongs to. Valve specifically said the sample did not associate the exposed numbers with Steam accounts.
That does not mean the wider phishing risk disappeared. Someone with access to old phone numbers or SMS content might use the information to make a scam look convincing. Attackers could send messages claiming to be Steam Support, warning about a suspicious login, or directing users to a fake account-recovery page.
Account takeover remains possible through separate problems, including:
Rank #3
- Meet Echo Dot Max: Experience rich room-filling sound that automatically adapts to your space and fine-tunes playback. Features a built-in smart home hub and Omnisense technology for highly personalized experiences.
- Music to your ears: With nearly 3x the bass versus Echo Dot (2022 release), it fits beautifully in any space, delivering your personal sound stage with deep bass and enhanced clarity. Listen to streaming services, such as Amazon Music, Apple Music, Spotify, and SiriusXM. Encore!
- Do more with device pairing: Connect compatible Echo smart speakers and smart displays in different rooms, or pair with a second Echo Dot Max to enjoy even richer sound
- Simple smart home control: Set routines, pair and control lights, locks, and thousands of smart home devices that work with Alexa without needing a separate smart home hub. With Omnisense technology, you can activate routines via temperature or presence detection.
- Say goodbye to drop-offs and buffering - With eero Built-in, Echo Dot Max doubles as a mesh wifi extender, adding up to 1,000 sq. ft. of wifi coverage to your existing eero network.
- A compromised email account
- Password reuse on another service
- Malware, keyloggers, spyware, or malicious browser extensions
- A stolen Steam Guard file or active browser session
- Phishing on a fake Steam login page
Those are general account-security risks, not evidence that the May 2025 SMS leak contained Steam passwords.
What Steam users should do now
Valve said users did not need to change their Steam passwords or phone numbers specifically because of this event. A password reset is therefore not mandatory solely because of the reported leak. Nevertheless, users should take the following steps if anything about their account looks unusual.
1. Review authorized devices
Open Steam’s Authorized Devices page and look for unfamiliar phones, computers, browsers, or sessions. Steam Support also recommends reviewing authorized access and using Sign out everywhere if you find anything you do not recognize. See Steam’s account-security recommendations.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →2. Change your password when there is an independent reason
Change your Steam password if you reused it elsewhere, received an unexpected security notification, saw an unfamiliar login, noticed an unauthorized purchase or trade, clicked a suspicious link, or suspect malware or email compromise.
If the password was reused, change it everywhere it appears—starting with the email account associated with Steam. Use a unique password for Steam and do not enter it on sites reached through unsolicited messages.
3. Secure the associated email account
Steam identifies a compromised associated email account as a common route to account takeover. Use a unique email password and enable your email provider’s two-factor authentication. An attacker who controls the email account may be able to intercept recovery messages even if the Steam account itself was not part of this incident.
Rank #4
- Hi‑Res Audio, Expertly Tuned – Enjoy up to 24‑bit/192 kHz Hi‑Res streaming, powered by a 100W peak amplifier, 4″ paper‑cone woofer and dual 1″ silk‑dome tweeters for natural mids, smooth highs, and room‑filling clarity.
- Smarter in Any Room - AI RoomFit technology optimizes the sound to your specific space and placement—balanced bass, clean vocals, and engaging detail wherever you place it.
- Open by Design - Stream in the WiiM Home App or cast directly via Google Cast, Spotify/TIDAL/Qobuz Connect, Alexa Cast, DLNA, Roon/LMS; join WiiM, Google Cast, Alexa multi‑room groups.
- Stereo & Cinema‑Ready - Pair two for true L/R stereo; add WiiM Sub Pro for deeper, tighter bass or combine with compatible WiiM components as center/surround for an immersive home‑theater setup.
- Control made simple – Manage playback and settings easily through the WiiM Home App, voice control via Alexa or Google Assistant (with compatible devices), and physical buttons on the speaker—streamlined design, no screen or remote needed.
4. Enable the Steam Mobile Authenticator
Valve recommended the Steam Mobile Authenticator as the preferred way to receive secure account messages. Users who currently rely on SMS can review the official Steam Guard guidance and consider moving to the mobile authenticator.
Recommended Free Tools
This recommendation should not be overstated: Valve did not say that every account using SMS-based Steam Guard was compromised, nor did it announce that SMS authentication had been disabled.
5. Scan devices before changing credentials after a suspected takeover
If you believe the account was actually compromised, scan your computer and phone for malware, keyloggers, spyware, malicious applications, and unsafe browser extensions. Steam’s recovery guidance emphasizes securing the computer and email account before recovering the account, because changing a password on an infected device may not solve the problem.
6. Use only official Steam support
Go directly to help.steampowered.com rather than clicking a link in an email, SMS, Discord message, or chat. Valve says its employees will not resolve account issues through Steam Chat, Discord, or other chat systems. Steam Support representatives will not ask for your account password.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What to do if you receive a suspicious Steam message
- Do not click links or reply.
- Open the Steam client or type the official support address yourself.
- Check authorized devices and recent account activity.
- Secure your email account if the message concerns a password or email change.
- Change credentials only from a trusted, malware-free device when there is a genuine reason.
An unexpected authentication message is worth investigating, but it does not prove that your credentials were exposed in this incident. It may be a phishing attempt, a mistaken login attempt, or a separate security event.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWhat remains unknown?
Valve’s statement addressed the sample it reviewed, not every claim attached to the advertised 89-million-record dataset. The public information cited here does not establish:
Best Value
- Powered by a 47% faster processor, the next-gen dual-tweeter acoustic architecture produces detailed stereo separation while a 25% larger midwoofer deepens the bass.¹
- Place this speaker anywhere and everywhere you want to listen. The compact design fits beautifully on your bookshelf, kitchen counter, desk, or nightstand.
- Stream from all your favorite services over WiFi. Pair a Bluetooth device with the press of a button. Connect a turntable or other audio source using an auxiliary cable and the Sonos Line-In Adapter.²
- Go from unboxing to unbelievable sound in just a few minutes. Simply plug in the power cable, connect your phone or tablet to WiFi, and open the Sonos app.
- With a tap in the Sonos app, Trueplay tuning technology analyzes the unique acoustics of your space and optimizes the speaker’s EQ. So all your content sounds just the way it should.
- Whether the full advertised dataset contained exactly 89 million records
- Who obtained or exposed the SMS material
- Which telecommunications or messaging systems, if any, were involved
- Whether every record in the advertised collection matched the sample
It is therefore inappropriate to assign blame to a named SMS provider or carrier without additional verified evidence. It is equally inappropriate to repeat claims that Steam passwords, credit-card numbers, or current authentication codes were leaked when Valve explicitly said those details were absent from the sample it examined.
Do not confuse this story with the later Valve hardware logistics incident
This May 2025 Steam SMS story is separate from later reports about an August 2026 cyberattack involving a logistics provider and shipping information for some Valve hardware customers. That separate incident concerns shipment data, not the alleged 89-million-record Steam leak. The two stories should not be merged when assessing account security.
Bottom line
The “89 million Steam accounts breached” headline goes beyond the evidence available. Valve said on May 14, 2025, that its sample contained older SMS messages with phone numbers and short-lived one-time codes, not Steam passwords, payment information, or phone-number-to-account mappings.
Free tools Windows power users keep installed
One-click scans. No signup required.
Steam users do not need to change their password or phone number solely because of this report. They should still review authorized devices, secure their email, consider enabling the Steam Mobile Authenticator, scan suspicious devices, and ignore anyone claiming to be Steam Support through chat or Discord.
Frequently Asked Questions
Did Steam suffer an 89-million-account data breach?
Valve said on May 14, 2025, that the sample it examined was not from a breach of Steam systems. The reported material consisted of older SMS records, and the full 89-million-record claim was not independently verified.
Were Steam passwords or credit-card details leaked?
Valve said the sample did not contain Steam passwords, payment information, or other personal data, and did not link phone numbers to Steam accounts.
Should I change my Steam password?
Not solely because of this incident. Change it if you reused the password, saw suspicious account activity, clicked a phishing link, or suspect email or device compromise.
Can old Steam SMS codes be used to hijack an account?
Valve said the codes were valid for only 15 minutes and that old messages could not be used to breach Steam accounts. Phishing and separate compromises remain possible risks.
The Bottom Line
Bottom line: A Steam-related SMS leak was reported, but Valve said it was not a breach of Steam systems. No confirmed exposure of Steam passwords, payment information, or linked account data was described in the sample Valve examined. Check your authorized devices and secure your email, but do not panic-reset your phone number or password solely because of this report.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




