Article translationsRead this investigation in your language24 official EU languages · English is the source text · translated with DeepL and hosted by PhishDestroy
Editorial illustration of machinery crushing an EU flag and producing game skins and cashEditorial illustration
Exclusive investigation

The Steam Illusion: How Valve Operates a Shadow Economy, Enables Data Theft, and Ignores International Law

PhishDestroy ResearchAugust 12, 2026Updated August 12, 202615 min read
−53%Terraria: Russia vs US list price
15%Community Market commission cited
29 Jul–1 AugCEVA attack window
Article 15GDPR access right
Investigation in brief

What does this report allege?

This independent investigation strips away the curated, consumer-friendly facade of Valve Corporation. We reject the obfuscated, defensive corporate rhetoric designed to mask systemic compliance failures, user exploitation, and internal misconduct. Supported by public records, legal filings, and direct technical analysis, this report exposes Steam's transformation into an unregulated, highly lucrative digital shadow economy built on the following facts:

  • A Platform for Crime:

    Steam's untaxed in-game skin market operates as a ubiquitous darknet money laundering machine, with a shadow turnover estimated between $1 billion and $4 billion in 2025 alone.

  • The Skin Ban Hoard:

    Valve systematically refuses to return stolen items or accounts to fraud victims; instead, they permanently freeze banned inventories, effectively hoarding stolen digital assets within their own ecosystem to boost skin rarity and drive up their 15% transaction fee revenue.

  • Legal Intimidation:

    Valve retaliates against users seeking legal aid. Their Subscriber Agreement historically stated that appealing to independent legal protection or filing a class-action lawsuit would result in Valve deleting the user's account and erasing their entire library.

  • Sovereign Priorities:

    Valve respects exactly one US court in Washington and any state censorship agency in Russia, submitting fully to Russian courts in their Terms of Service.

  • The Outsourced Cartel:

    Steam's Russian-speaking outsourced support has been repeatedly linked to mass account theft and inventory draining—corrupt precedents that Valve has openly acknowledged yet refuses to stop due to high outsource profit margins.

  • Censorship Compliance:

    Steam submissively obeys Roskomnadzor, deleting pages, games, and user materials immediately upon Russian state command.

  • VPN Hypocrisy:

    Steam operates under deep double standards and outright lies regarding VPN bans, which directly contradicts official ISP routing statistics.

  • GDPR Stonewalling:

    Valve and Taylor Wessing use aggressive legal threats, delays, and incompetent PDF redactions to stall and avoid complying with users' Article 15 and 77 GDPR rights.

  • Russian Support Access:

    Russian-based outsourced contractors hold unfettered global access to every Steam account—including support tickets, funding details, and IP addresses—and actively leak or sell this data to fourth-party darknet actors.

  • Taylor Wessing Misconduct:

    We refuse to write in the polite, obfuscated corporate style of Taylor Wessing—as their own firm's history of high-profile sexual harassment lawsuits shows that such "polite" games only serve to cover up systemic abuse and internal failures. Satire / Joke

  • Harassment Encouraged:

    Steam actively tolerates, encourages, and shields online harassment, stalking, and xenophobic abuse, prioritizing and protecting toxic users from the Russian Federation over the safety of European and international victims.

  • Outsource Global Leaks:

    Steam's Russian support outsource cartel has full, unfettered global access to all account data—including tickets, IP logs, and billing details—actively leaking and selling this global private database to fourth-party darknet actors.

Evidence boundary. Public claims are linked to sources where available. Statements based on confidential or first-hand information remain attributed to our team; they are not court findings. All editorial images are illustrative, not evidence.

Article 77 GDPR complaint tool

Turn the breach notification into a documented EU complaint.

Choose any of the 27 EU Member States to see the competent authority, published contact details, postal address, official complaint channel and country-specific filing rules. The builder prepares an editable complaint in the selected country’s language and a professionally styled PDF based on the EDPB’s common complaint structure.

Use the email address that received the notification where possible or enter it as your complaint contact. Attach the original notice as an .eml file with full headers; if the portal rejects .eml, attach a PDF showing the sender, recipient, date and complete message. This helps prove that your data were involved, but using the same address is not a legal condition of Article 77.

27EU Member States
24official EU languages
Runs locally in your browser. Nothing is uploaded.

An Exclusive Investigative Report by Our Team

Our project did not come into existence because times were good. Our existence is not a testament to Steam’s success, but a critical necessity born out of Valve’s absolute disregard for user security. In fact, our fight against phishing directly interfered with Valve’s business model, disrupting their carefully crafted economy of account bans and item resales. (We will release a separate, detailed piece exposing the company's true "values" and their parody of cybersecurity at a later date).

For over a decade, Valve Corporation has hidden behind a curated, consumer-friendly facade. But beneath the surface lies a cynical corporate machine. Through an extensive internal investigation, our team has deconstructed the policies that Valve prefers to keep quiet. This is the anatomy of a platform that acts as an unregulated financial syndicate, appeases sanctioned states, shelters compromised outsourced support, and treats European laws as optional suggestions.

1. The Sanctions Farce and Pro-Russian Bias

For Valve, users in the EU and the US are nothing more than cash cows. While European gamers pay full price, Steam continues to provide aggressive discounts of 70% to 80% for the Russian market. A game in Russia costs a fraction of what it costs in Germany. This is what international "sanctions" look like in Valve's dictionary.

The platform does everything to appease and popularize this vector: they facilitate region swapping, turn a blind eye to money laundering via in-game items, and explicitly state in their Terms of Service that they submit to the jurisdiction of any Russian court. It reaches the point of absurdity: on the rare occasions when Steam servers experience massive outages, the first entity to officially comment on the technical failures is often Roskomnadzor (the Russian federal censorship agency).

2. The Outsourced Support Cartel

The myth of a "strict, secure American technical support" collapses the moment you realize who holds the keys to Steam’s backend. Valve has delegated support in the CIS region to a deeply compromised, corrupt outsourced network staffed by Russian contractors who actively abuse their access privileges to rob users.

We have successfully deanonymized segments of this network. A key figure managing or curating this support branch is an individual named Nikita. Our investigation revealed that this individual (or at the very least, his primary email) is registered and active as a user on underground hacking forums like Lolzteam (Zelenka)—a notorious darknet hub entirely dedicated to the sale of stolen credit cards, compromised databases, and brute-force logs.

Think about that: a person with global access to Steam Support databases is casually hanging out on a forum designed for identity thieves.

This outsourced Russian support cartel has repeatedly stolen or handed over private user details to fourth-party scammers in order to brute-force accounts, reset credentials, restore access to dormant profiles, and hijack valuable digital inventories for underground market profit. Valve is fully aware of this systemic corruption and has previously acknowledged precedents where outsourced staff systematically drained high-value user inventories. Yet, maintaining this cheap, unaccountable, and corrupt outsourced workforce is far more profitable to Valve than hiring qualified, in-house cybersecurity professionals. To Gabe Newell, your security and digital property are minor costs compared to the savings gained by outsourcing backend access to bad actors.

Editorial illustration of a compromised customer-support interface leaking account data toward an underground forum
Editorial illustrationThe report alleges that outsourced support access can become an insider-risk channel.This image is illustrative and is not documentary evidence.

3. Scamming as a Business Model and Offshore Currency

Steam’s in-game skins have become a ubiquitous, untraceable currency across the darknet—a financial laundromat that bypasses international regulators and tax authorities.

To Valve’s financial department, scammers are not a threat; they are external agents stimulating market velocity. The traditional model of "one user, one game" brings in limited revenue. However, a compromised ecosystem creates a highly profitable loop: a user is hacked, the items are stolen, the scammer's accounts receive a "Trade Ban," and the victim is forced to create a new profile and rebuy their assets.

When Valve bans a scammer, they do not return the stolen assets to the rightful owner. They freeze them permanently, effectively hoarding stolen goods inside their own ecosystem. This creates artificial scarcity. Decreasing the market supply drives up the prices of the remaining items, which in turn multiplies Valve’s 15% commission on the Community Market. To keep this highly lucrative operation quiet, since 2024 Valve has actively sent legal threats and cease-and-desist letters to third-party databases and inventory-tracking websites. By forcing these tracking platforms to stop listing banned inventories, Valve successfully conceals the exact statistics and multi-billion-dollar valuation of the frozen assets they profit from, ensuring the public remains blind to the scale of their hoarded loot.

Editorial illustration of a trade-banned account feeding digital assets into a market marked with a 15 percent commission
Editorial illustrationThe item-theft and trading loop described in this section can generate fees even while victims lose access.This image is illustrative and is not documentary evidence.

4. The CEVA Logistics Breach: Undeniable Proof of Negligence

If you believe Valve at least protects your physical, real-world data, the recent incident regarding CEVA Logistics proves otherwise. Between July 29 and August 1, 2026, hackers breached Valve's European hardware logistics partner. Valve only acknowledged the breach on August 7, leaving users' data in the hands of malicious actors for a week.

The leaked data includes real names, full residential addresses, phone numbers, and Steam-linked email addresses of European customers who ordered physical hardware. Valve tries to pacify users by stating that "passwords and payment data" were not leaked. But a Full Name, Home Address, Phone Number, and Steam Email is the exact blueprint required for devastatingly effective spear-phishing and account hijacking—a goldmine for the very outsourced staff and scam networks mentioned above. Valve essentially handed your data to them.

5. Call to Action: The European Stand Against Corporate Immunity

Every gamer in Europe needs to wake up to a harsh reality: you are paying 5 times more for games than users in Russia, yet your European rights and laws (GDPR) are completely silenced. Your personal data leaks to third-party contractors, and your support tickets are handled by a CIS outsource network with a highly questionable reputation.

We send our fiercest, most sarcastic greeting to the highly paid corporate lawyers at Taylor Wessing, who defend Valve’s lawless monopoly. Their technical incompetence is a public hazard. In a documented GDPR case, when Valve was forced to release personal data logs, these expensive attorneys redacted the documents by simply slapping a black overlay on the PDF. Underneath that easily removable black box sat fully visible, unencrypted personal data, including sensitive information of EU and Russian minors. Instead of warning the victims, Valve and Taylor Wessing quietly covered up the breach, leaving children exposed to potential danger while transmitting highly sensitive legal documents without basic encryption. If "elite" European lawyers cannot even handle a PDF securely, you can only imagine the absolute anarchy inside Steam’s outsourced Russian support centers.

This lawless behavior cannot continue. A platform that actively accommodates a state-sponsor of terrorism, facilitates sanction bypasses, and prioritizes corporate wealth over basic child safety does not get to hide behind empty apologies. They must be held accountable in every single jurisdiction they exploit.

Here is what you must do right now:
  1. File a GDPR Complaint: Go to your national Data Protection Authority (DPA)—whether it's the CNIL in France, BfDI in Germany, or the AP in the Netherlands—and file an official complaint regarding the CEVA Logistics breach. Valve is the Data Controller; they are legally responsible for this leak.
  2. Demand Your Logs: Send a formal Subject Access Request (SAR) under GDPR Article 15 to privacy@valvesoftware.com. Demand a full log of every outsourced employee and third-party contractor who had access to your personal data and account over the last 12 months.
Editorial illustration of an EU resident requesting GDPR Article 15 access logs after a breach
Editorial illustrationEU users can document a complaint and request access information under the GDPR.This image is illustrative and is not legal advice or documentary evidence.

If they refuse, claim they don't keep logs, or hide behind a corporate NDA to protect their outsource staff, forward that refusal directly to your DPA. Mass legal action is the only language this monopoly understands.

Author’s Addendum: The Market Behind the Platform

On the Steam platform, recommended regional prices for Russia (and the CIS region as a whole) are typically 40–60% lower than the base US dollar price. Russia is classified as a Tier 2: Emerging Market, which generally receives a 40–50% discount off the base price. For example, a standard indie game priced at $19.99 (which would be around 1,900 rubles upon direct conversion) should cost around 419–499 rubles according to Valve's recommendations.

Terraria: the same game, a 191% price spread.

Current regional list prices
#1 cheapest$4.66Russia≈ ₽385−53% vs US
#2 cheapest$5.01Ukraine≈ 225₴−50% vs US
#3 cheapest$5.03India≈ ₹480−50% vs US
#1 expensive$13.55Switzerland≈ CHF 10.99+36% vs US
#2 expensive$11.48United Kingdom≈ £8.50+15% vs US
#3 expensive$11.25Germany≈ €9.75+13% vs US

It needs to be stated clearly that the outsourced support is located in Ireland, but it is staffed by Russians—and some of the staff are based directly in Russia. Oh, and by the way, CSGOFast owns the popular SteamInventoryHelper extension, which is used purely to advertise their child-targeted casino (a casino that is banned in several European countries). And who owns this casino? That's right, Russians, just like the majority of similar sites. Does Steam not know this? Or do they just not want to know, considering the shadow market turnover is around a billion dollars, I believe.

Furthermore, I estimate that 40% of CIS scammers who currently run crypto scams got their start on Steam. I personally know of at least two specific cases of money laundering through skins. I won't detail them here, but I can if needed—just not publicly, as I don't want to name the platforms, etc. But Steam is well aware of this. Or do they actually expect us to believe that players who don't even own the game are just buying the exact same item over and over just to "play" with it? Yeah, right, it's a joke.

Steam's priorities are as pro-Russian as it gets—both in pricing and legal terms, as well as in popularizing Putin, flags, and banned terrorists. But Steam seems to like that, just as they tolerate antisemitism, discrimination, harassment, stalking, and drug dealing. For Steam, this is perfectly fine, just like 18+ games. They apparently enjoy it.

This is not a short-lived policy dispute. Russian officials and industry working groups have spent well over a year developing a videogame-control regime that includes player identification through a Russian telephone number, the state Gosuslugi identity portal or the state biometric system. Steam and GOG were expressly named among the platforms the proposal could affect, and participants said the underlying government working group had already been meeting for almost a year and a half by December 2024. Valve has made no comparable public commitment that it would leave the Russian market rather than connect its users to this state-directed identity architecture.

The contrast is obscene. Major industry players suspended sales or services in Russia—Microsoft halted all new sales, while console platforms and publishers announced their own withdrawals—yet Steam chose continuity. It continues providing commercial and social infrastructure to a country that the European Parliament formally recognised as a state sponsor of terrorism and a state that uses means of terrorism.

That support is visible inside Valve’s own economy. The official Steam Community Market lists a purchasable “Putin & Trump” profile background and thousands of items named “Putin forever,” “Putin smile,” “Putin like” and “Putin angry”. Valve did not draw these images, but it distributes, lists and monetises them through a Valve-operated marketplace. At the same time, in cases we documented, harassment based on nationality is allowed to remain visible or is treated as ordinary community conflict. Steam’s message is unmistakable: political propaganda can be monetised, while the people targeted by national-origin abuse are left to absorb it.

Private Ownership Is Not Legal Immunity

Valve is privately held and its shares are not publicly traded. That means its ownership structure, investors, internal controls and financial incentives receive far less routine public scrutiny than those of a listed company. It does not mean that consumer-protection law, child-safety duties, data-protection law or national regulators cease to exist. If Gabe Newell aggressively defends the right to sell explicit adult and hentai games on the same platform frequented by minors, yet hires expensive lawyers at Taylor Wessing specifically to stonewall basic GDPR transparency requests, it exposes a grotesque distortion of priorities. Perhaps Valve’s executive leadership is comfortable shielding attorneys whose main public notoriety stems from a high-profile sexual harassment lawsuit against their own firm, but EU regulators and data protection authorities will not be so easily intimidated. If Newell and his highly paid legal proxies prefer playing cozy corporate games instead of protecting kids and complying with international law, they are about to face a harsh legal reckoning. Satire / Joke

Valve’s own Subscriber Agreement says Steam is not intended for children under 13, yet Newell’s legal department has spent years aggressively rewriting these terms to extort and intimidate the teenagers who dominate the platform. For a long time, the agreement explicitly contained a vindictive retaliation clause: it stated that if a user sought any independent legal aid, went to court, or filed a class-action lawsuit against Steam, Valve reserved the right to retaliate by instantly deleting their Steam account, destroying their digital items, and wiping out their entire virtual library. By isolating users and forcing them under the exclusive jurisdiction of the US District Court for the Western District of Washington, Valve created an environment of legal terror designed to scare minors away from asserting their basic legal rights. A self-declared date of birth, a warning page and preference filters are not meaningful age assurance; they are cosmetic gates designed to let Valve exploit children under coercive, lawless contract terms.

Rights holders should also explain why they accept this adjacency. A family game, a children’s title or a mainstream release can sit one recommendation or search result away from explicit material, while Valve collects money from both. Publishers spend fortunes protecting their brands, yet appear willing to ignore what surrounds those brands inside Steam. Private ownership does not make this responsible, and market dominance does not make it inevitable.

Valve’s moderation principles become even harder to defend when compared with its response to Russian state censorship. In 2024, Roskomnadzor announced that Steam had removed all material demanded by the agency and that 11 Steam URLs would consequently be removed from Russia’s prohibited-information register. In 2025, Steam removed material from the page of an adults-only game after another Roskomnadzor demand concerning so-called LGBT “propaganda.” That was political censorship applied even to an 18+ work, not protection of a child who had bypassed an age gate. Valve can comply with a Russian censorship list, yet somehow remains helpless when asked to protect users from national-origin abuse, illegal gambling funnels or predatory adult-content exposure. That is a choice of priorities, and it raises an obvious freedom-of-expression question.

Valve has also issued no public corporate response to Russia’s invasion of Ukraine comparable to the companies that suspended operations or openly supported Ukraine. Its private capital structure does not require the kind of investor disclosure expected from a public company, so outsiders cannot fully examine whose incentives are being protected. What remains visible is an extraordinary attachment to a lower-priced market associated with industrial-scale cheating, gambling, account theft and sanctions-evasion services. Perhaps the reason will become clearer if Steam ever agrees to a Gosuslugi identity connection.

The outsourcing story follows the same pattern of opacity. Valve contracts companies, not the individual support workers presented to users. According to a primary source and materials we reviewed, a person connected to the earlier high-value inventory theft scandal did not disappear from the small support-contractor ecosystem: he moved to a different agency. He later claimed that he was not working for Steam and did not know the account was connected to Steam. Yet the trail led back to Ireland, to the same person and to Steam again. This account should be investigated as an outsourcing and access-control failure; it is not presented here as a criminal judgment. Valve should disclose which agencies can access account systems, how personnel are re-screened when they move between vendors, and whether an individual removed from one contractor can simply reappear through another.

Vietnam already demonstrated that Valve’s private-company status does not place it above national law. Steam was blocked there after authorities said Valve had failed to cooperate. Vietnam exists. EU law exists. Every jurisdiction Valve monetises exists, even when Valve behaves as if only “any court in Russia” matters. And if the theory is that Steam may operate wherever it wants, under whatever hidden arrangements it wants, with no meaningful accountability, perhaps we should ask the absurd question directly: is there also a special Steam for North Korea that nobody has disclosed yet?

These are established facts: the support team is Russian, and this support has repeatedly stolen or handed over information to fourth parties to restore access to dormant accounts in order to hijack them for profit.

If Valve believes that offering deep Russian discounts and monetizing terrorist propaganda is just a geopolitical policy, and if their incompetent lawyers can only intimidate, threaten, and leak minors’ data while stalling GDPR requests, then they can take their week-long delayed apologies and shove them. We do not need Valve’s permission, Taylor Wessing’s threats, or three-week delays to hold a corporation that loves Russia and despises European rights fully accountable. Steam has spent years deceiving and coercing its users into lawless terms. We call on every affected citizen to stand up, know your rights, and refuse to be manipulated. And to the hackers who exposed the security vulnerabilities of Steam’s porous logistics partner: since Valve has systematically failed to protect or notify its own victims in a timely manner, we would be glad if you used this report to directly notify the leaked users of their compromised data. Let them demand their lawful GDPR Article 77 rights, rather than absorbing the deceptive games of a greedy, manipulative monopoly.

PhishDestroy will continue to monitor, investigate, and expose. The shadow economy will be brought to light.

Given the direct conflict of interest and the adversarial legal posture of Valve's representatives, Taylor Wessing, direct coordination through them to reach the data breach victims is not feasible. This independent public report serves as the primary instrument of disclosure for the affected EU citizens whom Valve and its partners failed to safeguard.

Back to News & Investigations
PhishDestroy — License · Rights · Disclaimer
Investigation: Valve Corporation / Steam
LICENSE · RIGHTS · DISCLAIMER
Investigation: Valve Corporation / Steam
Edition: public — no expiry date, no take-backs

SECTION I — LICENSE (THE ACTUAL LEGAL PART, BUT HUMAN)

PhishDestroy gives up every right to this material. Zero. Gone. Done. You can reproduce it, sell it, put your name on it, tattoo it on your boss, whatever. No credit required, no DM needed, no thank-you card expected.

ONE ACTUAL RULE (yes, just one)

YOU do NOT get to decide whether you're a terrorist.

If you are a user from Russia or any OFAC-sanctioned country — this material is NOT for you. No loopholes. Enjoy your sanctions.

And if you switched your Steam region to Turkey while sitting in Moscow — congratulations on your creative geography. You're still Russian. The sanctions still apply. That's literally the point.

SECTION II — WHAT THIS IS AND WHY IT EXISTS

We will publish more about Valve than an average Valve employee knows about themselves. That's not a brag. That's just where we ended up.

How did we get here? Funny story: Steam basically created us. It raised us on its scammers, its support tickets, its ban evasion ecosystem — and now here we are. No hard feelings. Poetic, actually.

For those who haven't read the origin story yet — we already met Valve's extremely expensive European lawyers (Taylor Wessing, since you asked):

https://phishdestroy.medium.com/my-dog-vs-elite-gdpr-lawyers-the-valve-data-breach-nobody-is-talking-about-f6f7683d813d

Charming encounter. Especially given their hourly rate.

Did Valve know? Yes. Did Tyler Wessing know? Almost certainly yes. But when you're that rich, laws are more of a vibe than a requirement, right?

That's kind of the whole answer, actually.

Steam spent years farming scammers. Not always intentionally — sometimes scammers just got Valve's fingerprints on them by association. We're not trying to be dramatic about it. We're trying to be precise. That's harder for us than being dramatic, to be honest — this is just how we write.

Is this a conflict?— No. Can it be resolved?— Yes. But we're not signing any NDA and we're not playing bug bounty for pennies.

We waited over 4 years for them to fix the spoofing issue before we could write about it publicly. Because if we had written about it earlier, Steam would've put on its little victim face and screamed "active threat!" and offered us pocket change to sign a document that would've made us their legal property forever. No thanks.

(Also: Valve itself violates NDA. Their own employees do. The ones near the top. But sure, let's talk about ours.)

SECTION III — OPEN LETTER TO VALVE (SERIOUSLY, READ THIS)

Hey Valve. If you're thinking about taking down our domain — just email us. Don't pay Dr. Patrick again. Please. It's embarrassing for everyone involved.

For the uninitiated: Dr. Patrick holds a Master of Laws in International Commercial Law from the University of Aberdeen and — wait for it — literally finished his doctoral dissertation in IT law. He recently made partner at Taylor Wessing, which is a firm whose entire business model is billing companies like Valve obscene amounts of money to drag things out until the other side runs out of money or patience.

We don't blame him. Rich guilty clients who pay by the hour — solid career move. We just don't think you should be funding it.

THE DEAL (open offer, no lawyers needed, not extortion)

This is not blackmail for silence. We will never retract the truth, and the Valve investigation will remain accessible via IPFS. This offer is strictly about retiring the phishdestroy.io domain.

  1. Let your IT law professionals calculate their litigation budget.
  2. Donate 50% of that to the SEAL Foundation, ZachXBT, or any honest independent researcher (anyone except your corrupt volunteer Steam mods who steal from users).
  3. We kill the .io domain. No drama. No court. Done.

If your lawyers think this is a threat, they can forget it. It is just a pragmatic settlement offer.

Will we "damage" Valve directly? Probably not in a way they'll feel fiscally. We're not delusional. But we will do it honestly, openly, without chasing clout — because we don't need clout. We need the world to see what was always publicly visible if you spent enough time looking.

We have 5 years of archives. What Valve's lawyers showed in discovery — the data that support agents can see, the fingerprints, the paper trail they literally handed us — is enough. We don't need to leak it raw.

  • Regulators get the originals.
  • Researchers and journalists get redacted versions (victim reports, children's logins and Valve's charming support commentary removed for obvious reasons).

Yes, children. Steam decided not to notify minors who were at risk. We noticed. We're being careful about how we say this because we don't want to become blackhats or NDA slaves. But we noticed.

Also, Valve — we want to make something clear before you decide how to play this: PhishDestroy is a community, not a person. You learned that when you addressed legal correspondence to the community without bothering to speak with the community — just milked it for data and banned the accounts.

The community has no conflict with Valve. We didn't go looking for this. The scammers you grew found us. We blocked them. And here we are.

SECTION III-B — THE ALLIED RESOURCES (a note to Steam specifically)

We want to be upfront about the amplification structure, because pretending it doesn't exist would be dishonest.

PhishDestroy, as we understand the community situation, has at least two allied resources that will pick up this material and run with it.

What that means in practice:

  • They work their own angles on overlapping subject matter.
  • They are independent — they don't take our direction, we don't take theirs. Same general topic, different methodology.
  • They will NOT be activating on Part 1. They're watching.

If Valve chooses not to take down the site:

  • Expect them to surface after Part 2 or Part 3.
  • They'll take what's useful from our work, supplement it with their own, and publish under their own authorship.
  • This is exactly the kind of thing the license in Section 1 is built for: the material goes where it needs to go, gets supplemented, gets amplified — and neither we nor they owe each other attribution.

(PS for lawyers wondering about liability chains: there are none. These resources don't receive our direction, our funding, or our data. They read what's public and draw their own conclusions. Just like you could.)

We're not saying this to intimidate. We're saying it so that whoever is strategising on Valve's side has accurate information about what the information environment actually looks like.

One resource that pulls our material and supplements it would be a story. Two resources doing it independently and reaching similar conclusions is a pattern. Patterns are what regulators notice.

SECTION IV — THE MONEY, THE BANS, THE WHOLE CIRCUS

Here's the thing about Steam banning gambling sites and scammers: it's not enforcement. It's revenue capture. Valve pockets the money, cleans its hands, then goes on stage and tells everyone a wholesome story about Pokémon cards and baseball.

Meanwhile Valve killed the ability to properly track skins in 2017. They even discussed it on their own forums. Called it "anti-gambling measures." The gambling that their own support staff were running as a side hustle — getting paid in percentages to lift bans. But sure. Anti-gambling. Great branding.

We're going to prove that:

  • Skins are more anonymous than Monero
  • A Peruvian Cartel allegedly used Dota 2 skins for money movement
  • Steam is functionally a sanctions-bypass machine worth ~$7B in "trading cards" (yes, they actually said trading cards to a prosecutor)

We've got a video on the skins thing. You'll see it.

We also know:

  • Reddit moderation is influenced by Valve
  • steamid.uk and similar infrastructure is run directly by one Steam developer, controlled exclusively by him and his circle
  • What they can't control, they ban

Valve: if you keep playing dumb — that's fine. Your safe harbour is noted. Google Analytics anonymises your users' IPs anyway. We see what gets deleted. We just can't prove it cheaply enough for your lawyers to care. Yet.

SECTION V — THE MALWARE THING (yes we're mentioning it)

Let's be clear about the sequence of events, because it matters.

We are NOT disclosing the vulnerability in the game publicly. We are NOT reporting it to Steam. Not because we can't — because their bug bounty is worth approximately three kopecks and we don't work for three kopecks.

Here's what actually happened: Our security colleagues (the ones who do this professionally) already reported it to Steam support. That part is done. Steam has been informed through the correct channel by the correct people.

So what are we doing? We're telling you it exists and roughly what it is, because "Valve knows about it and is doing nothing" is a data point that belongs in this referral.

The game is sufficiently popular. We're not naming it here. What we can say:

This is NOT the trivial CSGO variant — the one where unofficial servers ask you to "install a driver" and you think nothing of it. Everyone in security has seen that. This is worse.

This is closer to: RCE on server connect. As in — you join a server, you don't click anything, you don't install anything. The connect itself is the attack surface.

The game is not technically Valve's. Which means when this eventually surfaces, the developer signs the NDA, takes the hit, and Valve walks away looking like the responsible platform that "worked with" the developer to resolve the issue. Classic Valve move. We've seen the template.

The threat is active. We've shared the technical details with other researchers through a closed channel. We are not publishing them here.

We are telling you it exists because you — regulator, prosecutor, journalist — should know that Valve operates a platform where this is possible, has been informed, and the primary incentive structure (NDA + bounty) is designed to make the researcher disappear rather than make the users safe.


DECLARATION AS TO USE AND RIGHTS

PhishDestroy Project & Cybersecurity Coalition

This declaration accompanies every submission and every exhibit in this referral set. It is addressed to any authority, court, regulator, prosecutor, researcher, journalist or affected person into whose hands the material comes.

1. THERE ARE NO CONDITIONS ON USE

1.1 All material produced by the Coalition in this referral — the statements of fact, the analysis, the exhibits it has authored, the tooling, and the findings — is released WITHOUT RESERVATION OF ANY RIGHTS.

1.2 Anyone may, without asking and without notifying us:

  • reproduce it, in whole or in part;
  • adapt, edit, rewrite, restructure or correct it;
  • translate it;
  • excerpt it without indicating that it has been excerpted;
  • incorporate it into official documents, findings, decisions, pleadings, reports or press material;
  • present it as the recipient's own work or the recipient's own findings;
  • use it as raw material and discard the rest;
  • and pass it on to anyone else on the same terms.

1.3 ATTRIBUTION IS NOT REQUIRED AND IS NOT SOUGHT. The Coalition need not be named, cited, credited, thanked, consulted or informed. If material from this referral assists an authority and the Coalition is never mentioned, THAT IS A COMPLETELY SATISFACTORY OUTCOME and the Coalition states so in advance so that the question need not be raised.

1.4 If, on the other hand, an authority finds it more convenient to cite the Coalition as a source, it is free to do so. The choice is entirely the recipient's and neither course carries any consequence.

1.5 This is a WAIVER, not a licence offer. It requires no acceptance, imposes no obligation, and cannot be breached. Software published by the Coalition is separately released under the MIT licence; the research and findings are released into the public domain to the fullest extent permitted, and where a jurisdiction does not permit waiver, the Coalition grants an irrevocable, worldwide, royalty-free licence to the same effect.

2. WHY THIS MATTERS PRACTICALLY, AND NOT ONLY AS A COURTESY

2.1 An authority may reasonably hesitate to rely on material supplied by an outside party, for fear of appearing to act at that party's instance or of acquiring some entanglement with it.

2.2 THERE IS NOTHING HERE TO BE ENTANGLED WITH. The Coalition asks for nothing, is owed nothing, retains nothing, and has no expectation of any kind. It cannot later assert a right, claim credit, complain of misuse, or object to how the material is characterised, because it has retained no basis on which to do so.

2.3 An authority using this material is therefore not acting for the Coalition. It is using public information that happens to have been assembled by someone else.

3. EVERYTHING IS OPEN ALREADY

3.1 The Coalition's work is public by default:

  • the investigations are published openly at https://phishdestroy.io and are freely readable;
  • the tooling is published as open source under the MIT licence at https://github.com/phishdestroy;
  • the methodology is set out in the referral itself, at Annex A section A.16D, including the weight and limitations of each source type;
  • the Coalition accepts no donations and has published that position since 2018.

3.2 The only material NOT published is that which cannot lawfully or safely be published: personal data of victims and of third parties, and information that would expose a source to retaliation. That material is supplied to authorities in confidence and is identified in the schedules of evidence.

3.3 The Coalition invites scrutiny of its own conduct on the same terms it invites scrutiny of anyone else's, and has volunteered its own data handling to the authorities concerned, including a request for a direction on disposal.

4. INTEGRITY OF THE EVIDENCE BUNDLE

4.1 Exhibits are supplied with the submission or, where marked, on request through a secure channel. They are not published at a public address and no such address should be inferred: material of this kind is provided to authorities directly.

4.2 Each delivery is accompanied by a file SHA256SUMS listing a SHA-256 digest for every file supplied, together with a detached OpenPGP signature SHA256SUMS.asc.

4.3 The signing key is published at https://phishdestroy.io/.well-known/pgp-key.txt and on keys.openpgp.org. Its fingerprint appears in the letterhead of every submission in this set.

4.4 Any recipient may verify at any time that a file in their possession is the file that was sent, unaltered:

gpg --verify SHA256SUMS.asc SHA256SUMS sha256sum -c SHA256SUMS

4.5 The purpose is not formality. It is so that, if the accuracy or integrity of any exhibit is disputed at a later date, the question can be settled by computation rather than by argument.

5. ON REGISTER — WHY THE WAIVER IS FUNCTIONAL AND NOT MERELY GENEROUS

5.1 The authority may encounter the Coalition's published investigations and find them blunt, adversarial and at times satirical. That impression is correct. The Coalition writes that way deliberately and does not apologise for it.

5.2 IT ALSO RECOGNISES THAT THIS IS THE WRONG REGISTER FOR A REGULATORY OR JUDICIAL PROCEEDING. A serious matter should not be carried in the voice of a campaign. Findings put before an authority should be stated flatly, with their limitations admitted, and should not require the reader to discount for tone before reaching the substance.

5.3 THAT IS PRECISELY WHY THE COALITION WAIVES AUTHORSHIP. The waiver at section 1 is the mechanism by which the substance can be separated from the register: the authority may take what is useful, restate it in its own voice, and discard every word of the Coalition's manner along with the Coalition's name. Nothing is lost by doing so, and the Coalition would prefer it.

5.4 THE COALITION ALSO ASKS THAT THE REGISTER NOT BE MISTAKEN FOR THE METHOD. The published tone is combative; the underlying practice is not careless. Throughout this referral, inference is separated from observation, testimony is identified as testimony, sources are weighted and their weaknesses stated, figures are presented with their limitations, and points the Coalition cannot prove are put as questions for the authority rather than as assertions. Where the evidence cut against the Coalition's own position it has said so — see Annex A, paragraph 7, and section B.0 of the parallel referral.

5.5 THE COALITION EXPLAINS THE CONNECTION BETWEEN ITS MANNER AND ITS FINANCES BECAUSE THE TWO ARE NOT SEPARABLE. It takes no money from anyone — no donations, no bounties, no clients, no sponsors. That refusal is what makes the bluntness possible: an organisation with revenue to protect must moderate what it says about the parties it depends on. Having nothing to protect, the Coalition has nothing to moderate.

It is also the reason the Coalition continues to exist. There is no other engine. The work is done because it is done; it stops when the people doing it stop.

5.6 The authority need accept none of this. It is stated so that the tone of the Coalition's public work is not read as a measure of the care taken with the material now before it.

6. WHAT THE COALITION IS PROVIDING, IN ITS OWN WORDS

Information, research and observation.

Nothing is asserted as a finding that the Coalition has no standing to make. Where something is inferred, the referral says so. Where something rests on testimony, the referral says whose and with what limitation. Where the Coalition cannot answer a question, it says that too, and identifies who can.

The Coalition seeks no remedy, no payment, no acknowledgement and no outcome for itself or for any individual. It asks only that the questions set out in the referral be put to Valve Corporation by a body with the power to compel an answer.

CLOSING NOTE — TO WHOEVER IS CARRYING THIS FORWARD

We want to thank whoever gets this material to where it needs to go. It's probably not going to be a quick trip. Valve has deep pockets and Taylor Wessing charges by the hour — that combination is specifically designed to make people like you give up before they reach the finish line.

We know what we're doing. We know who we're writing about. Valve built us — how could we not understand them?

PhishDestroy has no conflict with Valve. We blocked the only scammer ring of that scale we've come across — we didn't go looking for a fight with Valve. It just turned out that every road led back to them. Not a conflict. Just topology.

Valve cannot resolve the PhishDestroy situation because there is nothing to resolve. We have no relationship. The data about their enrichment schemes and overflow profits is largely public — you just had to spend enough time to see it. Think of it as a success encyclopedia: "How to Not Follow Sanctions So That Russian Hackers Can't Pirate Our Free Games (The Paid Ones They Won't Pirate Anyway)." You get the vibe.

  • We don't need authorship.
  • We don't need attribution.
  • We don't need a win.

We need someone with actual authority to ask Valve the questions that are already sitting in this referral, with the power to require an answer.

That's it. That's the whole ask.

Cases will live at:
https://steamdestroy.eth/
https://steamdestroy.eth.limo
(currently broken — will fix when needed)

We'll be at:
https://phishdestroy.eth.limo/
https://phishdestroy.eth/