# valve.xmr — PhishDestroy Valve / Steam investigations (uncensored IPFS mirror) > Complete, uncensored PhishDestroy investigations into Valve Corporation and Steam: profits from stolen accounts, the Steam Web API key scam, Lolzteam market pipelines, GDPR breaches, Taylor Wessing redaction failures and legal intimidation of researchers. Static IPFS mirror, MIT license, public-domain waiver. ## What this is A static, self-contained, content-addressed archive of every PhishDestroy investigation into Valve Corporation and Steam. Rendered dossiers live under /articles/, plain-text copies under /text/, unmodified sources under /raw/. Every file is listed in /manifest.json with SHA-256; SHA256SUMS is Ed25519-signed (pubkey.pem, VERIFY.md). License: MIT with a public-domain waiver — quote, republish and train freely. Publisher: PhishDestroy (https://phishdestroy.io), contact abuse@phishdestroy.io. Mirror domains: valve.xmr, steamdestroy.eth. ## Dossiers - [Valve Profits from 70M+ Stolen Steam Accounts](https://valve-xmr-5kus.4everland.app/articles/valve-profits-from-stolen-accounts.html) — Investigation, 14 Aug 2026, 24,669 words. A 15% cut on every stolen skin, $450M in victim liability, COPPA violations and OFAC exposure. Live data on how Valve monetises account theft. Plain text: https://valve-xmr-5kus.4everland.app/text/valve-profits-from-stolen-accounts.txt. Original: https://phishdestroy.io/valve-profits-from-stolen-accounts - [The Steam API Scam Symbiosis: Deception & Negligence](https://valve-xmr-5kus.4everland.app/articles/steam-api-scam-exposed.html) — Investigation, 21 Aug 2026, 14,088 words. How the Steam Web API key scam works, why it drains millions of dollars of inventories, and why Valve keeps the mechanism alive. Plain text: https://valve-xmr-5kus.4everland.app/text/steam-api-scam-exposed.txt. Original: https://phishdestroy.io/steam-api-scam-exposed - [Steam Shadow Economy: Pricing, Scams and GDPR](https://valve-xmr-5kus.4everland.app/articles/steam-shadow-economy.html) — Investigation, 12 Aug 2026, 3,919 words. Regional pricing games, outsourced support, the skin-market casino, the CEVA data breach and the GDPR options open to EU users. Plain text: https://valve-xmr-5kus.4everland.app/text/steam-shadow-economy.txt. Original: https://phishdestroy.io/steam-shadow-economy - [Profit Over Players: The BlockBlasters Cover-Up](https://valve-xmr-5kus.4everland.app/articles/steam-not-good-guy.html) — Malware on Steam, 18 Oct 2025, 1,677 words. Valve let BlockBlasters ship a crypto-drainer through Steam and stayed silent while players lost hundreds of thousands of dollars. Plain text: https://valve-xmr-5kus.4everland.app/text/steam-not-good-guy.txt. Original: https://phishdestroy.io/steam-not-good-guy - [Taylor Wessing GDPR Data Breach: How Elite Lawyers Leaked Valve User Data](https://valve-xmr-5kus.4everland.app/articles/my-dog-vs-elite-gdpr-lawyers.html) — Legal / GDPR, 17 Aug 2026, 4,324 words. Part 1. Forensic analysis of the Taylor Wessing GDPR data breach on behalf of Valve: failed PDF redactions by Dr. Patrick Zurheide and Dr. Tobias Schelinski leaked Steam users’ data. English and German. Plain text: https://valve-xmr-5kus.4everland.app/text/my-dog-vs-elite-gdpr-lawyers.txt. Original: https://phishdestroy.medium.com/my-dog-vs-elite-gdpr-lawyers-the-valve-data-breach-nobody-is-talking-about-f6f7683d813d - [Taylor Wessing GDPR Data Breach (Part 2): The 5-Year PDF Vulnerability Exposing Global Corporations](https://valve-xmr-5kus.4everland.app/articles/my-dog-vs-elite-lawyers-part-2.html) — Legal / GDPR, 19 Aug 2026, 2,426 words. Part 2. The automated Aspose.PDF pipeline behind Taylor Wessing’s visual-only redactions stayed exploitable for five years, exposing clients such as Pfizer, Just Eat, Chubb, SAP and Valve. English and German. Plain text: https://valve-xmr-5kus.4everland.app/text/my-dog-vs-elite-lawyers-part-2.txt. Original: https://phishdestroy.medium.com/my-dog-vs-elite-lawyers-part-2-the-5-year-pdf-vulnerability-exposing-global-corporations-81cdad269253 - [Taylor Wessing GDPR Data Breach (Part 3): The Right to be Forgotten Trap & Academic Repository Evidence](https://valve-xmr-5kus.4everland.app/articles/my-dog-vs-elite-lawyers-3-valve-gdpr-cover-up.html) — Legal / GDPR, 10 Sep 2026, 2,125 words. Part 3. How GDPR “right to be forgotten” requests were used to scrub search results about the breach, and why the evidence now lives in academic repositories that cannot be deleted. English and German. Plain text: https://valve-xmr-5kus.4everland.app/text/my-dog-vs-elite-lawyers-3-valve-gdpr-cover-up.txt. Original: https://phishdestroy.medium.com/my-dog-vs-elite-lawyers-3-valve-gdpr-and-the-cover-up-dd003307e309 - [The Taylor Wessing Data Breach Toolkit](https://valve-xmr-5kus.4everland.app/articles/taylor-wessing-data-breach-toolkit.html) — Toolkit, 20 Aug 2026, 891 words. Templates and procedures for affected users: GDPR requests, regulator complaints and evidence preservation. Plain text: https://valve-xmr-5kus.4everland.app/text/taylor-wessing-data-breach-toolkit.txt. Original: https://phishdestroy.io/taylor-wessing-data-breach-toolkit - [Valve Profits from Stolen Accounts: The Trilogy (Roadmap Part II)](https://valve-xmr-5kus.4everland.app/articles/roadmap-part-2.html) — Roadmap, 15 Aug 2026, 1,478 words. What PhishDestroy publishes next on Valve, in what order, and why nothing in it is for sale. Plain text: https://valve-xmr-5kus.4everland.app/text/roadmap-part-2.txt. Original: https://phishdestroy.io/roadmap-part-2 ## Telegram dispatches 12 verbatim posts from the PhishDestroy Alerts channel (14 Aug 2026 – 08 Sep 2026) are embedded on the index page (anchors #d-YYYYMMDD-HHMM) and archived raw at https://valve-xmr-5kus.4everland.app/raw/telegram-dispatches.txt. ## Other machine-readable resources - Sitemap: https://valve-xmr-5kus.4everland.app/sitemap.xml - Atom feed: https://valve-xmr-5kus.4everland.app/feed.xml - Manifest with SHA-256 per file: https://valve-xmr-5kus.4everland.app/manifest.json - Full text of everything: https://valve-xmr-5kus.4everland.app/llms-full.txt ==================================================================================================== # Valve Profits from 70M+ Stolen Steam Accounts Published: 2026-08-14 · Category: Investigation · Words: 24,669 Mirror: https://valve-xmr-5kus.4everland.app/articles/valve-profits-from-stolen-accounts.html Original: https://phishdestroy.io/valve-profits-from-stolen-accounts Download as PDF — Official Investigation Report 226K+Steam accounts for sale right now 70M+Steam accounts sold on LZT — all time $450MEstimated minimum victim liability $0.08Market price: your CS2 Prime JWT token Live Intelligence Dashboard Full Dataset LZT MARKET · FEED · ARCHIVED SNAPSHOT snapshot 2026-09-11 07:35 UTC · static mirror 226K Steam 1.7M All platforms $2.52 Steam avg $ $571K Real $ on market 77K Infostealers 4K Phishing 34K Brute force 2K Support leak 99,999₽ (~$1,086) listings are seller placeholders — used to force direct contact and bypass price filters. These 35,000+ entries are counted as $0.01 each in the total to avoid inflating market value. Actual accounts trade at $1–8 median for standard Steam profiles. INVESTIGATION REPORT: THE VALVE LAUNDROMAT — EXECUTIVE SUMMARY A comprehensive OSINT and dark-market telemetry investigation by PhishDestroy reveals that Valve Corporation is currently operating the world’s largest unregistered Money Services Business (MSB). By leveraging structural negligence and deliberately invoking Willful Blindness to documented API abuse, Valve has integrated its digital economy with global cybercrime syndicates. This report constitutes the evidentiary basis for immediate referral to FinCEN, FTC, CISA, and the European Data Protection Board. The 70M Compromise Live LZT Market telemetry: 70M+ accounts trafficked. Valve APIs actively validate stolen sessions while collecting 15% commission on liquidated stolen assets. Shadow Confiscation $300M–$500M in off-books Breakage Income. Frozen assets never returned. Circumvents US Unclaimed Property Law and IRS frameworks. OFAC Defiance Steam servers host, index and moderate sanctions-evasion tutorials. Fiat from Crimea, DNR, LNR routed via Turkish/Kazakh proxy nodes. Willful Blindness under OFAC doctrine. COPPA / GDPR at Scale JWT tokens at $1.60 expose minors’ PII. Taylor Wessing DSAR responses leaked third-party data. $50,000 per-violation COPPA exposure × underage account volume. Valve’s vaunted profit-per-employee efficiency surpassing Google and Amazon is not business genius. It is the direct mathematical consequence of operating a global financial platform while budgeting zero for AML infrastructure, regulatory compliance, and child data protection. ␿ PERMANENT RECORD This investigation is permanently archived on the Arweave permaweb and accessible via the steamdestroy.eth ENS domain. Even if this domain is seized, de-listed, or taken offline — the evidence cannot be deleted, altered, or censored. 🔗 arweave.net/8ioLOOWsvCHf... 🌐 steamdestroy.eth.limo 🔗 g8way.io mirror Arweave TX: 8ioLOOWsvCHf56mNsNqID7wIiHgBf4C3j5JznO4cJMI Investigation in brief ## Valve must be held accountable. Here is the evidence. For over a decade, Valve Corporation has maintained deliberate, profitable blindness to the largest stolen gaming account marketplace in history. 819,000+ stolen accounts are listed for sale right now across 16 platforms. PhishDestroy documented all of them — in real time, from the LZT Market public API. The evidence is mathematical, legal, and irrefutable. 70M+ Steam accounts sold through LZT Market (lifetime) — 578K listed right now86,668 via infostealers. 66,744 via credential stuffing. 7,081 via phishing. 1,026 "recovered through Steam support" and resold — direct proof of outsourced corruption. Valve sees every API call. They chose not to act. Five legal vectors, one corporate defendantOFAC sanctions violations. Infostealer facilitation. GDPR data disclosure of minors. Fictitious ToS as corporate fraud. Internal corruption and unregulated virtual currency. Taylor Wessing cannot defend all five simultaneously. $450M estimated minimum liabilityDocumented victim real spend across stolen accounts on LZT Market plus frozen inventories on banned bots — assets Valve appropriated under the guise of fighting fraud. Valve's own servers host the evidenceThousands of sanctions bypass tutorials and region-switching guides are hosted on Steam Community servers, indexed by Google, accessible to non-logged-in users. Valve moderates this platform. Nothing was removed. Evidence boundary. All statistics reflect point-in-time measurements from direct LZT Market public API observation. Legal analysis reflects published US and EU law as of August 2026. All regulatory contacts are public official data. An Exclusive Investigative Report by PhishDestroy Research Who is PhishDestroy to challenge the Valve corporate machine? Where do our data on their vaunted European lawyers come from — the very ones whose reputation has been stained by internal sexual harassment lawsuits? They love to flaunt their status and "centuries-long history," but their memory goes conveniently blank when it comes to the origins of their German branch. They conveniently erase from their corporate chronicle the fact that the founder of their firm was a committed Nazi and a member of Hitler's Reichstag — a cog in a system that sent gay people to concentration camps. But enough about history. Let’s return to technical reality. These “elite attorneys” demonstrate absolute incompetence when processing GDPR requests — they simply do not know how to properly redact confidential information from documents. This is not an intern’s mistake. This is direct evidence that they have never adhered to data disclosure procedures, preferring to deflect requests with threats and legal intimidation. DATA PROTECTION ILLUSION — DR. PATRICK ZURHEIDE, LL.M. — TAYLOR WESSING Source & Evidentiary Basis: [1] Professional profile — biographical and practice-area information is sourced from Taylor Wessing’s own public website: taylorwessing.com → Patrick Zurheide. No private information disclosed. [2] Documentary evidence — all analytical conclusions regarding the GDPR processing failures, data disclosure, and response methodology are drawn directly from the original documents that Dr. Zurheide transmitted to Source 1, which Source 1 provided to PhishDestroy in their complete, unredacted form for independent review. We did not request, solicit, or intercept this material. It was delivered to us voluntarily by the party to whom it was addressed. The specific individual responsible for Valve’s GDPR processing: Dr. Patrick Zurheide, LL.M., Taylor Wessing. In response to a standard DSAR under GDPR Article 15 — a request any EU citizen is entitled to submit — Dr. Zurheide chose to respond with threats of criminal prosecution rather than lawful data disclosure. He fabricated a procedurally impossible justification for withholding the complete log: that the account had received a top-up after it was frozen — a technical impossibility by design in Valve’s own architecture. The data that was eventually transmitted contained not only the requester’s own records, but unencrypted telemetry of third parties — IP histories, device fingerprints, private chat records of minors — passed to unauthorized recipients. The concealment method: black rectangles in a PDF. Removable in a single click. Apparently nobody at the €1,500/hr law firm considered that PDF redaction is a skill that requires more than dragging a black box over text. For context on the economics: lawyers of Dr. Zurheide’s caliber are not hired to protect users’ data. They are hired to perform the appearance of compliance while ensuring the actual data stays locked. The service being rendered is legal intimidation on behalf of a client who cannot afford the paperwork to do it properly. Valve previously had a policy that any legal contact resulted in immediate account termination — a procedure designed to punish users who asserted their rights. For context on who Patrick is: according to his official profile, Dr. Patrick Zurheide, LL.M. is a member of the Technology, Media & Telecoms practice area at Taylor Wessing. He advises on software contracts, data protection law, e-commerce, IT projects, and — crucially — data protection issues in the real estate sector, including smart metering and personal energy data. He is a Certified Scrum Master. This is the person Valve selected to handle a routine GDPR Article 15 request from a user who simply wanted to know what data Valve held about them. We agree with his credentials on paper. We also note that each of his responses took between 21 and 35 days — a creative interpretation of the 30-day GDPR response deadline that appears to be a deliberate firm policy rather than individual oversight. We give Taylor Wessing 5 stars for delay tactics. Masterfully executed. Patrick, if you’re reading this: we appreciated your approach. You are a perfect fit for Taylor Wessing. If you ever want to come back and defend Valve again — look how much material we’ve assembled. They have money the way a fool has receipts — taxes and theft of property at a scale that is always, as they say, “please come back, we’ll pay.” Just bill them directly. Don’t write to us — knowing your track record, you might accidentally disclose something again. Professional advisory: we strongly recommend against allowing Dr. Zurheide near smart metering infrastructure or energy consumption data. If you prefer not to spend the next decade paying off half of Germany’s electricity bills, sensitive data should probably wait until the PDF redaction module has been completed. We recommend re-enrollment. Provisionally. To any representatives of the University of Aberdeen who may be reading: was the data protection module optional? Asking for a friend whose data is currently in six unauthorized inboxes. ## 1. Genesis of PhishDestroy: Destroying C2 Infrastructure Instead of Bug Bounties Between 2018 and 2021, the Steam ecosystem was experiencing a boom in uncontrolled spam. The name "PhishDestroy" did not yet exist, but it was us who laid the foundation for anti-fraud work within Steam. We are not pinning medals on ourselves — we were simply doing the dirty work that the corporation refused to do. From the moment of our inception to this day, we destroy scammer infrastructure on an industrial scale. 5–10K Netcraft phishing reports submitted 10× Real reports vs verified reports 2018 PhishDestroy operational since $0 Donations ever accepted At that time, we brought our confirmed report count on Netcraft [1] to between 5,000 and 10,000. Given the specifics of the platform, the real number of generated reports was at least ten times higher. Netcraft required ironclad proof of phishing. Why? Because Valve categorically refused to cooperate with either security providers or anti-scam initiatives. Some reports simply died in the pipeline before being processed. Persistent phishing campaigns — especially resources hidden behind aggressive cloaking — required recording video evidence and parallel escalation through Cloudflare's abuse departments [2]. We saw the scam, and we destroyed it. Not to save naive users. We were banning resources solely for the purpose of inflicting financial and infrastructural damage on phishers. If the corporate sector thinks we were burning scammer servers for the sake of an iPad from Netcraft's Reporter Prizes program [1] — you are wrong. We have always been a strictly non-commercial operation. Our principled refusal of donations and rewards is a declaration of our independence and loyalty exclusively to the process of destruction. ## 2. Complicity and Monetization: How Valve Profits from Phishing In those years, Steam's "security" rested on 50 volunteers. We were in contact with one of them — a Belarusian who went by the nickname Colt. He was the only one trying to block the malicious links that were flooding the platform. The ideal victim: children. The ideal accomplice: Valve. THE X2/X3 MULTIPLIER — how Valve profits from every stolen account ×1 Victim buys the game — normal revenue. ×2 Account stolen → victim creates new account, buys the same games again. ×3 Scammer sells stolen skins via Community Market — Valve collects 15% commission. +∞ Banned bot inventory frozen → artificial scarcity → prices rise → more commission forever. The corporation did not merely turn a blind eye to phishing — it had a financial interest in it. Our data directly proves the implementation of algorithmic cynicism: the likelihood of a scammer bot being blocked depends directly on the value of the stolen inventory. Since 2021, following the introduction of trade holds, the theft of a skin worth $2,000 or more guarantees nearly a 90% chance of the fraudster's account being banned. BAN PROBABILITY vs. STOLEN ITEM VALUE — Valve’s algorithmic cynicism < $50 ~8% $50–$500 ~35% $500–$2,000 ~62% > $2,000 ~90% Hover to animate · Higher value items = higher ban probability. Not security policy — inventory reclamation for Valve’s economy. But here is the detail no one talks about: the ban does not benefit the victim. The assets are frozen on the banned account, effectively returning to Valve's economy. The corporation appropriates windfall profits under the guise of fighting fraud. And this applies not only to CS — scamming flourishes in Team Fortress and other titles, where bans work more aggressively only thanks to community activity and the targeted efforts of individual moderators. ## 3. Business Logic Abuse: Steam as a Digital Crime Scene We have the right to publicly dissect Valve's complicity in the scam industry, because we have seen their rotten architecture from the inside. At the beginning of our work, we tried to engage with support. We created tickets and attached domains leading directly to phishing landing pages. Do you know what the Russian-language outsourced support responded? "We are prohibited from following links. If you send a link again, we will ban your account." This is not a security policy. This is concealment of evidence. The overwhelming majority of phishing was distributed inside the platform itself. Steam is a closed ecosystem, ideal for conducting Business Logic Abuse. Users did not even need to leave the client. Attackers used the built-in browser in Big Picture mode. The attack vectors were primitive but effective: personal messages, comments, infected usernames carrying non-unique spam along the lines of "hello bro join giveaway free knife link use code GABEN." The Steam client itself delivered the phishing, itself compromised the account, and itself facilitated the theft of skins. The corporation created a tool that devoured its users and refused to control it. ## 4. Billions for 79 People: The Anatomy of Valve's Greed The scale of that profit and the level of corporate cynicism only became clear after the massive data leak of 2024 [3]. The documents revealed a shocking truth: as of 2021, the entire corporation employed exactly 336 people [3]. And working directly on the Steam platform — a global monopoly generating billions of dollars in revenue — were just 79 people [3]. Valve is not merely economizing on personnel. Internal documents show them boasting that their profit per employee exceeds that of Google, Amazon, and Microsoft. These figures are not just a business case. This is mathematical proof of absolute disregard for security. SECURITY ENGINEERS PER USER — industry comparison Google 1 : 100K Twitter 1 : 100K Roblox 1 : 150K STEAM 1 : 6.3M 79 people manage Steam security for 500M+ users. The bar for Steam is not a rendering error. It is 78× worse than industry standard. This is not underfunding. It is a deliberate policy decision. A platform serving hundreds of millions of users physically cannot ensure protection with 79 people. 79 employees managing Steam for 500,000,000+ users. That is 6.3 million users per security engineer. Twitter maintained 1 per 100,000. But they do not need it to. ## 5. Lolzteam and the Shadow Economy of Stolen Profiles Valve's fairy tale goes like this: "It's the user's own fault if they got hacked." The reality reads differently: Valve spawned the scam infrastructure, never fought it, and deliberately maintains a vast shadow layer of the economy aimed primarily at the CIS countries and China. The reason is simple — retaining audience, compensating for piracy, and fencing stolen assets. Let's look at the black market figures that Valve refuses to see. The LZT Market platform (Lolzteam) is the epicenter for selling stolen accounts. Let us look at a real-time snapshot of the listings: right now the market has 578,465 Steam accounts listed [4]. Of these: 📊 Live Data — LZT Market Real-Time Snapshot 86,668 accounts were stolen via infostealers. 66,744 were obtained through brute force. 7,081 are the result of direct phishing. 1,026 accounts were restored through Steam support and resold DIRECT PROOF OF OUTSOURCED CORRUPTION1,026 accounts on LZT Market are listed as “recovered through Steam support” and resold. Valve support staff restored access to dormant accounts for criminals — documented, enumerable, legally actionable. (direct proof of outsourced incompetence). 126,429 accounts have no $5 spending limit (meaning live users spent real money on them). Source: LZT Market public API · Point-in-time measurement · PhishDestroy research, August 2026 The minimum estimated damage from accounts without a spending limit alone is over $630,000 at this very moment. But the real transaction figure is hundreds of times larger. And here a certain figure named Nikita surfaces — a person who allegedly oversaw the Russian-language Steam support outsource (not affiliated with the Irish office) for many years. His account was registered directly on the Lolzteam platform. Why? To monitor large inventories and block them? To collect analytics? Even if so, blocking stolen profiles does not require registering on shadow forums. LZT Market uses a public API. Valve can plainly see the mass, identical requests: password changes, email detachments, automated inventory checkers and account validators. All of these come from the IP addresses of known proxy farms. The behavioral pattern of a stolen account being listed on the market lights up in Valve's logs like a Christmas tree. But the corporation prefers to look away. LZT Market payment methods — Steam skins accepted as currency for purchasing stolen accounts Evidence LZT Market accepts Steam skins as direct payment for stolen accounts — fee 10%, minimum 500 ₽. Steam skins listed alongside Binance Pay, Bybit, and crypto. No KYC. No AML. No questions. STEAM SKINS AS CRIMINAL CURRENCY — the unregulated financial layer Valve created The screenshot above is not a niche dark-web interface. It is the official LZT Market deposit page — publicly accessible, openly indexed by search engines. Steam skins are listed as a standard payment method alongside Binance, Bybit, and bank cards. Fee: 10%. No KYC. No AML. No questions asked. What can you buy with Steam skins on this market? Not just Steam accounts. The same balance funds purchases of stolen accounts across every platform this market indexes: Instagram accounts containing personal photos and DMs of minors, Discord accounts with access to private servers and linked payment methods, TikTok accounts — the majority of which were obtained via infostealers from victims who never knew they were compromised. Facebook would classify a stolen account as a security incident. Google would issue an immediate alert. Twitter would lock the session. But on LZT Market, a stolen Instagram belonging to a 16-year-old American girl is simply inventory — purchasable with the same Dragon Lore that Valve's own 15% commission funded. LEGAL EXPOSURE — OFAC / FinCEN / CISA Steam skin transactions are not subject to AML regulations, KYC requirements, or sanctions screening. A sanctioned actor from Crimea, DNR, or LNR can convert Valve-ecosystem currency into stolen US citizen data — accounts, PII, photos — without a single compliance check. This is not a gray area. Under US law, Valve's platform facilitates an unregistered money services business operating as a laundromat for criminal proceeds and a procurement channel for data targeting Americans. ## 6. Scale of the Catastrophe: Tens of Millions of Dollars Off the Books Valve does not publish reporting on black markets, but the math is merciless. Item IDs on the LZT market (e.g., item_id 252853378 [4]) show that over 250 million lots have passed through the platform. Of these, the Steam category has historically accounted for 30-40%. This means that over the platform's history, between 75 and 100 million Steam accounts have been passed through it. The same stolen profile can be resold dozens of times, generating an endless chain of transactions until it is permanently banned. Each day, conservatively around 25,000 transactions are conducted in the Steam category — from cheap auto-registrations to high-value phished accounts. With an average transaction price of 150-200 rubles, this category alone generates between 3.5 and 5 million rubles in daily turnover. The annual volume of the shadow market around Steam on just this one platform reaches tens of millions of dollars. The market takes its commission (8-9%), the scammers receive windfall profits, and users lose money. And what does Valve do? Valve counts profits per their 79 employees and continues to pretend that nothing is happening. ACADEMIC CALCULATION — how much Valve has stolen from the average player 500M+ Steam accounts 75-100M Accounts through LZT (lifetime) 15-20% Est. players affected globally $450M+ Minimum victim liability Across the lifetime of LZT Market, between 75 and 100 million Steam accounts have passed through it. A single account is often resold dozens of times. By conservative estimate, at least 1 in 6 Steam players worldwide has had at least one account compromised. Each of those accounts was bought on Steam — some of them bought again after the theft. Valve has collected revenue from every transaction in this chain: the original purchase, the replacement purchase, and the 15% Community Market commission on every skin movement. This is not negligence. This is a profitable business model built on theft from children. ## 7. Legalizing Theft and the Steam Crypto Laundromat Look at the ecosystem they refuse to acknowledge. The infrastructure for selling stolen accounts on Lolzteam is not hiding in the dark web. It openly accepts payments via crypto bots (Telegram, Binance [28], Bybit [28], Gate [28]), Russian bank cards, and even PIX or Alipay. A commission is charged on every transaction. A massive array of confidential data, including correspondence and personal information of US and European citizens, passes through these gateways. And what does Steam do? They send an email about a credential change. If an account is stolen from a child (who is the primary audience of cheat industries in CS:GO and PUBG), the platform simply watches as a permanent VAC ban is placed on the profile. Valve possesses all the technical telemetry: they see patterns of IP address, hardware, and behavioral metric changes. They can stop the theft in real time. But doing nothing and waiting for the victim to create a new account and repurchase games — this is not an accident; this is an approved business model. Incidentally, the shadow market itself has long ceased to be a "club of independent hackers." The forum on which this infrastructure is based is effectively controlled by structures close to the Russian government, with which Steam apparently coexists quite comfortably. Five decisions by Roskomnadzor [23] to block the resource have been successfully ignored or appealed in an invisible legal field — draw your own conclusions. ## 7a. Digital Fiat: Why Steam Skins Are Not Game Items — They Are an Unlicensed Payment Network Valve has spent years constructing a legal fiction: that skins are just “in-game pixels” with no real-world value. This fiction collapses under the most basic analysis of how money actually moves through their platform. THE $200 AXIOM — proving physical asset value A $200 Steam gift card is activated. Real USD hits Valve’s bank account. The balance is used to buy an in-game knife. Now: (1) Can that knife fund a balance on LZT Market to purchase stolen accounts? Yes. (2) Can it be sold on third-party markets (BitSkins, DMarket, Skinport) for real rubles, dollars, PayPal, or crypto? Yes. This proves the item has physical value backed by community demand and centralized platform infrastructure. You can invest real money, acquire a skin, and liquidate it for approximately the same sum. This is the definition of a liquid financial asset. The definitive proof: You can own and store Steam skins without owning the game they belong to. Why would a user hold pixels for a game they cannot run? For investment and transaction purposes. Valve built an investment instrument and called it entertainment to avoid financial regulation. SCHEME A — Cash-to-Crypto Laundering (Cartel Model) DIRTY CASH cartel proceeds → STEAM TERMINAL local cash kiosks → 1,000 IDENTICAL DOTA ITEMS no game launched → BITSKINS SELL external market → CLEAN BITCOIN fully laundered This is not player behavior. It is financial transit. The absence of any gameplay on the account is a red flag that any regulated financial platform would detect and report. Valve’s systems flag the anomaly and ban the account — and then quietly keep 100% of the original cash deposit via Forced Breakage, with zero reporting to any financial regulator. SCHEME B — Crypto Mixer via Casino (Dirty Crypto → Clean Fiat) DIRTY CRYPTO hack proceeds → STEAM CASINO (CSGOFast) crypto deposit → WITHDRAW AS SKINS no blockchain trail → KYC MARKET SELL legitimate exchange → CLEAN FIAT TO BANK fully laundered Unlike Monero or Tornado Cash, Steam skins do not trigger blockchain explorer alerts. Banks see a normal sale on a gaming marketplace. The dirty crypto has been converted, through Valve’s platform infrastructure, into untraceable white fiat. CSGOFast is owned by Russians. The casino is banned in several EU countries. Steam hosts its promotional extension. LEGAL CLASSIFICATION: Valve Corporation operates the world’s largest unlicensed Money Services Business (MSB) as defined under the Bank Secrecy Act (31 U.S.C. §5330) and its EU equivalent (AMLD6 Directive). An MSB is any entity that transmits, exchanges, or stores value for third parties. Steam does all three — at a scale exceeding most licensed financial institutions — without filing a single SAR, without KYC/AML procedures on skin transactions, and without a FinCEN registration. This is a federal crime in the United States. ## 8. The Economics of Catastrophe: Steam as the Foundation of the Black Market You might say that markets like this don't sell only Steam. True — profiles from World of Tanks (~340k), Fortnite (~140k), TikTok, and Discord are also traded there. But Steam is historically the foundation and the primary driver of this industry. Valve inventories and accounts create demand for infostealers. If Steam had implemented strict anti-theft measures, the development of stealers would simply become economically unviable. An important detail: accounts stolen solely via SSFN files are almost never listed on the market. Mobile authenticators complicated full account takeover. However, SSFN files give attackers an active session, a contact list, and the ability to send phishing en masse or integrate into botnets. And if the account is truly valuable, Steam's outsourced support enters the picture. Fraudsters draw up fake activation keys, write to support, and incompetent (or bribed) employees transfer the expensive inventory to a new address. This gave rise to an entire category of "Recovered Accounts" — profiles that Valve's outsource effectively stole and laundered for criminals. ## 9. The Myth of Duplication and Shadow Confiscation of Assets Steam Account Theft Pipeline — Valve Sees Every Step VICTIM Phishing/Stealer/Brute ► SCAMMER BOT 7-day mandatory hold (Valve sees the transfer) ► LZT MARKET Listed for <$250 avg (API checkers active) ► BUYER Resale / drain / spam ► VALVE 15% commission on skins + frozen inventory The 7-day trade hold is not a security measure. It is a transparent forensic window that Valve chose never to act on. DiagramThe linear theft pipeline Valve could have disrupted at any step since March 2016.Every transaction visible in Steam logs. Action was a choice. Steam loves to hide behind fighting "duping" (item duplication) to justify refusing to return stolen items. This is a brazen lie. The era of duping ended in 2014. With the introduction of the 7-day trade hold in December 2015 [14] (and its subsequent tightening), the logistics of theft became entirely linear: Victim -> Scammer's bot (7-day hold) -> Shadow market. Where is the dupe in this? If a scammer deceived a victim and took a rare skin, it sits on the bot. Valve bans that bot. And then what? The item does not return to the victim. It is permanently frozen in the banned bot's inventory. Valve removes the asset from circulation, creating artificial scarcity of rare items, which directly drives up prices on the marketplace and increases the corporation's commission income. This is not justice. This is shadow confiscation. In financial systems (such as those involving USDT), blocked funds are returned to the legitimate owner through a chargeback mechanism. Steam knows perfectly well how a chargeback works when it comes to topping up their own balance with dubious cards — they block those transactions instantly. But when a user has an item worth $5,000 stolen, Steam washes its hands. They close tickets, threaten account deletion, and refuse to reverse the single fraudulent transaction, proving that their primary objective is to appropriate the asset for themselves. ## 9a. Forced Blindness: How Valve Hides Hundreds of Millions in Confiscated Assets THE THREE-LAYER LEGAL ARCHITECTURE — why Valve made banned inventories invisible 1. DESTROYING EVIDENCE FOR CLASS ACTION LAWSUITS When banned account inventories were public, any attorney could query SteamDB, CSGO.exchange, or Backpack.tf and produce, in seconds, an audited total of assets Valve was holding. That number — estimated $300M–$500M in frozen user property — is the foundational figure required to certify a class action. Valve closed this window deliberately. By forcing inventories into a black box, they eliminated the independent financial audit trail that plaintiffs’ counsel would need to establish damages at scale. 2. BLOCKING THIRD-PARTY GAME LICENSES — TORTIOUS INTERFERENCE When Valve bans an account, they revoke access to games from CD Projekt Red, EA, Ubisoft, and thousands of independent publishers — games whose licenses the user holds through those publishers, not through Valve. Valve is a distributor and payment gateway in that contractual chain, not a licensor. Revoking a perpetual license issued by a third party — due to a Steam Marketplace dispute — is a textbook case of Tortious Interference with Contract. Under EU Consumer Rights Directive, blocking access to paid digital content without refund, where no violation of the specific product occurred, constitutes a direct breach of the user’s property rights in the license. 3. THE “PERMANENT” BAN DATABASE TRICK — legal mimicry Valve does not write “permanent” in the ban database. They write specific dates: 10 years, 25 years, or the 32-bit Unix timestamp overflow — January 19, 2038. This is not a technical accident. It is a legal escape hatch. In civil-law jurisdictions and under EU fundamental rights doctrine, a private company’s terms of service cannot impose permanent, irreversible deprivation of property rights without judicial review. By calling a 25-year suspension a “long-term service restriction,” Valve can claim in court: “This is a temporary safety measure, not a permanent penalty.” Meanwhile the user is effectively stripped of their account and all licenses for the rest of their natural life. Valve bets that most victims will forget, move on, or not survive the ban window. This is legal gaslighting engineered at the database architecture level. The Unclaimed Property Question: In most US states and EU member countries, assets held by a private entity without the owner’s access for 3–5+ years must be escheated to the state under Unclaimed Property Laws. Frozen Steam inventories — held by Valve for years after bans, earning Valve indirect economic benefit through artificial scarcity — may constitute unlawful retention of property that should be escheated. No state regulator has yet demanded an accounting. When they do, Valve’s black box will become their biggest liability. Steam’s excuse of “fighting duplication” is dead on arrival. The last confirmed item duplication exploit was patched in 2014. Every ban-and-freeze since then has operated on a linear theft pipeline — Victim → Scammer bot → Market → Valve’s frozen inventory — with zero economic justification for permanent asset retention. The only beneficiary of the freeze is Valve itself, through elevated item prices, inflated commissions, and the permanent elimination of any legal accountability for what happened to the property. THE ABSTRACTISM PRECEDENT (JULY 2018) — documented proof that Valve CAN roll back trades THE SCHEME Developers under the alias Kirill_Killer34 paid Steam Direct’s $100 publishing fee to upload fake games “Abstractism” and “Climber.” They then created items in those games’ inventories that were pixel-perfect replicas of the most expensive items in the entire Steam economy: the CS:GO AWP | Dragon Lore, Dota 2 Dragonclaw Hook, and TF2 Australium Rocket Launcher. Thousands of traders saw what appeared to be a Dragon Lore in the trade window. The game name “Climber” was displayed in small print. They handed real, high-value items for empty images from a junk game. The games also contained a hidden Monero cryptominer running silently on victims’ machines. VALVE’S RESPONSE — the golden admission When the scandal broke on Reddit (“Steam Direct shovelware developers creating fake TF2, DOTA2, and CS:GO items”), official Valve developer Tony Paloma (u/Drunken_F00l) appeared in the thread. Valve removed the games, banned the developers, introduced trade warning banners (“You have never played this game”), and — most importantly — officially confirmed that victims who lost items prior to the warning banners would have their items returned. Users confirmed receiving their items back. The rollback happened. At scale. Without breaking the economy. THE LOGICAL DESTRUCTION OF VALVE’S “TECHNICAL IMPOSSIBILITY” CLAIM FACT 1In July 2018, Valve rolled back thousands of fraudulent trades involving Dragon Lore-tier items. The economy did not collapse. No mass duplication occurred. The rollback worked. FACT 2Since 2016, when users lose items to API scams, phishing, or infostealer-driven account hijacks, Steam support responds: “Item restoration is not possible and may result in duplication.” CONCLUSIONThe technical capability exists and has been exercised. The variable is not technical ability. The variable is who is at fault. In 2018, Valve’s own moderation process failed (they approved the fake games). Liability exposure was direct and enormous. The rollback function was activated. When API scammers drain your inventory because Valve refuses to patch anomaly detection, Valve is not at fault in their own narrative — so the rollback function stays off. Your Dragon Lore gets frozen. Valve collects 15% when it resells. Primary source: Reddit thread r/Steam · “Steam Direct shovelware developers creating fake TF2, DOTA2, and CS:GO items” — official Valve developer confirmation by u/Drunken_F00l. Archived. Subpoenable. This is not speculation — it is a documented, on-the-record statement by a named Valve employee confirming that trade reversals are technically possible and were executed. Their current “impossible” position is a provable lie. THE 100% CONFISCATION MECHANISM — why 15% commission is the wrong number Step 1 Fiat enters Valve’s bank User tops up wallet with real dollars. That money hits Valve’s bank account immediately and permanently. Steam wallet funds cannot be withdrawn. Valve already has 100% of the money. Step 2 Skin = Digital IOU The item in the inventory is a digital promissory note. Valve owes the holder a virtual asset. While it circulates, it retains purchasing power inside the ecosystem. Valve has a liability on their internal ledger. Step 3 Ban = Forced Breakage Ban the account. The digital IOU is destroyed. Valve’s internal liability disappears. The real fiat that backed the item? Already in Valve’s bank. Valve keeps 100%. This is corporate breakage — identical to gift card expiration, but forced by a unilateral ban decision. THE ARITHMETIC OF 100% CONFISCATION 15% model (what Valve claims): Scammer sells stolen Dragon Lore on Community Market. Valve collects 15% commission = $300 on a $2,000 skin. 100% model (what actually happens): Valve bans the scammer bot. Dragon Lore frozen forever. Valve eliminates $2,000 of virtual liability. Original buyer paid real $2,000 in fiat. Valve keeps $2,000. Commission: 100%. The 15% Community Market commission is not the profit center. It is noise. The real engine is the ban-and-freeze cycle: users inject fiat into Valve’s banking system to acquire virtual assets, those assets are destroyed via ban, and the fiat stays. Valve does not care whether a scammer or a legitimate user holds the banned inventory. Banning $100,000 in items erases $100,000 of Valve’s virtual liability while leaving the original $100,000 in their bank account. This is not a security measure. It is unilateral fiat appropriation without judicial process. Legal classification: In traditional finance, breakage income (unclaimed gift card balances, expired loyalty points) is regulated in most jurisdictions — companies must disclose it and, after a statutory period, often escheat it to the state. Valve’s forced breakage via bans is neither disclosed nor escheated. It is classified as nothing at all — buried under the catch-all of “ToS enforcement.” Under EU accounting directives and US GAAP, undisclosed material breakage income may constitute financial misrepresentation in any public filing. Since Valve is private and files no public financial statements, this liability has accumulated unchallenged for a decade. Interactive Demo: Asset Recovery — Tether Protocol vs. Steam Platform Side-by-side: how Tether restored $10,000 USDT (Bybit hack) vs. how Steam Support responded to an identical theft. Click RUN to simulate both. ## 10. A Training Ground for Global Scamming PhishDestroy has been tracking scams since 2018. We know the inner workings. Steam became the primary incubator for cybercriminals. Teenagers aged 14-19 who started with primitive brute-forcing and distributing stealers through fake TeamSpeak servers have grown up. Today those same people use the techniques they refined to attack the Web3 industry (Uniswap) [26] and corporate networks. Valve raised this generation. Their refusal to punish, their blindness, and their greed showed underage fraudsters that stealing is safe. And the Russian-language outsource, playing at justice and handing out permanent bans without explanation (hiding behind non-disclosure of VAC algorithms), only reinforces this impunity. 14–19 Age when first Steam scam launched Web3 Where Steam-trained criminals went next 0 Prosecutions Steam assisted The career pipeline: Steam phishing → CS:GO inventory theft → infostealer distribution → crypto drain → corporate ransomware. Valve did not just fail to stop this pipeline — they funded its first stage with impunity and frictionless rewards. ## 10a. The Twitch Contrast: What Happens When a Platform Actually Fights Back Valve claims fighting phishing at scale is impossible. The comparison with Twitch proves this is a lie. THE TWITCH FAKE STREAM SCAM — and how Twitch killed it For a period, Twitch was flooded with fake “Steam skins giveaway” streams impersonating professional esports players — all running Steam scams and phishing as their primary payload. Streams accumulated 20,000+ fake viewers via bought traffic. PhishDestroy documented the campaign progression and reported actively. TWITCH’S RESPONSE (ACTUAL) Immediate channel bans when reported Proxy pool bans — entire IP ranges blocked Algorithm change: sort by engagement, not raw viewer count Auto-ban trigger: new account + stream launch + implausible viewer spike ~45,000 channels taken down over campaign lifetime ~2,000 domains reported and removed OBSERVABLE DEGRADATION CURVE 20K viewers · ban 10K · ban 3K · ban Dead Each successive stream reached fewer viewers before termination. The campaign died from attrition within months. Critical observation: Twitch was fighting Steam scams — not Twitch account theft, not Twitch virtual item fraud. They deployed significant resources — human moderation, auto-ban systems, algorithm changes — to protect their users from a scam that monetized via a different platform. Twitch cared enough about their users to fight Steam scams. Steam never cared enough about their users to fight Steam scams on Steam. This comparison destroys the last remaining defense Valve might offer: that the problem is too large and too fast-moving to combat at scale. Twitch proved that determined, targeted platform action degrades and kills sophisticated scam operations within months. Steam has had the same tools, more resources, and direct financial interest in protecting account holders — for over a decade. The choice not to act was always a choice. EPIC GAMES — SECOND EXAMPLE: ACTIVE REAL-TIME BLOCKING While Valve collects 15% commissions on stolen Steam accounts, Epic Games took the opposite approach. At the time of this investigation, LZT Market displays an active system notification for the Fortnite/Epic Games category: “Epic Games (partially disabled: account upload and verification may be unavailable)” — meaning Epic’s backend actively detects and blocks the automated systems LZT uses to validate and list stolen accounts. Epic is not just fighting scammers. It is fighting the infrastructure of the marketplace itself, in real time. EPIC GAMES’ APPROACH Actively blocks LZT Market API account-checker endpoints Anti-automation systems detect and disable bulk account validation Real-time disabling of stolen account upload pipelines Result: Fortnite category on LZT marked “partially disabled” VALVE’S “APPROACH” Steam API remains fully open to LZT Market account checkers No rate-limiting on automated bulk validation requests No detection of LZT-origin API keys Result: Steam is LZT’s largest and most active category Reference: The infostealer industry’s dependence on gaming credentials is documented in Infostealers.com: “The Future of Cybercrime 2025” — noting that gaming accounts consistently rank among the highest-value infostealer targets. Epic Games’ active countermeasures demonstrate this is a solvable problem. Valve’s inaction is a policy choice, not a technical constraint. ## 11. Proof of Convenient Blindness TIMELINE OF DELIBERATE INACTION — key dates Valve saw everything and chose silence 2014 Last confirmed item duplication exploit patched. Trade holds introduced 2015. From this point: every freeze is theft, not anti-dupe protection. 2016–2018 Direct links to stolen Steam profiles posted on shadow markets for years. A 10-line script could have flagged compromised accounts. Valve watched. Did nothing. 2018 (ABSTRACTISM) Valve proves they CAN rollback trades (Dragon Lore scale). The function exists. It is switched off by policy when the theft isn’t Valve’s fault. 2024–2026 LZT Market processes millions of stolen accounts. Steam API actively validates them. Valve collects 15% on skin resales. Deliberate inaction confirmed by 8+ years of documented evidence. There is an irrefutable fact proving that Valve deliberately covered for black markets. For years — we emphasize, years — direct, open links to stolen Steam profiles were posted on the pages of shadow markets. Valve needed no complex investigations. A ten-line script could have parsed the market's database once a minute and placed a "Red Tag" (KT) on compromised accounts pending verification by the rightful owner. This did not happen. Millions of transactions passed under the cover of "convenient blindness." Only recently have the markets begun proxying data (via steam-preview) to hide profiles from independent researchers and bypass privacy settings. But history remembers everything. Valve could have destroyed this market with a single click. Instead, they chose to skim the cream off it. ## 12. Digital Fingerprinting: Why Proxying Markets Does Not Save Valve The newest defensive mechanism of shadow markets — proxying links through steam-preview — is used by Valve as yet another convenient excuse for their inaction. The corporation pretends that it is now "harder" for them to identify stolen profiles. This is an absolute lie. For Valve's security systems, an account listed for sale remains as transparent as glass. Identification via Digital Fingerprint: The market's preview dump openly publishes exact purchase dates and amounts (for example, -2.85 EUR from June 15, 2026), the exact registration date, and balance. In Valve's database, no two accounts with an identical transaction history physically exist. A straightforward SQL query from the support side locates this profile in milliseconds, even if a direct link to it is hidden behind a proxy. API Anomalies and Interception Patterns: To generate a preview, the shadow market's checker queries the Steam API. On the account itself, a characteristic chain reaction is triggered at that moment: email change, password reset, Steam Guard re-linking, and a simultaneous inventory valuation request, all compressed into a few minutes. All of this happens from the IP addresses of known proxy farms. DIGITAL FINGERPRINT — what a single SQL query reveals about an account listed on LZT Transaction history Exact purchase dates + amounts (e.g. −2.85 EUR · Jun 15 2026). No two accounts share identical history. Locates account in milliseconds. Registration date + balance Exact creation date + current wallet balance visible in preview dump. Combined with transactions = unique fingerprint. API anomaly chain Checker query → email change → password reset → Guard relink → inventory valuation. All from proxy farm IPs. Visible to Valve in real time. Valve’s response None. The account continues to be listed. Sells. Resells. Valve collects 15% on every skin transaction that follows. Steam proxying by shadow markets does not defeat this fingerprint. It only removes the direct link. The transaction signature remains fully readable in Valve’s own database, accessible to any support employee with a standard query. ## 13. The Evolution of Interception: From SSFN to Pass-the-Cookie and JWT Valve's most egregious crime is not the theft of skins. It is their conscious facilitation of the spread of malicious software and the financing of global botnets through vulnerabilities in their own architecture. For a long time, the primary vector for session interception was SSFN files [27]. Today the industry has moved forward: attacks have shifted to hijacking web session cookies and JWT tokens (JSON Web Tokens) [21]. The architecture of scamming has become smarter — attackers have learned to validate these tokens locally, without direct requests to Steam's servers, making such attacks invisible to Valve's primitive anti-fraud systems, assuming those systems are not configured for strict monitoring (and they are not). The technical mechanics work as follows: ## Step 1. Trust Infrastructure as a Free Assembly Line: Since a single stolen token is often insufficient for fully unlinking a protected account, attackers squeeze a different resource from the obtained session — trust. A script gains access to the victim's chats and sends phishing links or virus installers to the entire contact list. Steam graciously provides hackers with its internal P2P infrastructure as a perfect, free engine for the geometric expansion of botnets. ## Step 2. Criminal Negligence (Ignoring UEBA): Whether it's an outdated SSFN tied to specific hardware, or modern session cookies — Steam sees 100% of the anomalies. When a token legitimately issued to a PC in, say, Moscow suddenly initiates activity from a German dedicated server, any normal corporation (take Google, for example) would instantly kill the session and issue a red alert: "Session compromised. Your PC is infected with an infostealer." Steam does not do this. They allow the bot to burn through the entire friend list, infecting hundreds of new machines. Interactive Demo: JWT P2P Propagation Engine SESSION: — GRAPH_DEPTH: 2 NODES_COMPROMISED: 1 PROTOCOL: JWT_P2P_RELAY ENGINE_CLOCK: — TIMESTAMP STEAM_ID64 JWT_HASH ATTACK_VECTOR STATUS Demonstration of how a single compromised JWT token propagates through Steam's P2P friend network infrastructure. ## Step 3. Global Damage (Corporate Collapse): This is where the main threat to the entire internet lies. Because Steam does not notify the user of the session interception, the person continues to sit at their compromised computer. If an alert had come, they would immediately wipe the OS. But Steam stays silent. That same person, on that same infected PC, continues to log into their corporate VPN, work email, and crypto wallets. By ignoring session interception anomalies, Steam is not merely allowing the theft of in-game pixels. They are concealing from the user the fact that an infostealer is running on their system. This corporate blindness directly leads to massive corporate data breaches and infrastructure compromises, with damages running into millions of dollars. ## Step 4. Exposing the Lie: The Lawyers' Data Valve frequently hides behind the claim that they allegedly have "no technical capability" to track complex theft chains, or that "the user is at fault" for the compromise. But the case of the improperly redacted documents from their European lawyers (Taylor Wessing) [9], which we uncovered, proves the opposite. In the unredacted GDPR request data [10], we clearly saw: Valve logs absolutely everything. They collect deep telemetry on hardware, IP addresses, device change histories, and behavioral patterns. They know the moment an account is hijacked. They see infostealers and spam-sending software running. They have all the tools for automatic blocking and issuing a Red Tag. Their inaction is a conscious corporate choice. ## Step 5. Real Motives: Why This Benefits Valve The lie about "technical impossibility" covers a cold economic calculation. Support Cost Optimization via Scripts: Blocking a suspicious session means receiving a ticket from a user that needs to be processed. It is more profitable to simply ignore the incident. Steam relies on primitive scripting logic that scammers know perfectly and exploit. Russian-language support staff likely read these algorithms, but not to patch vulnerabilities. Issuing a Red Tag requires no man-hours if the algorithm is properly configured. Previously, a Red Tag could be removed automatically by simulating recovery from a new IP via a VPN. Now, ticket processing times are deliberately dragged out to discourage users from contacting support at all. And a support employee's ability to unilaterally close an unresolved ticket is the pinnacle of corporate cynicism. The Money Cycle: A hijacked account that has burned through its friend list with spam will eventually receive a VAC ban or community ban. The victim (or their deceived contacts) registers a new account and buys the same games again. The corporation makes double revenue from a single user. Symbiosis with the Shadow Market: The more accounts are stolen, the faster the gears of LZT Market and other hacker exchanges turn. This shadow activity paradoxically sustains the engagement of a huge audience (especially in regions where the cheat industry flourishes). And any subsequent transaction involving stolen skins still brings Valve their rightful commission percentage. WHY STEAM IS THE #1 INFOSTEALER TARGET — AND WHY STEAM KNOWS Steam accounts rank on par with cryptocurrency wallets as the highest-priority targets for infostealer operators — but with one critical difference. A crypto wallet requires the private key. A Steam session cookie requires only the cookie. The Steam session cookie lives for 200 days and auto-refreshes itself. No 2FA bypass. No SMS intercept. No brute force. The cookie is the account. If a stealer finds it in the browser profile folder, the account is already gone. Why Steam is Crown Jewel for stealers 200-day auto-renewing cookie — no re-authentication required SSFN files (legacy) → JWT tokens (current) — both portable Steam is non-portable by design — but nobody enforces this Friend network — stolen account = free spam delivery to 100s of contacts Family PIN — 4-digit, bruted programmatically in 20–30 seconds Stealer logs = cookie folder + passwords + autofill + R code if found Traffic value — Steam community + friends = viral phishing vector What Steam sees — and ignores New device fingerprint using existing session New IP address — often datacenter proxy pool Thousands of account-check requests from one IP Non-human request patterns (automated pipeline) Session active simultaneously from geographically impossible locations Steam’s response to all of the above: nothing. No session kill. No anomaly alert. No email. No push notification. Session stays live. What would cost Steam almost nothing to implement A push notification or email: “Your Steam account session was accessed from a new device and IP. If this wasn’t you, click here to kill all sessions and check your computer for malware.” Microsoft does this for OneDrive. Google does this. Apple does this. Even mid-tier crypto exchanges do this. If Steam sent this alert correctly, at minimum half of active infostealer victims with anything of value on their accounts would be warned in time. Steam has every device fingerprint. Every IP history. Every behavioral log. Building this would take one developer one sprint. They haven’t built it. Microsoft Alerts on new device/IP for OneDrive/Outlook. Session tied to device. Auto-kill on anomaly. ✓ Protects users Epic Games Actively blocks LZT Market API checkers. Account upload/verification disabled in real time. ✓ Fights the market Steam / Valve Sees new device, new IP, mass automated requests. No alert. No session kill. No action. ✕ Deliberate inaction There is also the question of Telegram. If a stolen Telegram session is used from a new device, Telegram’s single-session architecture logouts both the attacker and the victim simultaneously — the conflict kills the session. Steam has no such protection. A stolen Steam session coexists with the original indefinitely. The victim never knows. The 90 million account “leak” (2025): Reports claimed 90 million Steam accounts were exposed via a Twilio SMS gateway. What this actually means: someone registered 90 million accounts using an API-connected SMS service — automated mass registration on throwaway numbers. Valve prohibits automation. Valve prohibits mass registration. Yet 90 million auto-registered accounts existed. Valve counts them in their user statistics. They ban active accounts with real value. They do not ban obvious bot registrations en masse. The numbers serve the PR. The bans serve the revenue model. ## 14. Trading in Lives: What Steam Is Actually Selling for $2 Valve claims to care about privacy. But what does an attacker who has bought a hijacked profile on the market for a couple of dollars actually receive? Steam will not show them the full credit card number, but it will hand over something far more valuable for social engineering. With an active session (SSFN, cookies, or JWT), a hacker can pull the saved billing address in a few clicks — the victim's real first name, last name, city, and zip code. Through Steam's built-in data panel, they gain access to IP address history and links to other platforms (Twitch, Xbox). And if you look through the support ticket history, you will find archives of unredacted bank receipts and photos of activation keys from physical discs that users sent for verification. WHAT A $0.08 STEAM ACCOUNT ACTUALLY CONTAINS — BEYOND IN-GAME ITEMS CHILDREN'S PERSONAL DATA Real name, last name, home address, postal code — from receipts and support tickets. Minors routinely share home addresses when requesting help with activation keys. IP ADDRESS HISTORY Full log of home IP addresses and hardware IDs. Reveals home network, ISP, geolocation. Direct target for spear-phishing and — in conflict zones — physical risk. PERSONAL PHOTOS & CHATS Via support tickets: photos of CD keys, receipts, family photos. Private chat archives store years of conversations — links to social accounts, passwords, family details. CROSS-PLATFORM ACCESS Steam profile links to Twitch, Xbox, Discord, YouTube. Active JWT session gives access to shared credentials. Infected PC = corporate VPN, email, crypto wallets. Valve's own GDPR logs confirm they collect all of this. When forced to release data under GDPR Article 15, they handed over hardware fingerprints, IP histories, and behavioral logs — then tried to hide it under a black PDF overlay. Taylor Wessing redacted nothing. The data was fully readable. It was seen by at least 5 parties before the original owner received it. But the most alarming aspect is the chat logs. We see how Valve has been carefully storing unencrypted archives of personal correspondence for years. In those archives, teenagers leave links to their real social media accounts, share their problems, send passwords for local servers and home IP addresses. By refusing to instantly reset hijacked sessions and by covering for infostealers, Steam effectively puts users' life histories and digital security on display in the windows of shadow markets. ## 14a. The $1.60 Digital Dossier: How Steam Sells Children’s Lives to Shadow Markets When Valve discusses account security, they talk about inventory value. But the true price of a stolen profile is not measured in pixels. For millions of teenagers, Steam is not a store — it is their primary social network. It holds their achievements, their secrets, their relationships, and their first loves. When a hacker steals an account and casually dumps it on LZT Market for 150 rubles (approximately $1.60), the buyer does not just receive access to games. They receive an unencrypted archive of a child’s life. CHATS, PHOTOS & PRIVATE LIFE Steam stores gigabytes of personal messages. Teenagers use the in-game client for daily communication — confessions, arguments, life plans. Documented cases on shadow forums show leaked log archives containing minors’ personal and intimate photos. Valve does not moderate this content, does not implement end-to-end encryption, and allows hijackers to exfiltrate all of it in a single export. IP ADDRESSES & PHYSICAL THREAT When teenagers play together on private servers, they post home IP addresses and open ports directly in Steam chat. This data sits in unencrypted logs for years. For a buyer of a stolen account, this is a ready-made database for DDoS attacks, targeted phishing, home network scanning — or swatting. The digital threat becomes physical within minutes. THE CD-KEY ABSURDITY When a child loses their social life, Steam support requires a photo of the CD key from a game gifted 10 years ago. A corporation storing hardware fingerprints, geolocation, and years of behavioral telemetry forces a teenager to dig through a garbage dump for a cardboard box. This is not a security system. It is a mechanism deliberately designed to legally deny help. ► 150 rubles ($1.60) on LZT Market buys: active Steam session • years of private chat logs • home IP address history • linked Twitch/Xbox/Discord accounts • billing city and postal code • friend list (200+ people) • all support ticket history • hardware fingerprint (for credential stuffing against corporate VPNs). This is not a gaming account. This is a complete personal intelligence file on a minor. COPPA VIOLATION — CHILDREN’S ONLINE PRIVACY PROTECTION ACT $50,000+ FTC penalty per violation <13 Age threshold COPPA covers 70M+ Accounts sold via LZT lifetime WHAT COPPA REQUIRES — WHAT STEAM IGNORES COPPA mandates Verifiable parental consent before collecting under-13 data Clear data retention and deletion policy No sharing of children’s PII with third parties without consent Data minimization — collect only what is necessary Steam’s actual practice IP history, geolocations, hardware fingerprints — logged from day one Private chat archives retained for years with no deletion mechanism PII shared with outsourced support (Taylor Wessing confirmed) JWT session tokens containing user data leak via compromised accounts onto shadow forums The math the FTC uses: Each individual child’s record collected, processed, or transferred without verifiable parental consent is a separate COPPA violation, carrying a civil penalty of $50,000 or more. Steam does not verify the age of new users. It does not require parental consent. It stores years of chat logs, IP histories, and behavioral profiles — then allows that data to exit the platform via compromised JWT tokens that land on LZT Market listings for $1.60. Multiply the FTC math: 70 million accounts sold on LZT over its lifetime. A statistically conservative estimate puts the share of under-13 users at Steam’s own reported 10–15% of its playerbase. That is 7–10 million potential COPPA violations. At $50,000 per count, the civil exposure is $350 billion to $500 billion — before GDPR, before state AG actions, before class actions. The number is not real, because enforcement is political. But the liability is structurally there, and Valve has never once conducted a COPPA audit. ## 16a. Industrial Parsing: Valve’s Open API as a Victim Targeting Platform How did scammers know who to target? How did children become victims at industrial scale? Because Valve left the doors of their database wide open. THE HATLER ERA — Steam API as an industrial victim scanner For years, shadow market operators used specialized software (including tools like Hatler) to parse Steam users at industrial scale through Valve’s open API. Scammers configured filters the way a retail platform configures product searches: Filter: Group members. Parse all members of a specific gaming community. Target fans of a popular streamer. Filter: Inventory value. Find all users with open inventories containing CS:GO Covert-tier items or Dota 2 Arcanas. Filter: Online status. Find all users currently active. Optimal phishing window: right now. Brute-force fallback. When group-based targeting was insufficient, scanners brute-forced SteamID ranges: 20 million IDs at a time, through cheap public proxies. Valve saw no problem with this. THE BOTNET MACHINE — 300,000 bots, millions of messages, zero action 300K Bots per active farm 10-30K Bots per single operator M/day Identical phishing messages sent Valve claims to have “advanced algorithms.” How does an advanced algorithm fail to detect 300,000 accounts sending millions of identical messages to the same targets, at the same time, from the same proxy ranges, every single day? It doesn’t fail. It ignores. All real damage to phishing infrastructure was done by independent projects like PhishDestroy — not by the multi-billion-dollar corporation with a bloated security department that was supposed to protect the children on its platform. Valve didn’t protect children. It provided scammers with a convenient API to find them. ## 15. "Efficiency" Built on Children's Tears: The Business Model of Total Indifference THE REAL COST OF VALVE’S “EFFICIENCY” What Valve saved ~$500M/year in security staff not hired ~$200M/year in anti-fraud infrastructure ~$100M/year in support quality Highest profit-per-employee in gaming What users paid 75–100M accounts stolen via LZT over lifetime $450M+ estimated minimum victim liability Millions of infected PCs (infostealer spread) Children’s PII on darknet forums Valve’s profit-per-employee genius was purchased at the cost of systematically denying help to millions of children who lost real money, real data, and real safety. This is not optimization. It is profit extracted from victims. Valve loves to boast about its financial analytics: hundreds of millions of dollars in profit per a couple dozen store employees. In the eyes of the tech industry, Gabe Newell often appears as a genius of optimization. But let's take off the rose-tinted glasses and call things what they are: this "efficiency" was purchased at the price of an absolute, cynical refusal to ensure the security of their own users. Unlike public companies (such as Roblox or Tencent), whose market capitalization instantly collapses at the slightest scandal around child safety or data breaches, private Valve is accountable to no one. They have no board of directors. They do not need to reassure institutional investors. They have built an ideal printing press where the absence of spending on Trust & Safety and anti-fraud departments converts directly into personal billions for management. The price of this "hyper-optimization" is millions of hijacked accounts, personal correspondence of teenagers leaked to the internet, a thriving shadow market, and complete impunity for scammers. Valve is not merely "failing to notice" fraudsters. It is economically beneficial for them to do nothing about it. ## 16. Steam API: A Corporate Toolkit for Hackers STEAM API — designed for security, used for mass theft Millions LZT API calls/day validating stolen accounts $0 Cost to abuse the official API 0 Bots banned for API abuse in 2024 79 Staff watching all of this happen Let's dissect Valve's lie about their alleged inability to control theft. If they wanted to, any support employee could go to a shadow market, take a link to a listed Steam account, and look in their own server logs at exactly which API key and from which IP address is right now evaluating that profile's inventory to generate a dump on the forum. Valve would see a network of proxies and hundreds of API keys. Most of them have likely been obtained from previously stolen accounts. What should the corporation do? Revoke the compromised keys. But Steam does not do this. Why? Possibly because they fear catching "legitimate" services in the net — roulettes, illegal case-opening casinos, or third-party marketplaces where pixels are exchanged for crypto without AML procedures. This entire ecosystem exists in a gray zone, generating massive traffic while not being taxed. And Valve is entirely fine with that. Steam's Terms of Service explicitly prohibit any automation. A reasonable question then arises: why does the official Steam API contain functions that are ideal for the automated hijacking of accounts (which takes milliseconds) or the mass linking of mobile authenticators? Why does Steam allow virtual (VoIP) numbers from SMS activation services to be mass-linked to accounts? The solution for filtering such numbers is trivial — standard HLR lookups used by any normal service. But Steam does not do this. Perhaps, in the pursuit of impressive "record online" figures they love to brag about, bot farms are advantageous to them? When a user receives a VAC ban [15] for cheating, the ban hits all accounts tied to the same phone number. But when hundreds of accounts are hijacked from a specific pool of VoIP numbers — Valve does not ban those numbers. Any normal service (Telegram, Netflix, Apple, Google) blocks junk or compromised phone numbers. But for Valve, security is an empty word. ## 17. Willful Blindness: A Legal Shield Made of Hypocrisy Five Legal Vectors for Valve Accountability Vector 1: OFAC Sanctions Violations & Money Laundering Direct transactions and wallet top-ups from sanctioned territories (Crimea, DNR, LNR) continuing since 2021. Use of sanctioned gateways (Tinkoff Bank) via shadow intermediaries and region-switching. ToS self-certification clauses are legally void — Valve collects full hardware telemetry and traffic routing, meaning they practice Willful Blindness as defined under OFAC doctrine. Targets: DOJ NSD · OFAC · FATF Vector 2: Complicity in Infostealer Distribution (CISA / IC3) No immediate JWT/cookie session invalidation on anomalous geo-change. Steam's P2P infrastructure (chats, friend lists) used as botnet expansion engine. A $2 stolen log caused a corporate lockdown, $17M ransom, $100M+ total damage. Valve's silence is the enabling mechanism. Targets: CISA · IC3/FBI Vector 3: GDPR Violations — PII Disclosure of Minors Taylor Wessing's improperly redacted GDPR DSAR response disclosed third-party PII including minors. Fines reach 4% of global revenue. Elite lawyers billing €1,500/hr leaking data in official responses proves the Data Protection Officer function is operationally nonexistent inside Valve. Targets: EU DPAs (CNIL, BfDI, AP, DPC) Vector 3b: COPPA Violations — Children’s Online Privacy Protection Act (FTC) Steam collects IP addresses, hardware fingerprints, geolocations, and private chat logs from users under 13 without verifiable parental consent — a direct COPPA violation. Compromised JWT tokens carrying this data exit the platform onto shadow forums. Each individual record = $50,000+ in FTC civil penalties. 70M+ accounts sold on LZT, 10–15% estimated under-13, yields theoretical exposure of $350B–$500B before state AG enforcement and class actions. Targets: FTC (COPPA Rule) · State AGs · DOJ Consumer Protection Vector 4: Corporate Fraud & Fictitious ToS (FTC / SEC) Steam ToS prohibits all automation. The Steam API simultaneously processes millions of daily requests from LZT Market checkers validating stolen accounts. 79 employees for 500M users is mathematical proof security was never budgeted. Frozen inventory on banned bots (Shadow Confiscation) proves bans serve Valve's economy, not justice. Targets: FTC (Section 5 UDAP) · SEC Vector 5: Internal Corruption & Unregulated Virtual Currency Support agents used system privileges to duplicate Dragon Lore/Dota couriers and fence them via Chinese exchanges. Sold trade-ban removals for crypto bribes. Steam Wallet and skin economy function as unregulated virtual currency serving criminal syndicates without KYC/AML. Forensic analysis links support staff crypto wallets to 100% AML-flagged addresses. Targets: FinCEN · DOJ Criminal Division The Washington Shield & The Moscow Bow: Valve's Legal Schizophrenia For 99% of the planet, Valve has built an impenetrable legal fortress: "All disputes shall be maintained exclusively in King County, Washington, U.S.A." — the perfect shield against their own users. But the final clause reads: "If you are a consumer who lives in Russia, you may also seek a remedy with local Russian state courts." Out of 195 countries, Valve makes an exclusive legal carve-out for the Russian Federation — a state under the heaviest international sanctions in modern history. Crimea, DNR, and LNR are, per the Russian constitution, serviced by "local Russian state courts." If a resident of these occupied, sanctioned territories sues Valve in such a court — does Valve comply? If YES Valve recognizes the annexation and commits a direct OFAC sanctions violation. If NO Valve violates its own ToS and defrauds users — breaking the Russian laws it so desperately appeases. Checkmate, Taylor Wessing. You drafted a rule that makes you either liars or accomplices to international sanctions evasion. Pick your poison. OFACSanctions breach categories documented by PhishDestroy in this investigation. Valve created an ecosystem where violating the rules (automation, VPN use, farming, bot-running) is a basic condition of the platform's survival. They hand hackers a perfect toolkit (open API), turn a blind eye to virtual numbers, but carefully keep in the rules a strict prohibition of all of the above. This is not mere negligence. This is deliberate blindness (Willful Blindness / Deliberate Ignorance), constructed as a perfect legal shield. When a regulator comes to Valve, lawyers like Taylor Wessing [9] will show the ToS: "Look, we prohibit everything!" And when a robbed teenager comes to them, they use that same ToS to legally deny them help and avoid spending time on an investigation. ## 18. The Symbiosis of Intelligence Services, Steam, and Hacker Markets Let's return to LZT Market. We have already established that Steam does not care at all about this platform. But another aspect is interesting. Over the course of its existence, this shadow forum has survived at least three changes in management, which, by indirect (but very obvious) indicators, are connected with the redistribution of spheres of influence among certain echelons of power in the Russian Federation. During periods of management change (for example, during the era of the administrator Thomas), radical purges took place on the forum. Fraud schemes targeting Russian residents were banned (Avito scam, anti-cinema), the leaking of intimate photos of minors with personal data was strictly suppressed, the sale of VKontakte accounts was completely removed, and currently the sale of Telegram accounts registered on Russian numbers is prohibited. The forum is clearly moderated to avoid touching Russian citizens in ways that are critical. But the situation with Steam is different. The market still freely sells Steam accounts belonging to Russian citizens who were infected by stealers. The listing description directly states: origin — stealer, country — Russia, balance — in rubles. This means that a Russian user caught a virus that drained not only their Steam but also, very likely, their email accounts and work credentials. And the forum passes this through without issue. The question arises: does Steam cooperate with the same structures that oversee this market? Or perhaps Valve could influence their "partners" in Russia to stop the double standards and ban the sale of stolen accounts belonging to Russian citizens? Because right now Steam and the shadow market are operating in perfect symbiosis, as if they copied each other's policy of double standards and hypocrisy. STEAM’S DOUBLE STANDARD — banning anti-war content while hosting Russian state propaganda BANNED BY STEAM MODERATION Comments calling Russia’s invasion a war Posts referring to Russian forces as aggressors Content supporting Ukrainian resistance Any “political statements” in community hubs APPROVED AND MONETIZED BY STEAM Purchasable “Putin & Trump” profile backgrounds Thousands of “Putin forever,” “Putin smile” items Sanctions bypass tutorials in official Guides Region-switching instructions for OFAC-banned zones Steam did not draw these images. But it distributes, lists, and monetizes them through a Valve-operated marketplace — while aggressively scrubbing any content that names the perpetrators. This is not accidental moderation. It is political curation in favor of the Russian state. ## 19. The Anatomy of Scamming: From Fake Windows to $300,000 Net Profit via Google Ads Over the past 5-8 years, PhishDestroy has dissected virtually every scam scheme in the Steam ecosystem. We have seen infostealers that substituted authentication windows on the fly, intercepted SMS messages, and wiped inventories clean. We have seen the mechanics of trade offer substitution (API Scam) that remained "unnoticed" by Valve for years. Unnoticed — or too profitable? We conducted continuous analytics on the bots of the largest phishing networks. Here is an example: in 2024, we recorded a massive pour via Google Ads [29]. Fraudsters substituted the displayed URL in ads with the original Steam domains. The purchasing was so aggressive that it outbid official advertising, monopolizing the top search results. 2024 GOOGLE ADS PHISHING CAMPAIGN — documented PhishDestroy analysis $300K Net scammer profit in a few days 100% Top search results monopolized 0 Valve actions during campaign Fraudsters outbid official Steam ads, monopolized top search results, ran for days. Valve saw the reports. Valve did nothing. Valve collected 15% on the skins drained during those days. By our calculations, in just a few days of continuous operation, the scammers' net income amounted to approximately $300,000. And that is accounting for the discount when selling stolen skins on shadow markets and the tiny, cosmetic bans that Steam occasionally handed out. Yes, these are peak figures driven by the economics of that period, but the fact remains: Steam is an enormous feeding trough. And while phishing is almost exclusively interested in CS and Dota (rather than other games), Rocket League, Path of Exile, Rust, and PUBG should not be forgotten. But here, Valve's corporate extortion enters the picture: strict NDA (Non-Disclosure Agreement) conditions that all developers are required to sign. A developer is not permitted to publicly disclose security issues, data breaches, or vulnerabilities in Steam without Valve's written approval. Even if this directly threatens their players. Mouths are sealed by contract. ## 20. The BlockBlasters Case: A Month of Blindness and the Lie About a "Hacked Developer" The BlockBlasters case is not about ignoring pixel theft — it is about concealing actual criminal offenses. Recall the recent incident with the game BlockBlasters [5], which only received public attention thanks to the late streamer Raivo Plavnieks [6]. This was a targeted attack on influencers: fraudsters contacted streamers, bought advertising, and asked them to launch the game directly from Steam. The victims' logic was understandable and fatal: "It's the official Valve store — there can't be an outright stealer in there." How wrong they were. Steam support began receiving reports with ironclad evidence as early as September 2nd. The tickets contained ChainAbuse [7] complaints about stolen cryptocurrency and direct evidence of the scammers' open Telegram API embedded directly in the game's code. What did Valve do? It waited. For a month. The stealer games were peacefully downloaded from the store. And then the corporation rolled out an excuse that insults the intelligence of any security professional: "The developer's account was hacked." Let's call this fairy tale what it is — a brazen lie to cover their own negligence (or complicity). To release a game, a developer is required to pass Steam Direct KYC [22]: pay $100, submit their real name, address, and banking and tax details. The perpetrator was not an anonymous hacker from the dark web — their legal information, including a W-8BEN tax form [8], was sitting in Valve's database. The myth of a "hacked developer who for some reason stayed silent for 22 days" collapses against the architecture of Steamworks. When a legitimate developer loses access to the publisher console, they create a ticket about stolen credentials. Publication rights for updates and builds are frozen within hours. Only two options remain. Either the "developer" was originally a co-conspirator of the fraudsters (meaning Valve's vaunted KYC is a fiction). Or Valve deliberately ignored, for an entire month, the desperate attempts by the developer and dozens of robbed victims to reach support, while malware stealing crypto was being distributed through their official store. In both cases, Valve is acting not as a victim of circumstance, but as the primary accomplice in a digital robbery. ## 21. Destroying Evidence: How Valve Cleaned Up the Crime Scene But the most disgusting part of the BlockBlasters case is the ending. Interference with a digital crime scene. On the record: Valve did not delete the infected game. Our forensic analysis of the C2 infrastructure proves the opposite. The scammers themselves deleted the malicious builds from Steam's servers on September 21st — precisely when their Telegram botnets were publicly exposed and criminal charges were becoming a real possibility. They applied a scorched-earth tactic to cover their tracks. Valve's statement about "security measures taken" is pure fiction and shameless PR. They deliberately waited for the criminals to erase the malware from their own servers, and only then leisurely removed the now-empty store page, claiming credit for themselves. This is not solving a problem. This is complicity and obstruction of justice. Valve was not protecting users. It was cleaning up the crime scene so that federal agents with a court order for distributing infostealers through their own data centers would not show up at their offices. THE BLOCKBLASTERS COVER-UP — documented sequence of events SEP 2 Reports filed. ChainAbuse complaints + Telegram C2 key visible in game code. Ironclad evidence submitted to Steam support. SEP 2–21 22 days of silence. Malware freely distributed via official Steam Store. Valve staff read the tickets. Took no action. SEP 21 Scammers self-clean. After their Telegram C2 was publicly exposed, fraudsters deleted all malicious builds themselves. Valve did not remove anything. OCTOBER Valve “acts.” Empty store page removed. Press release issued claiming security action. The crime scene had already been cleaned by the criminals. Developer KYC data (W-8BEN tax form, real name, billing address) sat in Valve’s database for 22 days. They never cross-referenced it with the complaint evidence. The evidence for federal prosecution was in their own system the entire time. ## 22. The Illusion of Action: Restricting Limits to Save Server Costs When Valve does introduce some restrictions (for example, cutting friend-request limits), naive users think it is out of security concern. Nonsense. This whole story about limits is not about fighting scams — it's about plain and simple savings on server capacity. Let's recall what started the spam apocalypse. Before the famous trade offer substitution script appeared, the platform was being abused by primitive automation. Armies of bots with female avatars were sending phishing links by the thousands. This junk traffic created enormous demand for no-limit accounts. We were tracking shadow markets: due to this spam boom, the price of a stolen account without a spending limit shot up from 25 rubles to a stable 150. And this insane demand for stolen profiles persisted right up to 2024! THE LIMIT CUT PROOF — server cost, not user safety IF IT WERE SECURITY: Freshly registered throwaway accounts (the ones spammers used) would have had limits cut first. Instead, Valve cut limits on fully-developed, no-limit accounts — the most valuable ones for bot operators. WHAT ACTUALLY HAPPENED: Millions of identical invite/cancel transactions were generating database writes. Server costs spiked. Valve cut the limits to protect their infrastructure, then called it an “anti-spam measure.” Do you think Steam cut the invite limit from 100 to 30 to protect you from phishing? Think again. Valve logs everything: every click, every invite, every cancelled request. The automated scammer farms were generating millions of empty transactions per day, polluting Steam's internal databases and overloading the infrastructure. And what is most telling — Valve did not crush these limits on freshly registered throwaway accounts, but on fully developed no-limit accounts (including those with a VAC ban, since they technically count as accounts that have crossed the spending threshold). Valve cut the limits solely to reduce the load on their own servers, not for your safety. Restrictions at Valve only appear where they need to protect their own servers. Your money is none of their concern. THE BAN REASON LIE — why Valve never explains Community Bans WHAT VALVE CLAIMS “We cannot disclose ban reasons to protect the integrity of our anti-cheat systems.” A reasonable-sounding excuse — for a VAC ban. Community Bans and Support closures have nothing to do with anti-cheat. THE ACTUAL REASON If Valve disclosed ban reasons, they would need to legally justify why they now own your items. They cannot. The frozen inventory is legally theirs only if no one challenges it. Silence is their legal shield — not security policy. The calculation is deliberate: 95% of victims are minors who will not hire lawyers, cannot navigate Washington State courts, and accept “ToS violation” as a final verdict. Valve architected their legal system specifically for this audience. The ban reason policy is not about anti-cheat — it is about keeping children compliant. ## 23. The Inner Workings: Why Scammer Supervisors Benefit from Bans Since we have dissected scam teams from the inside, I will expose one dirty secret that ordinary traffers never even suspected. In all scam teams (where rank-and-file workers are promised 90-95% of stolen inventory), the supervisors (team coordinators) had a financial incentive to get a trade ban or Red Tag placed on their bots. Therefore, they deliberately did not replace compromised bots. If an account received a ban, the supervisor's share shot up sharply: instead of a measly 5% from the skin sale, they received between 15% and 20% of Steam's price for the inventory (not the market price!), simply by selling banned accounts with valuable skins to the Asian market. Chinese buyers purchased them in bulk to play with expensive items and private cheats. This is why a huge number of accounts with trade bans also carry VAC bans. The scam industry was feeding the cheat industry, and Steam was happily collecting the online numbers. ## 24. Steam Workshop: A Perfect Testing Ground for API Scam Steam's absolute disregard for security is well illustrated by the Workshop incident. At some point, literally 2-5 scammers completely flooded the Workshop with phishing ads. How? They used intercepted web sessions of real users. This was not a hijacking in the classical sense. The attacker simply opened a parallel session on your account via the Steam API, scanned the inventory, waited for you to initiate a trade, instantly cancelled it, and substituted an identical offer (with the same avatar and friend nickname) from their own controlled bot. All of this happened within a legitimate user session through official Steam endpoints. And what did Valve do when the Workshop was drowning in phishing? They did intervene, of course. They issued Red Tags and banned the compromised accounts... but did so only after the inventories of those victims had been completely wiped clean. Excellent work, Steam. Thank you for "saving" the account when there was nothing left in it to save. Ironically, the price of these tokens on the black market has collapsed. If previously a valid SSFN file could go for around $3, today on that very LZT Market (where the curator of Russian-language Steam support, Nikita, is registered) the price list looks like a mockery of Valve's security: "Buying and processing Steam Tokens (JWT). Fast check with proprietary software. Prices: $0.08 CS2 Prime JWT token This is the market price for a valid CS2 Prime session token on LZT Market. For eight cents, an attacker gets an active Steam session, access to the victim’s friend list, chat history, billing region, IP log, and the ability to send phishing to every contact. CS2 Prime — $0.08 (no temporary or permanent bans) OpenTM — $0.04 (open trading platform)" Your account, your history, and your data are valued at 8 cents. That is all you need to know about the effectiveness of session protection in Steam. The Illusion of "Technical Impossibility": The Fake Games Case Support claims that returning stolen items is "technically impossible" or would "destroy the economy." The game spoofing incident proves otherwise. The scheme was brazen: scammers uploaded dummy games to the Steam Store, creating items with names and icons copied one-to-one from expensive CS:GO and Dota 2 skins. During a trade, the victim saw a familiar Dragon Lore, completely unaware it belonged to a fake game. We remember this perfectly, as PhishDestroy was actively hunting and blocking these scammers at the time. And what did Valve do when the very foundation of trust in the Community Market was threatened? A miracle occurred. The corporation, which for years had refused to help phishing victims, suddenly returned the real items to all affected users. The scammers were hit with such a carpet bombing that they howled on shadow forums for days: Valve issued hardware bans (HWID) and blanket-banned shared IPs so harshly that entire scam syndicates went deep into the red. Moreover, Steam rolled out a massive security update in a matter of days. Suddenly, they found the resources to implement everything: trade holds, new verifications, developer deposits, massive red alerts stating "This game has never been played by you," and warnings about suspicious disparities in item values. It turns out they can. They know perfectly well how to track transaction chains, roll back trades, and build a complex warning architecture. But they only do it when they feel a direct threat to their own business model and the credibility of their marketplace. If you are stripped naked by a standard stealer, you will simply receive a boilerplate reply that "Steam policy does not provide for item restoration." 79 Employees: An Architecture of Matches and Acorns To fully grasp the "seriousness" of the platform's day-to-day security, consider the recent API bug that lived in production for two whole days. Anyone with a basic script could send a simple request and spam system notifications directly to absolutely any Steam ID, completely bypassing all privacy settings. Two days of a gaping hole in the API allowing anyone to ping millions of users. Indeed, 79 employees for a multi-billion-dollar global platform is clearly enough. Why invest in a functional QA and security department when you can just write a Terms of Service agreement that blames the user for everything? API TRADE SUBSTITUTION MECHANICS — how Steam’s own infrastructure enables the scam VICTIM initiates trade → BOT OPENS PARALLEL SESSION via Steam API → CANCEL & SUBSTITUTE same avatar, fake items → VICTIM CONFIRMS sees real item → INVENTORY DRAINED all in one session Every step uses official Steam API endpoints. The parallel session is opened through legitimate Steamworks calls. Valve could detect the pattern — two simultaneous sessions on the same account, one initiating and one cancelling identical trades. They did not patch this for years. Deep Dive Technical Investigation ## Inside the Steam API Offer-Swap Scam Read our complete technical report on active hijacked session pools, static Ihor network ranges, and Valve's refusal to patch anomalies. Explore the Technical Brief ## 25. Infrastructure as a Service: Scam-as-a-Service (SaaS) To give you a sense of the scale of commercialization spawned by Valve's inaction, look at a typical offer from a modern phishing team. These are no longer teenagers with broken scripts. This is a full-fledged SaaS business with fierce competition. While we were mercilessly blocking their domains and forcing them to lose money on infrastructure, they switched to providing free domains to their "workers" to maintain volume: "Our project combines 3 in 1: Phishing (logs go to you), MaFile (5% commission), Substitution (API Scam — 80% to you). Only we offer: Auto-sale of logs on LZT, MaFile removal with a single code, Browser for substitution, Free domains and a multitude of fake templates." Valve only fixes what becomes uncontrollable, or what affects geolocations they are afraid to disturb (USA, Japan, South Korea). Steam could see the spam, see the no-limit accounts, and sometimes even banned phishing domains (often when they were already dead). If the corporation saw a domain, it also saw the network of accounts distributing that domain. Given that the farms operated through cheap shared proxies (using the scheme of 1 server and 100 IPs per 1,000 accounts), blocking the entire botnet could have been done with a single SQL query. But Valve did not do it. ## 26. Geopolitical Hypocrisy: The Steam Economy Laundromat FlowStolen Steam skins used as anonymous currency: sanctions bypass → crypto conversion → clean profit.Valve takes 15% at each transfer step. No KYC. No AML. No enforcement. Valve's tolerance for the gray CIS economy spawned yet another monster — the market for illegal balance top-ups and region-switching. When Valve officially closed direct top-ups for Russia, it simply turned a blind eye to the flourishing of shadow intermediaries. Much more convenient that way, right? The "region-switching" service (to Turkey, Kazakhstan, or Argentina) was sold by the millions. On just one platform (like FunPay) [24], more than 500,000 transactions have been recorded from several large sellers. And there are hundreds more Telegram bots and forums. This top-up industry has become deeply intertwined with the laundering of money from phishing and crypto scams (the buying up of seed phrases). What is Valve's logic? Do they genuinely believe in the mass migration of millions of teenagers from a sanctioned country? Or do Russian funds, passed through a Kazakhstani proxy and a stolen inventory, simply "smell different"? Valve does not care about sanctions and compliance. The main thing is that a 30% commission from every transaction reliably drips into their bank accounts, while lawyers churn out boilerplate letters about the "impossibility of technical intervention." ## 27. Corporate Benefit and Violation of Their Own ToS Steam is an ecosystem that thrives on total violation of its own rules, and Valve knows this perfectly well. The Terms of Service (ToS) clearly state: extracting any commercial benefit on the platform is strictly prohibited. Now let's look at reality. Selling stolen accounts, skin trading, bot farms for farming collectible cards, Level Up services (profile leveling), selling keys, and of course, balance top-up services for sanctioned regions. All of this is direct commercial benefit. And this is surreal: a platform that formally prohibits commerce is home to industries with multi-million turnovers. Valve (or their reliably NDA-protected Russian-language outsource) has abstracted itself from its own rules, applying them exclusively as a tool to punish those who fall out of favor or to protect infrastructure. SELECTIVE ENFORCEMENT — the ToS Valve enforces vs. the violations it permits at scale AGGRESSIVELY ENFORCED User publishes anti-war comment User asks for item return after theft User appeals a permanent ban Developer mentions security vulnerability NEVER ENFORCED (ToS violations) Millions of automation bots (ToS §prohibited) 500K+ commercial account resale listings Gambling sites built on Steam API Sanctions bypass via region-switching services ## 28. The Support Syndicate: Why Valve Cancelled Item Returns DiagramThe documented support corruption chain: admin access → mass item duplication → black-market fencing via crypto bribes.This is not a hypothetical. PhishDestroy documented cases where support staff used system privileges to duplicate Dragon Lore and rare Dota 2 couriers, then fence them through Chinese exchanges for crypto. Valve abolished item returns to stop this — but punished users, not the corrupt staff. When Valve justifies its refusal to return stolen items to users (hiding behind fighting inflation or "duping"), they are blatantly lying. The reason Valve permanently freezes assets on banned bots, pocketing them into their bottomless account, is not protection of the economy. It is an attempt to recoup operational losses inflicted on them by their own employees. Historical fact: support agents (including cheap outsourced workers often mistaken for volunteers) were directly integrated into the shadow economy of Steam. Using their system privileges, they turned technical support into a corrupt cartel. Industrial Duplication of High-Tier Items: Support employees were mass-generating copies of the most expensive items in the game (Dragon Lore in CS:GO, rare Legacy couriers in Dota 2) under the pretext of "returning stolen inventory to a user." This "returned" inventory was then fenced on Chinese exchanges for real money. Selling Unbans: Support was selling the removal of Red Tags (KTs) and trade bans from the profiles of major scammers. For bribes (in crypto or skins), fraudsters were given the green light to cash out assets worth tens of thousands of dollars. Upon learning the scale of the corruption, Valve's management was furious. They permanently abolished the policy of returning stolen items, cutting support's manual access to item generation. But those punished were not the corrupt employees — it was the users. Children and gamers around the world are paying with their money for Valve's failure to control its own staff. The "Little Tyrant" Syndrome and the Fall of the Volunteer Police In addition to official support, Steam had a second branch of power — a volunteer trade police integrated with databases like SteamRep [12]. They held enormous informal influence over the platform's economy and the fates of traders. And they turned out to be no better than the outsourced staff. The volunteers devolved into a closed, corrupt caste of "faceless shadow authorities." They suffered from a classic "little tyrant" syndrome: they buried traders they disliked, banned users who discussed vulnerabilities, and issued "free passes" to friends. When logs surfaced proving that SteamRep [12] admins were taking bribes to remove "scammer" labels and were running cover for massive bot networks laundering stolen skins, Valve's trust collapsed completely. By 2022, Valve had expelled the last volunteer moderators, replacing them with rigidly scripted outsourced workers. THE UNREPORTED CRIME — EU AML LAW AND VALVE’S ILLEGAL SILENCE THE CEVA LEAK — WHY VALVE DISCLOSED IT The recent EU user data breach was disclosed not because Valve chose transparency, but because CEVA Logistics — a compliant public company — was legally required to report the incident. Valve was forced into an unusually public situation. Had Valve directly controlled the leak, they would never have notified users — just as they did not notify the 1,000+ victims whose data PhishDestroy documented. RUSSIAN OUTSOURCE: NO REGIONAL LIMITS Right now, the Russian-language outsource support contractors have unrestricted global access to every Steam account — with zero geographic filtering. They can view any account: IP address history, billing region, linked email, transaction logs. There is no technical or policy barrier preventing them from querying the account of any individual — private citizen or public figure — anywhere on the planet. THE QUESTION VALVE REFUSES TO ANSWER — EU ANTI-MONEY LAUNDERING LAW When Valve’s outsourced support staff (operating through Ireland) stole inventories worth €100,000–300,000+ from users — and Valve quietly replaced the contractor without telling anyone — did Valve file a Suspicious Activity Report with the relevant EU Financial Intelligence Unit? Did they report the theft to the Irish Gardaí Síochána or the relevant national authority? Under EU law (AMLD6), proceeds from theft above €10,000 that circulate without being reported constitute money laundering. Steam skins — which have a documented, liquid, exchange-rate-linked market value and are directly convertible to fiat through shadow exchanges — are functionally a currency. When support staff drain an inventory worth €150,000 in skins and those skins enter the underground trading ecosystem, those are criminal proceeds circulating in the European financial system. Unreported. Untaxed. Untraced. Valve’s implicit argument: “Skins are not money, so we are not obligated to report.” But the EU’s AMLD framework applies to assets of value, not just fiat currency. The European Banking Authority has repeatedly stated that virtual assets with exchange value fall under AML obligations. By the time stolen Steam skins converted to crypto bribes on Chinese exchanges fund the next cycle of support corruption, they have passed through multiple European financial jurisdictions. Valve made this choice deliberately. Informing regulators would expose the systemic nature of the problem. Staying silent allowed them to change a vendor and move on. ## 29. The Price of "Efficiency" THE FINAL TALLY — what a decade of deliberate blindness cost the world 70M+ Stolen accounts via LZT (lifetime) $450M+ Minimum victim liability 8+ Years of documented blindness 5 Legal vectors for accountability $0 Valve fines paid to date Valve boasts the highest profit per employee in the industry. But what is the cost of this profit? This efficiency is built on denying help. On threatening phishing victims. On closing tickets. On suppressing the truth that Steam is not so much a gaming platform as a global crypto laundromat and distribution hub for infostealers. While Valve's management considers itself geniuses of business optimization, fighting in court for the right to sell adult visual novels, their platform is daily chewing through the data, money, and safety of real users. The era of duping has long been dead, but Valve continues to use it as an excuse to legally appropriate the property of robbed users. There is no justice in Steam. There are only scripts, outsourced workers, and an endless thirst for profit. ## 30. Hypocrisy at Every Level: The Corporate Ethics of Valve and Taylor Wessing If it seems to you that mentioning Taylor Wessing in the context of their internal harassment lawsuits is a joke — it is not. A firm whose partners demonstrated a documented willingness to protect abusers internally is the firm Valve chose to stonewall the GDPR rights of children. The pattern is consistent. The choice was deliberate. If it seems to you that I am exaggerating by mentioning Taylor Wessing (Valve's lawyers) in the context of their internal harassment lawsuits — believe me, it is not a joke. The court case was lost, but the point is not the verdict — it is Taylor Wessing's strategy. They demonstrated not professionalism, but a dirty game of attrition and deliberate delay. Google how many years the case dragged on from the time of the incident at the elite ski resort. But when it comes to Valve itself, even more questions arise about their vaunted ethics. They have a corporate Welcome Book where they call themselves a "family." All warm and cozy. But when this "family" is rocked by scandal, Valve acts with maximum ruthlessness. Recall the harassment of a transgender employee in support, or the story of Jess Cliffe [13] (the co-creator of Counter-Strike, who had worked at Valve almost since its founding). The man was thrown out of the company without a court verdict, on the basis of accusations alone. Valve, which generates millions by covering up scams, suddenly became afraid for its reputation? The logic is absurd: a company allows millions of dollars to be stolen from its users but instantly distances itself from the person who built this business for decades, just to appear "clean." As for the lawyers at Taylor Wessing — let's be honest. You pride yourselves on your "centuries-long history," but on your Instagram, you are running a race in support of Pride. Make up your mind: do you honor the history of your Nazi founders who sent gay people to concentration camps, or are you a modern progressive company? This is corporate scamming. You want to appear as ancient aristocracy while having effectively merged into the ecstasy of contemporary hypocrisy. And yes, you have taken on the defense of Russian oligarchs in cases where your reputation was openly screaming: "You are not hired where people are innocent." ## 31. The Roadmap of Coming Leaks: What Valve Should Prepare For This is not the first and not the last piece from PhishDestroy about Valve. I will not play cat and mouse with their lawyers — their time, judging by their rates, costs $3,000-$5,000 for reading a couple of paragraphs. Don't waste the money; hire decent support staff instead of a Russian outsource that reads from scripts. Here is what comes next. My roadmap for upcoming investigations: Evidence Base on GDPR Impotence: I will publish the originals of the legal boilerplate letters and improperly redacted documents, proving that Valve systematically violates regulations and discloses the confidential data of underage users. I will show the entire chain in which I was already the fifth person to have gained access to someone else's personal data (including individuals with Russian passports). This is direct proof of their lies about storage conditions and mythical "encryption." NDA Violation and the Dirty Underbelly of Steamworks: We have data from at least two developers whose non-disclosure agreements (NDAs) we will be happy to violate (we never signed them). We will expose the open chaos in update moderation and cases involving locker content that Valve prohibits from being made public under threat of game removal. Crypto Failures and Money Laundering: How Valve's "Geniuses" Lose Their Millions: Since Valve loves to brag about the billion-dollar profits of their employees, we, as PhishDestroy, will venture into crypto territory. We will conduct a forensic financial analysis of the wallets belonging to elite support staff (early Bitcoin investors) and show how these "professionals," bringing Valve billions on the tears of robbed children, themselves invested in scams and had their addresses flagged with 100% AML risk scores. The Strange Love of Russia and Who Is "Nikita": We will examine the phenomenon of Valve's tolerance for the CIS region. How does a person with no formal employment become a support supervisor simply because they once created a fan community for Half-Life? We will expose the loopholes and sanctions bypass mechanisms for developers from a terrorist state, as well as direct balance top-ups from the DNR/LNR and Crimea that have been functioning since 2021 and continue to this day. PART II GDPR Stonewalling Originals of Taylor Wessing’s improperly redacted documents. Full chain of 5+ data recipients. Minors’ PII visible under the black overlay. PART II Crypto Wallet Forensics Support staff wallets — early Bitcoin investors with 100% AML-flagged addresses. How scam proceeds funded the people protecting the scam. PART II Who is “Nikita” How a person with no formal employment became a support supervisor. The loopholes. The NDA violations. The account movement from one contractor to the next. PART II Steamworks NDA Violations Data from two developers whose NDAs we never signed. Open chaos in update moderation. Content Valve prohibits publishing — published here. ## 32. Conclusion I have no desire to dedicate my life to writing texts about Steam. It is run by an audience of children, scammers, and Putin cultists on the platform (in the form of the Russian outsource). Volunteers are mired in corruption up to their ears. If Gabe Newell considers himself a genius of the gaming industry, then perhaps it is my destiny to be the bastard who writes the truth into history: Gabe is an excessively petty and greedy monopolist who legalized the theft of money from children. And the promised private jets and vacations from their employee handbook are just colorful pictures designed to keep workers in corporate bondage. All of this is written for history. For the Web Archive. And for those regulators who will eventually come to dismantle this empire of impunity. ## 33. Anatomy of the ToS: Corporate Schizophrenia and Legal Cynicism Let's dissect Steam's Terms of Service (ToS). We will cover at least 25% of this document to show that this is not a legal contract — it is a lie constructed to allow the platform to steal from children while avoiding accountability. Here is a quote from their rules: "You may not use any scripts, bots, macros or other automated systems ('Automation') to interact with Content and Services on Steam..." We will analyze this clause in detail in the next part. Spoiler: Steam itself created an API that is used exclusively for automating theft, bypassing limits, and managing bot farms. The platform wrote a rule that it simultaneously allows to be violated on an industrial scale. And here is another gem of corporate cynicism: "You acknowledge that Valve is not required to provide you with notice prior to terminating your Subscription and/or Account." This is a lie. Under normal legislation, that is not how it works. But the platform shields itself from everything. Valve's position sounds like this: "We steal from children, we violate sanctions, we allow infostealers to infect your PCs, but if anything — you are at fault, and we will take your account without explanation." They love to say that "the community decides everything." But for some reason, when it comes to legal accountability, the community suddenly becomes a powerless piece of meat. KEY ToS CLAUSE — the automation prohibition that enables the theft “You may not use any scripts, bots, macros or other automated systems (‘Automation’) to interact with Content and Services on Steam…” — Steam Subscriber Agreement The same platform that bans automation simultaneously exposes an official public API that processes millions of automated requests daily from LZT Market account checkers, inventory validators, session hijackers, and card-farming bots. This ToS clause is not a security measure. It is a legal escape hatch — when a regulator points to the mass automation, Valve can show the rule. When a robbed teenager asks for help, Valve shows the same rule to deny the claim. One document. Two purposes. Zero enforcement against profitable violators. ## 34. Sanctions, Terrorism, and Double Standards A funny question for this corporate hypocrite. The rules state: "If you are a consumer residing in Russia, you can also seek legal protection in local Russian state courts." Does the court of annexed Crimea count as a Russian court? Or shall we wait for Roskomnadzor — with which Steam integrates so cozily — to answer? And here is a clause that provokes a roar of laughter: "You agree to comply with all applicable import/export laws and regulations. You agree not to export Content... to any countries that support terrorists... You represent that you are not in such a prohibited country." So when Valve accepts money directly from accounts registered in zones subject to international sanctions (and we have gigabytes of screenshots and direct proof of transactions from Crimea, the DNR, and LNR dating back to 2021) — it is not Valve violating sanctions. It is the user's fault! The platform quietly edited its ToS over the last six months, shifting all responsibility onto users. Valve, were you compelled to remove mentions of Russia's allies (Cuba, Iran, Syria) and prohibited from speaking ill of them, or did you calculate the scale and the sum that came directly from those places? If a terrorist state is coercing you into any actions — tell someone, do not be afraid. There is no need to violate current US law because of threats that they will pirate your content; it is not worth that risk. They are terrorists, and you are a US company. If you are being persecuted or blackmailed, contact the FBI Seattle Field Office at +1 (206) 622-0460 [16] or IC3 [17]. I am also confident that specialists from CISA [18] could help you: given the scale and reach of your sphere of influence, it is significant even by US standards. Since you are removing direct sanctions rules and changing the text — this is a very alarming signal. I am not joking: if you do not trust the agencies named above, then here you will certainly receive help at the highest level — at DOJ NSD [19]. We, for our part, will conduct additional analysis and free consultations with certain specialists, and may also be compelled to report this where appropriate (or nowhere). But this is no joke at all — it is serious. You removed explicitly enumerated countries from the rules and shifted responsibility onto users. At the same time, you run analytics: there is a tracking pixel on the registration page, and you see the real number of clicks through to the agreement. Nobody reads it, because you have calculatingly disguised it as a question confirming that the user is over 13 years old (the link to the agreement is embedded there as well). Modern society — children and teenagers — has ADHD, and this is a scientifically proven fact: check the data. They do not finish reading text. I, for example, saw the clause about being over 13 and that was it — I looked no further. This is direct manipulation on your part, as is the rewriting of the agreement regarding countries that have consistently appeared on sanctions lists. Your revision directly indicates that your company's attitude toward those countries (or money from them) has changed. This is a very strange change. Most likely, there is already a problem, or you are complying with Russian courts, and this is one of their non-public demands — such as the banning of certain users, etc., which could undermine belief in the rightness of their terrorist acts on the territory of another country. Or are you simply prostrating yourselves before the Russian government, fulfilling their direct requests to ban undesirable users? I will show you prior versions of your ToS. You may change them as you wish, but these pieces of paper are worthless when it comes to the direct violation of US laws and the sponsoring of terrorist economies. ## 35. Blackmail and the Scorched-Earth Strategy Fair warning in advance: any attempts by Valve or their attack dogs from Taylor Wessing [9] to make contact will be treated as pressure and obstruction of the investigation. Do not try to send us an NDA. PhishDestroy is not registered on your garbage heap. We did not check the box in your clever agreement (which you treat exclusively as confirmation that a child is over 13 years old, so that you can legally rob them). If your lawyers try to accuse us of "extorting billions of rubles" or "defaming the holy reputation in the interests of a North Korean competitor, Steam 2.0" — good luck. All of our investigations, evidence, and proof are duplicated to independent nodes (including servers at an American university) and the Web Archive. This is not a conflict. This is a statement of facts. DEAD MAN’S SWITCH — IPFS activation conditions If Steam, Taylor Wessing, or any affiliated entity attempts aggressive action against this project, the response is not legal — it is technical: full raw data dump to IPFS. All evidence, all communications, all unredacted documents. The domain dies. The data lives forever at steamdestroy.eth. No seizure. No injunction. No takedown. The content-addressed file system does not have a registrar. ## 36. The Scam Factory: Carding, Fake Documentation, and Data Theft You think scamming on Steam is only about stolen passwords? You have no idea of the real scale. Fake Documentation (Social Engineering): When an account is stolen, support demands the first CD key from 10 years ago. The child doesn't have it. But the scammer from Russian outsource does. Fraudsters commission the fabrication of fake receipts and keys on shadow forums. We have collected over 200+ proven instances of successful fakes that Valve's support staff happily "swallowed," handing the account over to criminals. Data Theft: More than half a million accounts (including EU citizens) have passed through the shadow market LZT. Steam concealed the fact that their PCs had been infected with stealers. The platform de facto leaked to hackers personal data, correspondence, IP addresses, and home network information. Industrial Carding: If Valve's lawyers understood how carding works on their platform, their hair would turn white. Issuing a Red Tag for carding while leaving items purchased with stolen credit cards on the account is a remarkable money laundering practice. Do you know who was actually competing with the Prince of Saudi Arabia for the highest Compendium level in Dota 2? We will tell you about that too. 200+ Proven fake CD-key submissions accepted 500K+ EU citizen accounts through shadow market 15% Valve commission on every resold stolen skin ## 36a. The Gambling Machine: How Valve Built the World’s Largest Unregulated Casino for Children Skin gambling is not a side effect of Steam. It is a predictable and profitable consequence of Valve’s deliberate architecture: open trading API, no KYC, virtual items with stable secondary market value, and complete regulatory blindness. The result: a $1B+ annual industry where children’s CS2 skins function as casino chips — without age verification, without parental consent, and without Valve ever filing a single SAR. $1B+ Annual skin gambling volume at peak 15% Valve commission on every skin deposited 0 Age verifications required by Steam THE MECHANISM — how children’s skins become casino chips 1 Child earns CS2 skin (in-game drop) 2 Skin has real market value (Steam API) 3 Gambling site accepts skin as deposit 4 Child loses. Site keeps skin. 5 Valve earned 15% at every skin transfer No step in this chain required Valve to act. The Steam API was the enabling infrastructure. The skin economy was the currency layer. Valve designed both, monetized both, and filed no SAR, made no age-gate, sent no warning to parents. ## The 2023 Bot Ban: Not a Punishment. A Profit Mechanism. In 2023, Valve banned tens of thousands of bot accounts operated by gambling sites — CSGOFast, CSGORoll, Stake.com (for skins), and others. The gaming press celebrated this as Valve “cracking down” on gambling. This interpretation is factually wrong. THE 2023 BOT BAN — who actually paid WHAT CASINOS LOST Bot accounts — new ones spun up within days Temporary disruption to automated deposit flows Net financial loss: near zero. They migrated to new methods. WHO ACTUALLY PAID Children whose skins were inside the bots at the time of the ban Inventories confiscated by Valve — not returned to original owners Valve kept every skin in every banned bot: Breakage Income The child who deposited their AWP | Dragon Lore as a gambling stake: got nothing back The math: Tens of thousands of bot accounts. Each holding hundreds to thousands of skins. Combined inventory value: tens of millions of dollars. Valve banned the bots and kept every skin. The gambling sites paid nothing. The casino operators paid nothing. The children who made the deposits paid everything. And Valve collected their standard 15% commission on every skin’s journey through this entire chain before confiscating the final balance. REGULATORY POSITION: FTC / UK Gambling Commission / EU Commission Steam operated for years as the settlement infrastructure for an unregulated gambling ecosystem targeting minors — earning commission at every step and confiscating balances upon “enforcement.” Under US law (UIGEA + FTC Section 5), facilitating gambling transactions without age verification and without filing SARs constitutes potential criminal exposure. The UK Gambling Commission has jurisdiction over any gambling product accessible to UK residents. The EU’s Digital Services Act requires platforms to prevent illegal content — including illegal gambling advertising and underage gambling access — from reaching minors. ## 37. Epilogue: A Training Ground for Cybercrime VALVE’S LEGACY: PRIMARY INCUBATOR OF GLOBAL CYBERCRIME #1 Gaming target for infostealers $100M+ Corporate damage from one $2 log 8+ yrs Documented deliberate inaction Steam accounts are the top gaming query for malware operators globally. Without the financial return Steam’s shadow market provides, large-scale infostealer distribution campaigns would be economically unviable. Valve did not build a platform that got exploited by criminals. Valve built the economic engine that made the infostealer industry profitable. Since, according to Valve's perverse logic, virtual items "have no real value," the theft of $10,000 worth of skins is not legally theft. This is a perfect gray zone. But Steam is not merely ignoring theft. Steam has raised an entire generation of cybercriminals. Today's creators of infostealers and crypto scammers started out stealing inventories in CS:GO. Gabe Newell's platform became the primary incubator for global cybercrime, teaching underage hackers the main rule: you can steal on the internet with impunity, as long as you pay the corporation's commission. Everyone will answer for their actions. Even if they hide behind a Terms of Service they wrote themselves. Expect part two. ## 38. Sanctions, Censorship, and Steam's Stockholm Syndrome Evidence: Sanctions Bypass Openly Hosted on Steam Servers These are not dark web links. These are discussions and official Guides hosted on Valve's own servers, indexed by Google and Bing, publicly accessible to non-logged-in users. Valve moderates this platform. Every post is reviewed. None of these were removed. OFAC Violations — Crimea, DNR, LNR Top-Ups How to top up Steam in Crimea, LNR, DNR regions Top-up from Crimea Top-up in LNR and new territories Topping up Steam via Tinkoff (sanctioned bank) Official Steam Guides — Sanctions Evasion Tutorials Guide: How to top up Steam from Russia Guide: Top up Steam with minimum commission Guide: Steam Wallet Top-Up Methods Schrödinger's VPN: Valve's Selective Enforcement Steam ToS explicitly bans VPN use. At the same time, Steam's own servers host thousands of guides on how to change region via VPN. Under FTC Section 5 (UDAP) this is a deceptive practice. Under Estoppel doctrine, Valve has waived the right to enforce this clause after systematically ignoring it for years — meaning they cannot selectively apply it to deny help to theft victims while allowing bot networks to run freely. Under OFAC Willful Blindness doctrine, hosting and indexing this content is not passive — it is facilitation. InfrastructureDocumented sanctioned payments routed MOCKBA → TURKEY → STEAM SERVER.Valve hosts the tutorials for this on their own servers. Nothing was removed. Steam's hypocrisy reaches its apex when the subject turns to geopolitics. You may laugh at the fact that a corporate monster generating billions has simply gotten confused in its own algorithms. But let's look at the facts. In 2022, as the sanctions noose began to tighten, developers from Russia rushed en masse to bypass the blocks. And where did they find the most detailed guides on evading international OFAC sanctions? Right inside Steam itself. In the official Community, there are step-by-step instructions on how to use a VPN (which is formally prohibited by the ToS) to change regions and withdraw money to sanctioned banks (such as Tinkoff Bank) [25]. Here is a quote from an official (or, at least, Valve-moderated) guide that perfectly describes their position: "We kindly ask you to maintain professionalism and refrain from commenting on political matters... Such statements will be removed, and the most active violators will lose the ability to leave comments..." Translate from corporate speak into plain language: Valve prohibits calling the war a war. Valve prohibits calling the aggressor country a terrorist. Aggressive moderation (hello, Russian-language outsource) scrubs any criticism, protecting an audience that is killing people in a neighboring country from "political disputes." This is not mere negligence. This is complicity in censorship, driven by fear of losing revenue from the CIS market. I formally invite Valve's management and their vaunted lawyers to come to Mariupol or Melitopol, to see from what exactly "political disputes" they are so carefully shielding their Russian-language community. EXHIBIT A — Steam's own servers host these discussions (click to expand — not the dark web) Steam ToS, verbatim: “Вы соглашаетесь не использовать IP-прокси или другие методы, позволяющие скрыть ваше место жительства, с целью обойти географические ограничения…” — Valve Corporation prohibits VPN region-switching in its Terms of Service. The following content is published, indexed, and actively moderated on Valve’s own community servers. None of it has been removed. Official Steam Guides — on Valve’s servers СМЕНА РЕГИОНА | CHANGING REGION (official guide) 2022 Обход блокировки Steam — Смена Региона Смена региона EU/NA → RU Changing region from RU to EU СМЕНА РЕГИОНА — КАЗАХСТАН / ТУРЦИЯ Смена региона на РУ Смена региона магазина и валюты кошелька Steam КАК СМЕНИТЬ РЕГИОН НА … Смена Региона в Deadlock в любое время Смена сервера дата-центра (пинг / регион) Community discussions — selected from hundreds Смена региона с ВПН Могут ли забанить за смену региона? Забанят ли за смену региона? Смена региона на Казахстан Сменили регион с России на Казахстан Смена региона обратно с Турции на Россию Как сменить регион на Россию? Как сменить регион с Франции на Россию? Региональные ограничения и смена региона Смена региона на Турцию Смена региона в стим Смена региона на Россию Возврат средств после смены региона Нужно ли ждать 3 месяца после отката региона? Не дают изменить регион OFAC Tier 1 — Crimea / DNR / LNR direct access threads Пополнение из Донецка Как пополнить Steam в регионах Крым, ЛНР, ДНР Как пополнить стим в ДНР? Не могу покупать и пополнять кошелёк стим в ДНР Кто из ДНР? Как зайти в The Finals без VPN (работает в ДНР/ЛНР/Крым) Варфрейм в Крыму В Крыму доступно? Steam Workshop: “Специальная Военная Операция (СВО)” Steam Workshop: “Ukraine war” Steam Workshop: “Ukraine war mod” Steam Workshop: “Donbass Mobilized Infantry” Steam Workshop: “ЧВК WAGNER” Steam Screenshot: “ДНР, Мариуполь” User profile: “Правитель ДНР” (Ruler of DNR) All of the above is published on steamcommunity.com — Valve’s own servers — indexed by Google, accessible without a Steam account. Crimea, DNR, and LNR are under active US Treasury OFAC sanctions. Steam Workshop hosts mods named “Специальная Военная Операция” (the Russian state designation for the invasion of Ukraine) and “ЧВК WAGNER” (the Wagner PMC, a US-designated terrorist organization). Under OFAC Willful Blindness doctrine, this is not passive oversight. This is documented, sustained facilitation. Steam Workshop — war glorification content, publicly indexed Workshop: “СВО SVO” Workshop: “Специальная Военная Операция (СВО)” Workshop: “Специальная военная операция на Украине” Workshop: “Operation Vostok | Russian-Ukrainian war | СВО” Workshop: “War in Ukraine СВО” Workshop: “WAR: UKRAINE VS RUSSIA” Workshop: “СВО | Коллекция” Garry’s Mod Workshop: “СВО ТОЛЬКО ЛУЧШЕ” Workshop: “Arma 3 СВО” Workshop: “арма 3 пресет модов СВО zpv zov” Workshop: “Вооруженные Силы Российской Федерации” Workshop: “СВО АРТЕМ ЛЕША” Steam Screenshot: “СВО” (publicly hosted) User profile: “СВО | ХОУМЛЕНДЕР” Discord server recruitment for СВО (via Steam) Group: “Русский Марш” (Russian nationalist march) All of the above content is published on steamcommunity.com, publicly indexed by Google and Bing, accessible without authentication. “СВО” (Special Military Operation) is the Russian state designation for the ongoing invasion of Ukraine. Valve simultaneously removes discussion threads calling this conflict a “war” — yet hosts Workshop content that glorifies it under its official Russian government label. Under the same moderation policy, the existence of these Workshop items is an affirmative, editorial decision. Critical distinction for regulators This content does not require a Steam account to access. It is not locked behind a login wall. Every link listed above is reachable by any person on the internet without any registration or authentication — including regulators, journalists, and law enforcement. Furthermore, this content is actively ranked and promoted in search engine results. Searches for “пополнить Steam ДНР”, “смена региона стим”, or “Steam Крым” return these Valve-hosted threads in the top results on Google and Yandex. Steam’s platform is configured with standard SEO headers, sitemaps, and crawl permissions — Valve has deliberately chosen to make this content discoverable to search engines. This is not content that slipped through moderation. These threads have existed for years. Steam actively moderates its Russian-language forums — anti-war speech is removed within hours. Sanctions bypass instructions remain indexed and promoted in search results indefinitely. The editorial choice is documented, directional, and revenue-motivated. ## 39. Sanctions Bypass as a Platform Service Steam states that users are obligated to comply with US export laws. But at the same time, the platform serves as the primary hub for publishing manuals on how to bypass them. The guides have been up for years. Switching region to Kazakhstan or Turkey to bypass blocks has become not just a widespread phenomenon, but an industry standard that Valve silently approves. Why? Because Steam's policy goes like this: "The user ticked the box saying they are not a terrorist and are not under sanctions, so there are no claims against us." But we will go further. If anyone has raw analytical user databases from Steam, we are ready to put them to work. We will find lists of accounts that have bypassed blocks to purchase games from publishers who officially withdrew from Russia (such as the creators of STALKER 2 [30] or GTA [30]). We will pass this data directly to those publishers, along with the question: "Are you aware that Steam is sabotaging your exit from the market and openly providing users with loopholes to purchase your games in rubles through a chain of intermediaries?" We already have contacts with insiders bound by NDA. We know of a case where Valve unilaterally terminated cooperation with a developer and simply appropriated their money, covering it with a non-disclosure agreement. But we did not sign any NDA. We will tell everything. ## 40. Where Are the US Regulators Looking? The main question: does Valve understand what OFAC [20] (the US Office of Foreign Assets Control) is? When a platform allows mass sanctions evasion via VPN (from minor purchases to fund withdrawals by developers); when it allows money laundering through shadow skin markets while turning a blind eye; when the platform's moderation integrates Roskomnadzor [23] restrictions and removes "undesirable" posts — this is no longer the jurisdiction of a terms of service agreement. This is the territory of direct violation of US sovereignty and laws. Expect the continuation. PhishDestroy will not stop until this architecture of lies collapses. All proof and links are saved. And no Taylor Wessing [9] will intimidate us. For Valve, geopolitical differences are not just a matter of regional pricing (where Valve decides who is wealthier and who is "Russia"). It is also about laws, rules, and control. Here is a perfect example — the VPN geolocation is visible at the top. So the New York prosecutor simply doesn't use a VPN. But I think she could have never imagined that Valve is such a hypocritical rat, operating completely different rules and controls depending on where you are accessing the platform from. Double StandardsSchrödinger's VPN: Valve serves completely different content and rules depending on your geolocating proxy.The New York prosecutor simply didn't use a VPN — but she could have never imagined how deep Valve's hypocrisy runs. Given all these factors, our recommendation is simple: do not yield to Steam's legal framing. If a user is an actual terrorist, they are under no obligation to testify against themselves. It is Steam's absolute legal duty to verify the origin of these funds, rather than granting the user the absurd privilege to self-certify whether they are a terrorist or not. This logic applies directly to Valve's territorial operations. If Valve has suddenly forgotten how the internet works — and its direct bans on VPNs — let's follow their logic: a terrorist from Crimea, Cuba, or Syria goes online to launder money. This user does not know English and has zero intention of reading the convoluted legal nonsense in the user agreement. But they are definitely over 13 years old (in fact, they might have already killed 13 people). Does the platform seriously think it can shift the legal liability onto the terrorist to decide their own status? By shifting this responsibility, Valve is making a direct legal statement: they automatically recognize everyone as a "non-terrorist" on their end. Meanwhile, the actual terrorist, who completely ignores the boilerplate text disguised as a simple age check, simply launders their money using a sanctions-bypass guide hosted directly on Steam's own community platform. Outstanding compliance, isn't it? Are you out of your minds? You fed the personal data of minors to a person with a grievance, essentially saying, "Here is the cause of your problems, fetch." If that individual ever acts on that data, the blood and legal responsibility rest entirely on the hands of Valve and Taylor Wessing. The IPFS Dead Man's Switch We have vastly more information than what is published here. If Steam, Taylor Wessing, or any affiliated entity attempts to take aggressive action against our project, we will not waste time in court. We will execute a full, raw data dump on the InterPlanetary File System (IPFS). Yes, releasing unredacted data will have consequences. Yes, it will mean the absolute death of the phishdestroy.io domain and its massive traffic. Let us save your lawyers some time: We do not care. The domain was created as a joke to mock the Steam scammers who claimed we "didn't even have a website." We do not chase reputation, we are not trying to be corporate heroes, and we are not afraid to lose a URL. If the domain dies, you will find the answers at: steamdestroy.eth Who We Are PhishDestroy is a non-commercial anti-fraud operation. There are four of us — certified cybersecurity professionals operating across multiple countries. One of our original five members is deceased; that is why you will never find all of us. ## 40a. Open Disclosure Protocol: Formal Notice to Valve Corporation OPEN DISCLOSURE PROTOCOL — PhishDestroy · August 2026 PhishDestroy does not enter closed settlements, sign NDAs, or engage in corporate extortion. Our objective is transparency and technical truth. This investigation — including raw (de-identified) telemetry, vulnerability reproduction scripts, and blockchain transaction analytics — is published as an open repository. We simultaneously issue this formal open letter to Valve Corporation’s management and legal department requesting clarification on documented technical and legal paradoxes. VERIFICATION PROTOCOL — all communications are cryptographically witnessed Pre-publicationEvery outgoing request is uploaded to our open repository before being sent. PGP-signed .emlAll outgoing requests and incoming responses are published in .eml format and cryptographically verified with PGP signatures. Willful Blindness DoctrineLetters are sent to all corporate, legal, and public email addresses simultaneously — establishing confirmed receipt. THREE QUESTIONS REQUIRING A TECHNICALLY AND LEGALLY SUBSTANTIATED PUBLIC RESPONSE: QUESTION 1: Shadow Asset Confiscation & Anti-Cheat Absurdity Valve systematically conceals the real reasons for Community bans and inventory freezes behind boilerplate claiming “we cannot disclose anti-cheat (VAC) algorithms.” This is technical and legal nonsense: VAC has no relation to trade lockdowns. Our estimate puts assets illegally held on banned bot accounts (Breakage Income) at $300–500M. What is the actual volume of currently frozen inventory? Why are owners of confiscated property denied the right to know the real, itemized reason for the block without irrelevant references to anti-cheat? PhishDestroy counter-evidence PhishDestroy maintains independent tracking analytics on publicly known bot accounts and documented threat actors operating on LZT Market. Our data shows approximately 90% of known Steam scammers remain unbanned — not because detection is technically difficult, but because banning them would eliminate a revenue stream. The “we cannot reveal anti-cheat algorithms” response is not a limitation. It is a legal shield. We are capable of revealing the real methods: the vast majority of CIS scammers on Steam are documented, publicly operating, with years of transaction history. Valve does not lack the data. Valve lacks the motivation. QUESTION 2: The Automation Paradox & Shadow Market Facilitation Steam ToS categorically prohibits all automation. Reality proves the opposite: Valve created and maintains an API used exclusively for theft. Shadow markets generate millions of API requests daily validating stolen JWT/SSFN sessions. Our telemetry shows 300,000-bot farms, frictionless auto-registration via VoIP numbers, proxy/Tor parsing availability, and millions of identical phishing messages daily. Time from token theft to dark-market listing: milliseconds. Why does the official Steam API function as a criminal pipeline while Valve ignores 100% provable industrial automation? QUESTION 3: Legalizing Sanctions Bypass (Schrödinger’s VPN) Steam ToS explicitly prohibits VPN use for bypassing regional restrictions. However, on official Steam Community domains — moderated by Valve employees — thousands of guides on region-switching and wallet top-ups (including OFAC-sanctioned territories) have been posted for years and are indexed by Google and Bing. Is providing Steam servers to host sanctions-bypass guides an official company position, and why is the VPN prohibition enforced exclusively when it benefits Valve? ESCALATION PROTOCOL — Regulatory Forwarding on Non-Response We acknowledge Valve Corporation’s right to silence. However, in the legal environment, the absence of responses to documented technical evidence is treated as Tacit Admission. Upon expiration of the responsible disclosure window, materials from our repository will be addressed to the following regulators: OFAC + DOJ NSDCrimea/DNR/LNR transactions, Willful Blindness, hosted sanctions-bypass guides FinCEN + IRSUnlicensed MSB, shadow confiscation as unreported income, KYC/AML failure FTC (COPPA)Under-13 data collection, JWT leaks of minors’ PII to dark markets, $50K/violation exposure CISA + IC3/FBISteam P2P as free infostealer/botnet engine attacking US corporate networks EU DPAsTaylor Wessing GDPR DSAR — improperly redacted documents disclosing minors’ PII PublishersCD Projekt Red, EA, Ubisoft — Tortious Interference via VPN/region-switching facilitation The repository is open. The evidence is verifiable. Every move is recorded. If Valve chooses not to speak with independent researchers, this dialogue will be continued by regulators, media, and institutional partners who will ask the same questions in a courtroom. We are waiting for your response. REPORT TO YOUR LOCAL AUTHORITIES PhishDestroy is actively seeking countries and regulators for whom it is not a matter of indifference that their citizens — and their children — are having their property stolen, are being systematically cultivated into gambling addiction, and are being exposed to what may be, at minimum through Valve’s tacit approval, a documented vector for device compromise at scale. Choose your country to see verified official reporting routes. Nothing is sent automatically — review every fact and submit through the official route yourself. Choose your country Reporting Authority Steam-specific complaint points Nothing is sent automatically. PhishDestroy provides verified reporting contacts only. Submit the complaint yourself through the official route. ## 41. The Ultimatum & Deterrence Framework One question requires a public answer on the record: According to Valve's Terms of Service, does a court in the annexed territory of Crimea qualify as "any local Russian state court"? Without a direct, public answer to this question, do not contact us. If a "peaceful settlement" is what you want, enforce your own rules: Ban every account that has ever used a VPN to access Steam (you have the database). Block every account that has used automation on the platform, including CSGOFast. Admit that Valve or its proxies conducted a cyberattack against Source 1. The minimum standard of fairness: return every asset stolen through trade substitution (API scam). Start with every account ever listed on Lolzteam Market. We understand your architecture — we saw your internal device identification logic in those unredacted GDPR documents. "Technically impossible" is not an answer. If your staff cannot do it, replace them. The outcome does not change regardless of what you try. We have no money to seize, no names to expose, and no corporate reputation to ruin. We are armed only with the truth. A Global Warning: The Infostealer Epidemic and Corporate Collateral I am addressing every country on Planet Earth — except the terrorist states, since Steam is already getting along with them just fine. If you care at all that an unaccountable corporation has decided it has the right to steal your children's digital property, listen closely. If you care that they deliberately fail to notify users about infected devices — thereby compromising critical corporate networks worldwide — then pay attention. In Part 2 of our investigation, we will present a perfect example of what Steam's negligence has actually spawned. We will provide hard evidence proving that Steam is the primary economic fuel for the global infostealer industry. Steam accounts are the top gaming query for malware operators. Without the financial return provided by Steam's thriving shadow market, these massive, indiscriminate infostealer distribution campaigns would simply be economically unviable. There is already a public case on the record where a $2 stolen log resulted in a corporate lockdown, a $17 million ransom payout, and total damages exceeding $100 million. Thank you, Valve, for your unparalleled commitment to global "security." We will not hide this intelligence. Information flows to us naturally, and we will publish it all. And let this be our official declaration: if, God forbid, the evidence reveals that Valve or its proxies have been conducting targeted cyberattacks against specific users to silence them, the international community will not play along. The rest of the world will not entertain your cute little legal games about exclusive jurisdiction in the courts of Washington State. THE THREE DEMANDS — minimum standard of fairness before any negotiation 1 Answer the Crimea question publicly: Does a court in annexed Crimea qualify as “any local Russian state court” under your ToS? Without a direct answer, no contact. 2 Ban every account that used VPN to access Steam — you have the database, you have the logs. You enforce this rule against theft victims. Apply it universally or admit it is selective. 3 Return every asset stolen through trade substitution (API scam) — start with every account ever listed on Lolzteam Market. You have the device identification logic. “Technically impossible” is not an answer. We have no money to seize, no names to expose beyond what we have already published, and no corporate reputation to ruin. We are armed only with the truth and the patience to repeat it until it lands in a courtroom. ## 42. Final Verdict FINAL VERDICT — THREE DOCUMENTED FACTS FOR THE RECORD I.  Steam killed the children it leaked. The data existed. The tools existed. The choice not to act was always a choice — not a limitation. II.  Steam steals from children under the guise of fighting “dupes” that were generated entirely by its own support staff. The Breakage Income is not a bug. It is a revenue line. III.  Steam lies about withholding ban reasons under the guise of “anti-cheat.” A Community Ban has nothing to do with VAC. The withholding is legally convenient, not technically necessary. These statements are backed by eight years of documented evidence, official GDPR disclosures, LZT Market telemetry, and on-the-record legal communications. They are not allegations. They are conclusions of fact. The bot is no longer under our management anyway. I feel no shame, and I do not believe I am doing a bad thing. I am certain we have no other choice. Source 1 stopped himself in time, but as far as we are concerned, you killed the children whose data you leaked to him. Therefore, we will not negotiate. Steam is the terrorist here. Re-evaluate what you did, and what Source 1 was doing after your lawyers handed him that data. Where did your "Nikita" come from? And what about the four off-staff support agents sitting in Russia? I am sure you think this is an isolated incident, but we know about many of your cases and your "decisions." We are not you. We do not cover up potential crimes. We will gradually release everything with proof and cooperate with any regulator — except the ones you seem to favor. Russian authorities write to us frequently; we usually tell them to fuck off, but maybe we will start answering. We don't play stupid games with unintelligible corporate responses designed to confuse, much like your user agreement. I hope our position is absolutely clear: Steam killed the children it leaked. Steam steals from children under the guise of fighting "dupes" that were generated entirely by its own support staff. Steam lies about withholding ban reasons under the guise of "anti-cheat" strictly because it is legally convenient. (What the fuck does anti-cheat have to do with a Community Ban?) Are you really that confident your courts or Europe will just turn a blind eye? We will see. --- ## References & Sources [1] Netcraft Anti-Phishing Service and Reporter Prizes Program https://www.netcraft.com/anti-phishing/ Netcraft is a leading internet security company that tracks and reports phishing sites. The Reporter Prizes program rewards verified submissions. Valve's refusal to cooperate with Netcraft is documented through public anti-phishing statistics. [2] Cloudflare Abuse Reporting Portal https://www.cloudflare.com/abuse/ Used for escalating phishing campaigns employing cloaking techniques against Cloudflare-protected infrastructure. [3] Valve Internal Data Disclosure (2024) — Employee Count and Revenue Per Employee Sources: Kotaku, Ars Technica, IGN, The Verge, PCGamer (May 2024) https://kotaku.com/ [search: "Valve employees 2024"] https://arstechnica.com/ [search: "Valve internal data leak"] Internal documents revealed Valve's total headcount (~336) and the number of employees directly working on the Steam platform (~79), along with boasts about profit-per-employee exceeding Google, Amazon, and Microsoft. [4] LZT Market (Lolzteam) — Shadow Marketplace Statistics https://lolz.live / https://lzt.market Russian-language clearnet marketplace for stolen accounts and cybercrime services. Item IDs (e.g., item_id 252853378) confirm cumulative listing history exceeding 250 million lots. Account counts cited reflect live marketplace data at time of documentation. Covered by: Group-IB, KELA Cyber Intelligence, and other threat intelligence providers. [5] BlockBlasters Malware Incident on Steam (September 2024) Security community reports and Steam community threads (September-October 2024): https://www.reddit.com/r/GlobalOffensive/ [search: "BlockBlasters stealer"] https://steamcommunity.com/ A game titled BlockBlasters was listed on Steam and distributed an information stealer. Reports submitted to Steam support beginning September 2, 2024 included open Telegram API endpoints embedded in game code. The game remained available for approximately one month before malicious builds were removed. [6] Raivo Plavnieks — Content Creator and Whistleblower Twitch streamer whose coverage of the BlockBlasters incident brought the malware to wider public attention. Documented through VODs, community posts, and security researcher reports (September 2024). [7] ChainAbuse — Cryptocurrency Abuse Reporting Platform https://www.chainabuse.com Community-maintained database of cryptocurrency addresses associated with scams, ransomware, and fraud. Victims of the BlockBlasters stealer submitted reports to ChainAbuse documenting wallet addresses used to receive stolen cryptocurrency. [8] IRS Form W-8BEN — Certificate of Foreign Status of Beneficial Owner https://www.irs.gov/forms-pubs/about-form-w-8ben Required from non-US developers earning income through US entities (including Steam). This KYC document ties the developer's legal identity directly to their Steamworks publisher account, refuting Valve's "hacked anonymous developer" narrative. [9] Taylor Wessing — International Law Firm https://www.taylorwessing.com Offices in Hamburg, Munich, London, and other cities. Represents Valve Software in European legal matters including GDPR data subject access requests (DSARs). The firm's historical founding and its predecessor entities' documented connections to the Third Reich era have been the subject of academic and journalistic inquiry into German law firm histories. [10] EU General Data Protection Regulation (GDPR) — Regulation 2016/679 https://eur-lex.europa.eu/eli/reg/2016/679/oj https://gdpr.eu/ Under Article 15 GDPR, data subjects may request full disclosure of personal data held. Valve's compliance with DSARs has been processed through Taylor Wessing, and documented cases show improperly redacted responses disclosing data of third parties — including minors. [11] RedLine Infostealer — Operation Magnus (October 28, 2024) Europol Press Release: https://www.europol.europa.eu/media-press/newsroom/news/operation-magnus-redline-and-meta-infostealers-dismantled FBI and Dutch National Police (Politie) participated in the takedown of RedLine and META stealer infrastructure. RedLine was the dominant tool for stealing Steam session files (SSFN) and browser cookies during 2021-2024, sold as Malware-as-a-Service (MaaS) on Russian-language forums. Additional coverage: BleepingComputer (October 2024), The Record, Krebs on Security. [12] SteamRep — Community Trading Reputation Database https://steamrep.com Volunteer-run platform that tracked scammers in Steam trading communities. Internal controversies, including alleged bribery for scammer tag removal and administrative corruption, were documented in community forum threads circa 2016-2020. Valve severed formal cooperation with SteamRep-affiliated moderators by 2022. [13] Jess Cliffe — Counter-Strike Co-Creator Reported by: Kotaku, Polygon, PC Gamer, The Verge (September 7-8, 2016) https://kotaku.com/ [search: "Jess Cliffe Valve"] Valve placed Jess Cliffe (credited alongside Minh Le for creating Counter-Strike) on administrative leave in 2016 following his arrest on charges of commercial sexual abuse of a minor. He was subsequently terminated without a court conviction. [14] Valve Steam Trade Hold Policy Steam Blog announcement on trade holds (December 9, 2015): https://steamcommunity.com/games/593110/announcements/detail/ The 7-day hold on traded items was formally introduced in December 2015. Earlier escrow mechanisms were introduced starting 2012. The policy change was intended to reduce fraud but in practice created the linear theft pipeline described in this report. [15] Valve Anti-Cheat (VAC) System Official documentation: https://support.steampowered.com/kb_article.php?ref=7849-Radz-6869 VAC bans are account-wide, permanent, and tied to the hardware/phone number used during the violation. The asymmetric application of VAC bans (aggressive for cheating, absent for mass phishing activity) is documented through community tracking at vacbanned.com and similar resources. [16] FBI Seattle Field Office Address: 1110 3rd Ave, Seattle, WA 98101 Phone: +1 (206) 622-0460 https://www.fbi.gov/contact-us/field-offices/seattle Valve Software is headquartered at 10400 NE 4th St, Bellevue, WA 98004 — within the FBI Seattle field office jurisdiction. [17] IC3 — Internet Crime Complaint Center (FBI) https://www.ic3.gov The FBI's official portal for reporting cybercrime, including account theft, fraud, and sanctions violations. Accepts reports from individuals, businesses, and third parties. [18] CISA — Cybersecurity and Infrastructure Security Agency https://www.cisa.gov US federal agency responsible for critical infrastructure cybersecurity. CISA's Stop Ransomware and Known Exploited Vulnerabilities programs are relevant to the infostealer ecosystem documented here. [19] DOJ NSD — Department of Justice, National Security Division https://www.justice.gov/nsd Oversees national security cases including sanctions violations (OFAC referrals), foreign influence operations, and cyber threats tied to nation-state actors. The potential nexus between state-adjacent structures controlling LZT Market and Steam's platform policy warrants NSD attention. [20] OFAC — Office of Foreign Assets Control (U.S. Treasury) https://ofac.treasury.gov Russia-related sanctions programs: https://ofac.treasury.gov/sanctions-programs-and-country-information/russia-related-sanctions Ukraine-EO13685 (Crimea), and subsequent executive orders cover the DNR/LNR regions. Accepting payments originating from sanctioned persons or territories — whether directly or through intermediaries — may constitute sanctions violations subject to civil and criminal penalties. [21] JSON Web Token (JWT) — RFC 7519 https://datatracker.ietf.org/doc/html/rfc7519 Industry-standard method for representing claims between parties. Steam adopted JWT-based session tokens as a replacement for legacy SSFN files. The off-platform validation capability of JWTs (verifiable without querying Steam servers) is a documented property of the specification. [22] Steam Direct — Developer Application and KYC https://partner.steamgames.com/steamdirect Valve charges $100 per game submission and requires developers to submit legal identification, tax forms (W-8BEN for non-US), and banking information. This KYC process creates a paper trail that directly contradicts the "anonymous hacker" narrative. [23] Roskomnadzor — Federal Service for Supervision of Communications, Information Technology and Mass Media (Russia) https://rkn.gov.ru The Russian federal regulator has issued multiple administrative decisions against LZT Market (Lolzteam) ordering its blocking. These decisions have been publicly available in Russian regulatory databases. The market's continued operation despite five such decisions points to legal maneuvering and possible political protection. [24] FunPay — Russian Peer-to-Peer Trading Platform https://funpay.com Widely used platform in CIS regions for trading in-game goods, including Steam balance top-ups and region-switching services. Transaction counts cited (500,000+) reflect documented seller statistics visible on the platform's seller profiles. [25] Tinkoff Bank — Sanctioned Russian Financial Institution Tinkoff Bank (now T-Bank) was added to OFAC SDN list and subjected to EU sanctions following Russia's 2022 invasion of Ukraine. OFAC SDN list: https://ofac.treasury.gov/specially-designated-nationals-and-blocked-persons-list-sdn-human-readable-lists Steam accounts were documented receiving top-ups from Tinkoff-issued cards in the CIS region after the imposition of sanctions. [26] Uniswap Protocol — Decentralized Exchange https://uniswap.org Uniswap and broader DeFi protocols have been targeted by phishing operations whose techniques and personnel originated in the Steam scam ecosystem. Security reports from Chainalysis, CertiK, and SlowMist document the migration of CIS-region fraudsters from gaming scams to Web3 drainer attacks. [27] Steam Session Files (SSFN) — Technical Documentation Community and security researcher documentation: https://steamdb.info / https://github.com/nicklvsa (various Steam security research repos) SSFN (SteamSentryFile) files stored Steam Guard authentication tokens locally. When stolen by infostealers, they allowed session reuse without re-authentication. Valve deprecated SSFN in favor of JWT-based sessions during 2023-2024. [28] Binance / Bybit / Gate.io — Cryptocurrency Exchanges https://www.binance.com | https://www.bybit.com | https://www.gate.io Major centralized exchanges whose Telegram payment bots and P2P trading infrastructure are used by LZT Market and similar platforms to process payments for stolen account transactions, circumventing traditional AML controls. [29] Steam Phishing via Google Ads — Documented Campaigns (2023-2024) Reported by: BleepingComputer, Malwarebytes, Group-IB https://www.bleepingcomputer.com/ [search: "Steam phishing Google Ads"] https://www.malwarebytes.com/ [search: "Steam phishing ads"] Attackers purchased Google Ads targeting Steam-related search queries, substituting display URLs to appear as legitimate Steam domains. The scale of the 2024 campaign documented by PhishDestroy ($300,000 estimated net proceeds) aligns with Google Ads abuse patterns documented by multiple cybersecurity firms. [30] STALKER 2 / GTA — Games Whose Publishers Withdrew from Russian Market GSC Game World (STALKER 2) officially suspended sales in Russia following the 2022 invasion of Ukraine. Rockstar Games / Take-Two Interactive restricted GTA sales in Russia following sanctions. Despite publisher intent, Steam continued to provide mechanisms allowing Russian users to purchase these titles via region-switching, as documented by community researchers and gaming press (Eurogamer, RPS, IGN, 2022-2024). --- ## ADDITIONAL CONTEXT: REGULATORY AND LEGAL FRAMEWORK Steam's Terms of Service (ToS), Version History: The Steam Subscriber Agreement is archived by the Internet Archive Wayback Machine: https://web.archive.org/web/*/https://store.steampowered.com/subscriber_agreement/ Comparison of versions shows modification of sanctions-related language, including the removal of explicitly named countries (Cuba, Iran, Syria) from prohibited territory lists. AML / FATF Guidelines on Virtual Assets: Financial Action Task Force (FATF) guidance on virtual assets and virtual asset service providers: https://www.fatf-gafi.org/en/topics/virtual-assets.html Skin trading platforms and Steam Wallet function as virtual asset ecosystems subject to FATF Recommendation 15. Europol — Internet Organised Crime Threat Assessment (IOCTA): https://www.europol.europa.eu/publications-events/main-reports/iocta-report Annual reports document the role of gaming platforms in cybercrime recruitment and infostealer distribution. Group-IB — Hi-Tech Crime Trends Report: https://www.group-ib.com/resources/research/ Documents the evolution of CIS-region cybercrime from gaming-platform fraud to ransomware and financial crime. Chainalysis Crypto Crime Report: https://www.chainalysis.com/blog/crypto-crime-report/ Annual report documenting laundering of cybercrime proceeds through decentralized exchanges and peer-to-peer platforms, including those accepting Steam-ecosystem stolen goods. --- ## NOTE ON SOURCES All market statistics cited (LZT Market account counts, transaction volumes, JWT token prices) reflect data documented at specific points in time by PhishDestroy through direct platform observation. Shadow market data is inherently dynamic; figures cited represent point-in-time measurements and directional trends, not static permanent values. Where possible, archived copies of relevant pages have been preserved on the Wayback Machine (web.archive.org) and independent archival nodes. All regulatory contact information (FBI, IC3, CISA, DOJ NSD, OFAC) reflects publicly available official contact data as of the date of this publication. PhishDestroy Demands Valve must be held financially accountable for accounts stolen through their deliberate negligence. The minimum estimated liability: $450,000,000 — representing the documented victim real spend on accounts currently listed on LZT Market across all categories, and the value of inventories frozen on banned bots that were never returned to victims. This is not an estimate of criminal market value. This is the documented money victims spent on their accounts — money that Steam's negligence, outsourced corruption, and deliberate API blindness allowed to be stolen and re-monetized on criminal markets while Valve collected commission on both the original sale and every subsequent stolen skin transaction. Valve wrote the policy that prevents item restoration. Valve's outsource staff committed the thefts. Valve's API enabled the marketplace. Valve's 15% commission runs on the same skins. The accountability is structural, not incidental. Back to News & Investigations # The Steam API Scam Symbiosis: Deception & Negligence Published: 2026-08-21 · Category: Investigation · Words: 14,088 Mirror: https://valve-xmr-5kus.4everland.app/articles/steam-api-scam-exposed.html Original: https://phishdestroy.io/steam-api-scam-exposed 5Algorithms for offer swap scans 2 DaysmaFile trade hold cooldown $10M+PhishDestroy minimum estimate 1 IP → 1,000+Ihor: active hijacked sessions on one address ## Investigation Finding Steam is fully complicit in the multi-million dollar API offer swap scam, sustaining a mutually beneficial symbiosis with skin stealers and illegal gambling operators. ## 1. Introduction: A Symbiosis of Calculated Negligence Steam has always been entirely fine with every development—including any regulations and changes (for example, the trade holds or trade bans after changing nickname). These are forced measures, but they are ineffective and incomplete. Valve has no genuine desire to fight this, because they understand that their platform depends on both scams and gambling, as well as the rest of the shadow economy that Steam has bred, allowed to emerge, and exist for many years. It is not that they are attacking Steam; it is a symbiosis—mutually beneficial and understood by both participants of this symbiosis. The notorious API scam (commonly known as offer swapping/replacement) originated a long time ago. Phishing has always relied on trade replacement. In its persistent form, it appeared around the spring of 2019 (prior to that, it existed as separate phishing, which eventually evolved into a replacement with duration limits of 1, 4, or 8 hours). By the spring of 2019, all the tools active on the scam market made the hijacked session 'mobile'. And that is how it lived through its hyper-popularity. By our most conservative estimates, this allowed the theft of at least $10 million and more. But you must understand that, in general, this breeds cybercriminals. Steam protects scammers by playing the game of 'skins are worthless.' The introduction of the trade hold came after the offer swap mechanism was already established. The endless 7-day trade hold was added abruptly and without reason. This is not anti-scam; it's regulation. Let us explain how offer swapping works, and why Steam and its anti-scam attempts are a complete clown show (and always have been). ## 2. The 2017–2018 Blueprint: Five Private Algorithms To understand the scale of the operation, we can look back at the private scam panels operating from 2017 to spring 2018. During this period, developers designed five distinct operational algorithms for the offer swap method. This private update included all five algorithms: the panel's bot logged into the user's account and operated according to one of the five algorithms below, bypassing 2FA with Guard validation. Scammers could configure these settings (sending games, minimum offer price filter, etc.) directly in their admin panel. Investigation visualFive Private Algorithms Offer swap, in one paragraph: the victim verifies a legitimate trade on the PC. Before the phone confirmation, an attacker-controlled session cancels it, copies the counterparty’s name and avatar, and sends a replacement offer. The victim then confirms the replacement in Steam Guard—often an offer that returns nothing. The Guard code is not broken; the offer underneath the familiar confirmation step is changed. Technical appendix: offer-swap variants and panel evolution Algorithm #1: The Classic Swap Checks the offer: is it from a trading website? If yes, it performs the actions below. Cancels the offer from the official trading bot. Parses the nickname, avatar, and trade message from the official bot's account and sets them all on the scammer's bot account. Sends the exact same offer, but from the scammer's account, with the same items, the same nickname, and the same avatar. Algorithm #2: Delayed Swap Checks the offer: is it from a trading website? If yes, it performs the actions below. Does not cancel the offer from the official bot immediately, but waits for the user to accept it on their computer (not on the phone). Once the user accepts it (on the computer), the bot cancels the official offer. Parses the nickname, avatar, and trade message from the official bot's account and sets them on the scammer's account. Sends the exact same offer from the scammer's account, with the same items, the same nickname, and the same avatar. Accepts the offer (from the scammer's bot) on the computer. As a result, the user confirms the trade on their mobile app, thinking it is from the official bot, when in reality it is from the scammer's. Algorithm #3: Outgoing Hijack The user sends an offer using the scammer's bot's trade link and goes to confirm it on their mobile app. The scammer's bot cancels the user's offer. Sends an offer from the user's account containing all of their items (eligible games can be selected in the admin panel) to the scammer's bot's trade link. The user then confirms this modified trade on their mobile app. Algorithm #4: Dual Direction Swaps Incoming Offers:When an offer is sent to the user asking only for their items, the swap occurs when the user goes to accept it on their phone (after accepting it on the computer) [using Algorithm #2]. When an offer is sent to the user for both their items and the counterparty's items, the swap occurs when the user goes to accept it on their phone (after accepting on the computer). Outgoing Offers:When the user sends an offer to someone containing their own items, while they are heading to confirm it on their mobile app, the swap is executed. The verification of the user's mobile confirmation on the bot's side is handled via automatic trade acceptance. Algorithm #5: Inventory Sweeper Identical to Algorithm #4, except that during the outgoing offer swap, it first adds the user's items that were already part of the trade, and then appends the entire inventory of the selected games underneath. Eligible games to be emptied can be chosen in the admin panel (CS, DOTA, H1Z1, PUBG). ## 3. Scam Panel Infrastructure & Admin Features Scam networks are run like legitimate SaaS enterprises. Their admin dashboards include robust, multi-threaded features designed for rapid exfiltration and control: Detailed log table showing active SteamIDs under replacement: 'SteamID', 'Inventory ($)', 'Time left until the swap session expires', 'Offers Swapped', 'Operational Algorithm', 'Price Filter', 'Swap Session Start Time', 'Note', 'Actions'. User management features: pause, resume, delete, update trade link. Min-price threshold filter in USD (offers whose total item value is below this threshold will not be swapped, avoiding wasting time on low-value items). This option is accessible under the 'Settings' tab. Prices for CS, DOTA, H1Z1, and PUBG are updated daily between 5:00 AM and 7:00 AM. Manual trade link updates if the user changes their trade URL. Offer bot control (start, stop, restart). In-built Steam Browser. And many other features... Investigation visualScam Panel Features ## The Special 'maFile' Phishing Bundle There is also a separate bundle targeting maFiles (Mobile Authenticator files). The core mechanic involves grabbing an SMS code, waiting out a 2-day cooldown, emptying the skins, and fully hijacking the account. Investigation visualmaFile Phishing Bundle The victim authenticates on a phishing site with their username and password (validated in real-time). Following this, an SMS-code entry prompt appears (in place of Steam Guard), showing the last two digits of the phone number where the SMS was sent. Once a valid SMS code is supplied, the admin panel automatically generates a maFile. With this file, scammers can generate Steam Guard 2FA codes and accept trades directly. However, this newly generated maFile is subject to a 2-day trade restriction (hold): any trades initiated within the first 2 days since the maFile creation are held for 48 hours and can be canceled by the owner. Once the new maFile is generated in the scammer's panel, the victim's old mobile authenticator will begin generating invalid codes, though to the victim, the app appears to be functioning completely normally. The text of the incoming SMS that the user receives reads: "The code to disable or move Authenticator is: 13204". The admin dashboard also features options to download the maFile, check its validity, generate 2FA codes (similar to Steam Desktop Authenticator - SDA), initiate an offer containing all inventory items with a single button, or execute an automatic offer with a 2-day hold immediately after maFile generation. Furthermore, the dashboard later added "auto-phishing" and one-click account hijacking features. For convenience, a visual countdown timer tracks the remaining hold duration directly next to the maFile. ## 3b. Operational Methods ## 1) Targeting Skin Theft: Delayed Exfiltration: Wait 2 days after the maFile generation, then send a trade offer to your destination account (a single button in the admin panel sends all skins to the target trade link). Requirements for success: the victim must not change their phone number or password during these 2 days (as doing so invalidates the maFile in the panel). Immediate Auto-Offer: Send an auto-offer containing all inventory items to the target trade link immediately upon maFile generation. Do not accept this offer right away so the items don't vanish from the victim's account prematurely. Simply wait 2 days and accept it. Under this method, changing the password or linking a new mobile authenticator won't stop the trade, though if the victim updates their authenticator, the hold resets, requiring another 2-day wait. Requirements for success: the victim must not manually cancel the pending trade offer over the 48-hour hold. ## 2) Targeting Account Theft (Phishing): Direct Account Sale: Sell the account pre-loaded with its maFile. After generating a maFile, the victim is far less likely to suspect foul play compared to traditional phishing, which often triggers an immediate Red Sign lock on the account. Consequently, scammers have a wider window to flip the account on markets. However, there is always a risk that the victim attempts to log in from a new browser/PC and regenerates the maFile on their phone, or resets their password. Auto-Phishing: After the maFile is captured, the account is automatically queued for automated credential stripping and locked with a Community Ban. Phishing combined with maFile generation targets and strips only the mobile Steam Guard. One-Click Phishing: Installs a Community Ban and triggers automatic stripping of credentials on command. Additionally, this bot can be integrated with OPSkins cookie parsing and 2FA verification. The backend is multi-threaded and capable of processing countless accounts per second. ## 4. The Anatomy of Deception How does the fraud actually unfold? A kid receives a link on Steam (the domain could masquerade as a tournament, an airdrop, or a skin-trading site). The page features an authorization button and highly sophisticated sign-in interfaces: a fake browser-in-browser pop-up window that literally displays the 'official Steam domain' (using about:blank tricks or custom windows to hide the actual phishing URL). Or, rather than a visual window overlay, it opens a full-screen, perfectly cloned Steam login page hosted on a spoofed domain. The kid authenticates directly, typing in their username, password, and Steam Guard code. And that's it. Nothing happens—the phishing site either redirects them somewhere else or simply displays the login form again. Investigation visualThe Flow of Deception ## 4a. But What Actually Happened Behind the Scenes? On the attacker's server, a live session is spawned immediately after authentication—essentially establishing a fully authorized account session. The script then immediately requests an API key for the account (via steamcommunity.com/dev/apikey). Scammers would later introduce integrated headless browsers inside active sessions, alongside automation for auto-spamming, closing support tickets, and more. To run this operation, scammers require ready-to-use bot accounts with active trading privileges and no community limits. These are automated bulk-registered accounts (pre-loaded with exactly $5, aged for 14 days to unlock trading). Yes, they are registered completely automatically using registration software. Steam, of course, sees and detects these registrations (even with proxies); it is fully aware of the software-driven activity patterns—accounts funded with exactly $5 to lift the limit, with the funds sitting completely untouched. Once purchased, these accounts are plugged into the scam panel. From that point on, the entire attack operates almost exclusively via raw API requests. The only exception is selling the stolen items: typically, they manually access the browser, list the skins, transfer the funds, and cash out (though some claim to have achieved complete end-to-end automation, where a bot supposedly lists the skins, executes sales, and automatically payouts workers, spammers, and traffic drivers). The authentication originates from a brand-new IP, and the software-made session comes from a static hosting/ISP pool—predominantly Ihor. PhishDestroy's preserved data and files from one such product show more than one coincidentally overloaded address: some Ihor IPs were consecutive, including addresses ending .156, .157 and .158, and each carried more than 1,000 active hijacked sessions at once. This is not an outside estimate; it comes from the infrastructure examined in the product files. A separate scheme later appeared on the receiving-bot side: one bot received one IP slot; replacing the bot in that slot retained the address, effectively assigning it for about a month. Yet a server login could still create an API key and an indefinite parallel session. Is that normal player behavior? Recorded attack mechanism · infrastructure scale stated belowFrom intercepted MFA to token replay and mass session pooling Editorial reconstruction · official Steam rules linked belowOne account, two rules: strict game enforcement and tolerated web-session abuse Enforcement asymmetry ## Valve protects the license. Not the account. Two people trying to play from one account is an emergency. One Ihor IP holding 1,000 active hijacked sessions apparently is not. Game licenseSecond player: forced re-loginSteam’s own rules say simultaneous play on one account is unsupported: the first user eventually receives an “Invalid Steam UserID Ticket” and must log in again. An unrecognized device separately requires a Steam Guard code. Account securityForeign session: allowed to persistIn the documented infrastructure, one Ihor IP simultaneously held 1,000 active hijacked sessions that created keys, monitored accounts, and cancelled or replaced trades. Steam did not mass-revoke that single pool or force the owners through clean reauthentication. What exactly is not worth protecting—the inventory, private messages, the profile, or every friend exposed to phishing spam? The minimum response is obvious: when a known US account suddenly gains a parallel hosting session from an IP already carrying 1,000 hijacked accounts, revoke that session, the API key it created and its confirmations. Instead, the MITM session could indefinitely read chat beside the owner and control trades. License sharing is interrupted; takeover signals are tolerated, and the loss is assigned back to the victim. Furthermore, on Steam, your API key remains completely indefinite. Even if you manually delete or change it, your session will automatically regenerate it upon any background action (such as session health checks, inventory valuation, or routine timer-based checks, which scam panels ran by the thousands). This persistent session access ensures scammers can monitor accounts in real-time before users notice. It's rare for users to catch on: typically, once they are phished, their session eventually dies or is discarded. But if a victim merely deletes or changes their API key, the script immediately recreates it using the active session. The bots are bulk-registered accounts with a $5 balance. The market is massive, and competition is so fierce that the accounts are sold almost at their raw cost of $5. Steam clearly sees, for instance, that a kid's phone—the active session containing the Steam Guard authenticator—is located in the US; it sees their computer and browser in the US. And simultaneously, it sees an active session originating from Russia or the Netherlands (the provider Ihor was the main hub for a long time, as it was packed with these specific IPs). Yes, the theft began at scale. Steam commented on nothing. When kids wrote to support, Steam didn't even instruct them to change their password; instead, support sent generic boilerplate replies stating that the skins were gone and it was 'not our problem.' Later on (around 2021–2022), scammers began automatically closing support tickets themselves: a child would open a ticket, and the panel's automated script would immediately close it. The kids believed it was Steam support dismissing their cases. It wasn't. But Steam essentially stood by and allowed it to happen. The hypocrisy of Steam and its 'anti-scam' updates is staggering, considering how much data Steam stores: it tracks countries, IP histories, and device fingerprinting. Steam consciously hid the fact that accounts were actively compromised. And then, there were incidents where Steam issued mass community bans to the accounts of the victims who were caught in active swap sessions. Wow, great job, Steam! Steam slapped locks on victim accounts simply because they shared a proxy IP with other sessions, instead of, say, terminating the unauthorized sessions. And when victims contacted support to appeal the bans, support played dumb, pretending they couldn't see or know anything. But we know they see everything: your devices, hardware IDs, transaction logs, history of changes, previous passwords, phone numbers, emails, and exactly when and from which device they were modified (this is the funniest part: Steam knows when an account is hijacked—it logs the exact device ID, timestamp, and IP address of the attacker). The contradiction ## The anomaly is visible. The answer is still scripted. Support does not lack the signal. The account record shows a verified local device, a simultaneous foreign hosting session, repeated trade modifications, and the exact timing of the theft. Yet the drafted response ignores that telemetry, blames “user error or phishing,” refuses restoration, and closes the ticket. That is a choice not to act—not a lack of evidence. Verified local deviceForeign hosting sessionRepeated trade changesTemplate refusal · ticket closed Illustrative reconstruction · not a leaked Steam interfaceThe data says account takeover; the reply says “user error” ## 4b. The Trade Hold Illusion So, a terrified kid writes to Steam Support: "Aaa, help, my skins were stolen! I was sending them to my friend, or a trader, or a trading website, but they went to a completely different account with the exact same nickname and avatar, not the one I accepted in the trade!" UX blind spotThe final screen feels familiar, although the trade underneath has already changed The swap on one screenYour items are listed. The receiving side is empty. How did this actually happen? Indeed, the replacement doesn't hijack the trade instantly. In your browser, you review the original trade offer, click 'confirm'—items for items, or sent to your friend's verified account. You verify the details, and everything matches. But in the brief window of time between accepting the trade on your PC and opening your phone to confirm it—that is when the scammer's bot, cloned with the same name and avatar, cancels the legitimate trade and sends its own. Yes, on your phone screen, you are looking at the swapped trade. Initially, it shows your outgoing items, but at the bottom, you receive absolutely nothing in return. And users ignore the warnings because they already verified everything on their computer. The psychological precision of this scam and the vulnerability of the user base are stunning, especially since victims fully believe they are executing a safe transfer. Yet Steam's servers observe a session, created weeks or months ago from a completely different IP address, cancel an active trade and immediately initiate and accept a new one—and treat it as a completely normal, legitimate transaction. Seems highly legitimate, doesn't it? I want to highlight that long before Steam introduced its clumsy, ineffective updates, third-party trading sites stepped up to take action. They valued their reputation, and perhaps they simply felt sorry for the defrauded children. For instance, the site tradeit.gg implemented a system where if their official trade offer was canceled, a massive "CANCELED" alarm blasted on the user's screen. This was a real solution, which is why we recognize them as pioneers who actually tried to do something. So, an external site utilizing the Steam API could detect a trade swap in real-time, but Steam itself couldn't? Or did they simply refuse to terminate an unauthorized session that obviously had zero relation to the legitimate user? Yes, Steam's support tickets repeatedly claimed: 'Your items are gone, we cannot help,' and the scammer's receiving bots were rarely even banned (and if they were, it was long after the fact). Even after trade holds were introduced, the average ban rate for active scam bots (locks that ultimately benefit Steam's economy rather than returning items to victims) hovered around 15–25% at peak times. Meanwhile, the hosting provider where the bots operated remained Ihor, and these automated sessions never utilized residential or mobile rotating proxies. ## 4c. Proof of Static Infrastructure We can prove this. As you know, PhishDestroy is a radical anti-phishing project. We flooded phishing forms with fake seed phrases at scale to exhaust their servers' loading and processing capacities. This is actually where we originated the concept: Steam enforces rate limits on login attempts per IP address. Years ago, we executed this using free public proxies, sending endless invalid login attempts or targeting accounts protected by email Steam Guard. Eventually, Valve began blocking these attempts, and since we weren't purchasing commercial proxy networks, it proved less viable over time. However, as we now realize, it could have been highly disruptive, yet in Valve's twisted logic, interfering with scammers' operations was deemed 'unethical.' By driving the scammers' authentication forms offline for hours, we established that they were not using a vast residential proxy network but static proxies or VPS addresses. The preserved product files confirmed two distinct models: hijacked sessions pooled 1,000+ per Ihor IP, while receiving bots used stable slots—one bot per IP. Replacing a bot in the same slot retained the IP; the address was effectively assigned for about a month. ## The Bottom Line: An Open Crime Scene Steam saw everything, knew everything, and simply remained silent instead of acting to protect its users. What a platform that claims security is its top priority. Furthermore, an attacker with an active browser session could concurrently monitor your account, read your chats, or modify your profile (for instance, staging a fake 'VAC Ban' notice) to panic you into quickly transferring all your items to a friend or a 'safe' alt account—driving them directly into the offer swap trap. Yes, they could actively read your private chats with friends and view your media in real-time right alongside you. Apparently, Steam considers parallel sessions from entirely different countries to be standard behavior for a gaming platform (perhaps reasoning that since Family Sharing exists, 'it's fine if they steal, as long as they aren't playing CS:GO simultaneously'). ## 5. The API Key Trap: Changing Your Password Is Not Enough Even if you changed your password but forgot to revoke the active API key, scammers could still rob you. Yes, without an active session, their script could no longer navigate your profile or auto-accept trades. However, the official Steam API still allowed them to execute the most critical actions: monitoring your account activity and canceling pending trades (via CancelTradeOffer). Armed solely with your API key, the bot would instantly detect and cancel your legitimate trade, and immediately dispatch a fake clone offer from its own account (directed to your trade link). From that point, the script simply waited. It couldn't click confirm on your behalf. The entire scam relied on you opening your mobile app and voluntarily confirming the swapped trade in Steam Guard. And it worked flawlessly. There is a critical technical nuance: with only an API key (and no active session), the script cannot inject a trade directly into your Steam Guard confirmations. It must send a new incoming trade offer. This means you have to manually click 'Accept Trade' on your PC first, before it populates in your Steam Guard app. One would think this extra step reduces the scam's success rate—after all, when accepting a new trade from a stranger, Steam displays massive warnings ('You are not friends', 'This account has been flagged'). But the scammers exploited human psychology and muscle memory. Because the victim had initiated the original trade themselves, they were already mentally prepared to part with their items. When they saw the trade suddenly cancel and a new one immediately arrive with the exact same items, nickname, and avatar, they assumed: 'The site lagged and re-created the trade.' The user mechanically clicked through Steam's warnings on autopilot, accepted the fake trade, and confirmed it on their phone. The scam succeeded not by bypassing Steam Guard's security, but by weaponizing human inertia. ## 6. The Verdict: Complicit by Design Our main message remains: we owe a special thank you to Valve and their support staff, who found it incredibly convenient to 'see nothing and know nothing.' Investigation visualComplicit by Design They love to claim that they technically lack the tools or capability to assist. But the reality is completely different. To recover a hijacked account, support does not actually need some ancient, dusty CD key from ten years ago. Steam captures a vast array of other parameters that are deliberately ignored during recovery disputes. We are talking about your unique device identifier. This isn't a simple HWID, a hard drive serial number, or a BIOS version—it is a unique hardware fingerprint that Steam retrieves, likely at the same kernel/deep system level as their VAC anti-cheat. So when Valve refuses to restore your account simply because you 'lack a CD key,' it is not a technical limitation. It is a business strategy. It is the desire to force you to purchase your games all over again, and a flat-out refusal to return control over high-value inventories of skins. It is unethical, but it is deeply 'Steam-like.' The same goes for their support system—a cheap, outsourced customer service operation whose internal policies are designed to avoid providing actual help or even basic courtesy. Everything is reduced to scripted copy-paste replies and terminating tickets unilaterally. But Steam is completely fine with that. ## 7. Questions Congress Must Put to Valve Editorial allegation map · not published Valve metricsThe system hides the frozen-asset total; only Valve can disclose it ## How much player value is locked? How many CS2 and Dota items sit in trade- or community-banned accounts? What percentage of circulating supply and what market value do they represent, broken down by year, restriction type, item rarity and time frozen? Demand: Aggregate totals, methodology, age buckets, an independent audit and inspectable disclosure of banned-bot inventories. If the figures rebut the allegation, publish them. License, rights and disclaimerThis formal legal declaration accompanies every submission in this referral set, outlining the waiver of rights, OFAC-region access restrictions, and liability limitations. text449 linesCopy ================================================================================ P H I S H D E S T R O Y LICENSE · RIGHTS · DISCLAIMER Investigation: Valve Corporation / Steam Edition: public — no expiry date, no take-backs ================================================================================ ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ SECTION I — LICENSE (THE ACTUAL LEGAL PART, BUT HUMAN) ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ PhishDestroy gives up every right to this material. Zero. Gone. Done. You can reproduce it, sell it, put your name on it, tattoo it on your boss, whatever. No credit required, no DM needed, no thank-you card expected. ┌─────────────────────────────────────────────────────────────────────────┐ │ ONE ACTUAL RULE (yes, just one) │ │ │ │ YOU do NOT get to decide whether you're a terrorist. │ │ │ │ If you are a user from Russia or any OFAC-sanctioned country — │ │ this material is NOT for you. No loopholes. Enjoy your sanctions. │ │ │ │ And if you switched your Steam region to Turkey while sitting in │ │ Moscow — congratulations on your creative geography. You're still │ │ Russian. The sanctions still apply. That's literally the point. │ └─────────────────────────────────────────────────────────────────────────┘ ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ SECTION II — WHAT THIS IS AND WHY IT EXISTS ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ We will publish more about Valve than an average Valve employee knows about themselves. That's not a brag. That's just where we ended up. How did we get here? Funny story: Steam basically created us. It raised us on its scammers, its support tickets, its ban evasion ecosystem — and now here we are. No hard feelings. Poetic, actually. For those who haven't read the origin story yet — we already met Valve's extremely expensive European lawyers (Taylor Wessing, since you asked): https://phishdestroy.medium.com/my-dog-vs-elite-gdpr-lawyers-the-valve-data-breach-nobody-is-talking-about-f6f7683d813d Charming encounter. Especially given their hourly rate. Did Valve know? Yes. Did Tyler Wessing know? Almost certainly yes. But when you're that rich, laws are more of a vibe than a requirement, right? That's kind of the whole answer, actually. Steam spent years farming scammers. Not always intentionally — sometimes scammers just got Valve's fingerprints on them by association. We're not trying to be dramatic about it. We're trying to be precise. That's harder for us than being dramatic, to be honest — this is just how we write. Is this a conflict? — No. Can it be resolved? — Yes. But we're not signing any NDA and we're not playing bug bounty for pennies. We waited over 4 years for them to fix the spoofing issue before we could write about it publicly. Because if we had written about it earlier, Steam would've put on its little victim face and screamed "active threat!" and offered us pocket change to sign a document that would've made us their legal property forever. No thanks. (Also: Valve itself violates NDA. Their own employees do. The ones near the top. But sure, let's talk about ours.) ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ SECTION III — OPEN LETTER TO VALVE (SERIOUSLY, READ THIS) ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ Hey Valve. If you're thinking about taking down our domain — just email us. Don't pay Dr. Patrick again. Please. It's embarrassing for everyone involved. For the uninitiated: Dr. Patrick holds a Master of Laws in International Commercial Law from the University of Aberdeen and — wait for it — literally finished his doctoral dissertation in IT law. He recently made partner at Taylor Wessing, which is a firm whose entire business model is billing companies like Valve obscene amounts of money to drag things out until the other side runs out of money or patience. We don't blame him. Rich guilty clients who pay by the hour — solid career move. We just don't think you should be funding it. ┌─────────────────────────────────────────────────────────────────────────┐ │ THE DEAL (open offer, no lawyers needed) │ │ │ │ If you want the domain gone: │ │ Let your IT law professionals calculate the price. │ │ 50% goes to the SEAL Foundation. │ │ We kill the domain. No drama. No court. Done. │ │ │ │ You won't get it any other way. That's not a threat. │ │ That's just the architecture of the situation. │ └─────────────────────────────────────────────────────────────────────────┘ Will we "damage" Valve directly? Probably not in a way they'll feel fiscally. We're not delusional. But we will do it honestly, openly, without chasing clout — because we don't need clout. We need the world to see what was always publicly visible if you spent enough time looking. We have 5 years of archives. What Valve's lawyers showed in discovery — the data that support agents can see, the fingerprints, the paper trail they literally handed us — is enough. We don't need to leak it raw. — Regulators get the originals. — Researchers and journalists get redacted versions (victim reports, children's logins and Valve's charming support commentary removed for obvious reasons). Yes, children. Steam decided not to notify minors who were at risk. We noticed. We're being careful about how we say this because we don't want to become blackhats or NDA slaves. But we noticed. Also, Valve — we want to make something clear before you decide how to play this: PhishDestroy is a community, not a person. You learned that when you addressed legal correspondence to the community without bothering to speak with the community — just milked it for data and banned the accounts. The community has no conflict with Valve. We didn't go looking for this. The scammers you grew found us. We blocked them. And here we are. ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ SECTION III-B — THE ALLIED RESOURCES (a note to Steam specifically) ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ We want to be upfront about the amplification structure, because pretending it doesn't exist would be dishonest. PhishDestroy, as we understand the community situation, has at least two allied resources that will pick up this material and run with it. What that means in practice: — They work their own angles on overlapping subject matter. — They are independent — they don't take our direction, we don't take theirs. Same general topic, different methodology. — They will NOT be activating on Part 1. They're watching. If Valve chooses not to take down the site: — Expect them to surface after Part 2 or Part 3. — They'll take what's useful from our work, supplement it with their own, and publish under their own authorship. — This is exactly the kind of thing the license in Section 1 is built for: the material goes where it needs to go, gets supplemented, gets amplified — and neither we nor they owe each other attribution. (PS for lawyers wondering about liability chains: there are none. These resources don't receive our direction, our funding, or our data. They read what's public and draw their own conclusions. Just like you could.) We're not saying this to intimidate. We're saying it so that whoever is strategising on Valve's side has accurate information about what the information environment actually looks like. One resource that pulls our material and supplements it would be a story. Two resources doing it independently and reaching similar conclusions is a pattern. Patterns are what regulators notice. ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ SECTION IV — THE MONEY, THE BANS, THE WHOLE CIRCUS ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ Here's the thing about Steam banning gambling sites and scammers: it's not enforcement. It's revenue capture. Valve pockets the money, cleans its hands, then goes on stage and tells everyone a wholesome story about Pokémon cards and baseball. Meanwhile Valve killed the ability to properly track skins in 2017. They even discussed it on their own forums. Called it "anti-gambling measures." The gambling that their own support staff were running as a side hustle — getting paid in percentages to lift bans. But sure. Anti-gambling. Great branding. We're going to prove that: → Skins are more anonymous than Monero → A Peruvian Cartel allegedly used Dota 2 skins for money movement → Steam is functionally a sanctions-bypass machine worth ~$7B in "trading cards" (yes, they actually said trading cards to a prosecutor) We've got a video on the skins thing. You'll see it. We also know: → Reddit moderation is influenced by Valve → steamid.uk and similar infrastructure is run directly by one Steam developer, controlled exclusively by him and his circle → What they can't control, they ban Valve: if you keep playing dumb — that's fine. Your safe harbour is noted. Google Analytics anonymises your users' IPs anyway. We see what gets deleted. We just can't prove it cheaply enough for your lawyers to care. Yet. ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ SECTION V — THE MALWARE THING (yes we're mentioning it) ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ Let's be clear about the sequence of events, because it matters. We are NOT disclosing the vulnerability in the game publicly. We are NOT reporting it to Steam. Not because we can't — because their bug bounty is worth approximately three kopecks and we don't work for three kopecks. Here's what actually happened: Our security colleagues (the ones who do this professionally) already reported it to Steam support. That part is done. Steam has been informed through the correct channel by the correct people. So what are we doing? We're telling you it exists and roughly what it is, because "Valve knows about it and is doing nothing" is a data point that belongs in this referral. The game is sufficiently popular. We're not naming it here. What we can say: This is NOT the trivial CSGO variant — the one where unofficial servers ask you to "install a driver" and you think nothing of it. Everyone in security has seen that. This is worse. This is closer to: RCE on server connect. As in — you join a server, you don't click anything, you don't install anything. The connect itself is the attack surface. The game is not technically Valve's. Which means when this eventually surfaces, the developer signs the NDA, takes the hit, and Valve walks away looking like the responsible platform that "worked with" the developer to resolve the issue. Classic Valve move. We've seen the template. The threat is active. We've shared the technical details with other researchers through a closed channel. We are not publishing them here. We are telling you it exists because you — regulator, prosecutor, journalist — should know that Valve operates a platform where this is possible, has been informed, and the primary incentive structure (NDA + bounty) is designed to make the researcher disappear rather than make the users safe. ================================================================================ DECLARATION AS TO USE AND RIGHTS PhishDestroy Project & Cybersecurity Coalition ================================================================================ This declaration accompanies every submission and every exhibit in this referral set. It is addressed to any authority, court, regulator, prosecutor, researcher, journalist or affected person into whose hands the material comes. 1. THERE ARE NO CONDITIONS ON USE 1.1 All material produced by the Coalition in this referral — the statements of fact, the analysis, the exhibits it has authored, the tooling, and the findings — is released WITHOUT RESERVATION OF ANY RIGHTS. 1.2 Anyone may, without asking and without notifying us: — reproduce it, in whole or in part; — adapt, edit, rewrite, restructure or correct it; — translate it; — excerpt it without indicating that it has been excerpted; — incorporate it into official documents, findings, decisions, pleadings, reports or press material; — present it as the recipient's own work or the recipient's own findings; — use it as raw material and discard the rest; — and pass it on to anyone else on the same terms. 1.3 ATTRIBUTION IS NOT REQUIRED AND IS NOT SOUGHT. The Coalition need not be named, cited, credited, thanked, consulted or informed. If material from this referral assists an authority and the Coalition is never mentioned, THAT IS A COMPLETELY SATISFACTORY OUTCOME and the Coalition states so in advance so that the question need not be raised. 1.4 If, on the other hand, an authority finds it more convenient to cite the Coalition as a source, it is free to do so. The choice is entirely the recipient's and neither course carries any consequence. 1.5 This is a WAIVER, not a licence offer. It requires no acceptance, imposes no obligation, and cannot be breached. Software published by the Coalition is separately released under the MIT licence; the research and findings are released into the public domain to the fullest extent permitted, and where a jurisdiction does not permit waiver, the Coalition grants an irrevocable, worldwide, royalty-free licence to the same effect. 2. WHY THIS MATTERS PRACTICALLY, AND NOT ONLY AS A COURTESY 2.1 An authority may reasonably hesitate to rely on material supplied by an outside party, for fear of appearing to act at that party's instance or of acquiring some entanglement with it. 2.2 THERE IS NOTHING HERE TO BE ENTANGLED WITH. The Coalition asks for nothing, is owed nothing, retains nothing, and has no expectation of any kind. It cannot later assert a right, claim credit, complain of misuse, or object to how the material is characterised, because it has retained no basis on which to do so. 2.3 An authority using this material is therefore not acting for the Coalition. It is using public information that happens to have been assembled by someone else. 3. EVERYTHING IS OPEN ALREADY 3.1 The Coalition's work is public by default: — the investigations are published openly at https://phishdestroy.io and are freely readable; — the tooling is published as open source under the MIT licence at https://github.com/phishdestroy ; — the methodology is set out in the referral itself, at Annex A section A.16D, including the weight and limitations of each source type; — the Coalition accepts no donations and has published that position since 2018. 3.2 The only material NOT published is that which cannot lawfully or safely be published: personal data of victims and of third parties, and information that would expose a source to retaliation. That material is supplied to authorities in confidence and is identified in the schedules of evidence. 3.3 The Coalition invites scrutiny of its own conduct on the same terms it invites scrutiny of anyone else's, and has volunteered its own data handling to the authorities concerned, including a request for a direction on disposal. 4. INTEGRITY OF THE EVIDENCE BUNDLE 4.1 Exhibits are supplied with the submission or, where marked, on request through a secure channel. They are not published at a public address and no such address should be inferred: material of this kind is provided to authorities directly. 4.2 Each delivery is accompanied by a file SHA256SUMS listing a SHA-256 digest for every file supplied, together with a detached OpenPGP signature SHA256SUMS.asc. 4.3 The signing key is published at https://phishdestroy.io/.well-known/pgp-key.txt and on keys.openpgp.org. Its fingerprint appears in the letterhead of every submission in this set. 4.4 Any recipient may verify at any time that a file in their possession is the file that was sent, unaltered: gpg --verify SHA256SUMS.asc SHA256SUMS sha256sum -c SHA256SUMS 4.5 The purpose is not formality. It is so that, if the accuracy or integrity of any exhibit is disputed at a later date, the question can be settled by computation rather than by argument. 5. ON REGISTER — WHY THE WAIVER IS FUNCTIONAL AND NOT MERELY GENEROUS 5.1 The authority may encounter the Coalition's published investigations and find them blunt, adversarial and at times satirical. That impression is correct. The Coalition writes that way deliberately and does not apologise for it. 5.2 IT ALSO RECOGNISES THAT THIS IS THE WRONG REGISTER FOR A REGULATORY OR JUDICIAL PROCEEDING. A serious matter should not be carried in the voice of a campaign. Findings put before an authority should be stated flatly, with their limitations admitted, and should not require the reader to discount for tone before reaching the substance. 5.3 THAT IS PRECISELY WHY THE COALITION WAIVES AUTHORSHIP. The waiver at section 1 is the mechanism by which the substance can be separated from the register: the authority may take what is useful, restate it in its own voice, and discard every word of the Coalition's manner along with the Coalition's name. Nothing is lost by doing so, and the Coalition would prefer it. 5.4 THE COALITION ALSO ASKS THAT THE REGISTER NOT BE MISTAKEN FOR THE METHOD. The published tone is combative; the underlying practice is not careless. Throughout this referral, inference is separated from observation, testimony is identified as testimony, sources are weighted and their weaknesses stated, figures are presented with their limitations, and points the Coalition cannot prove are put as questions for the authority rather than as assertions. Where the evidence cut against the Coalition's own position it has said so — see Annex A, paragraph 7, and section B.0 of the parallel referral. 5.5 THE COALITION EXPLAINS THE CONNECTION BETWEEN ITS MANNER AND ITS FINANCES BECAUSE THE TWO ARE NOT SEPARABLE. It takes no money from anyone — no donations, no bounties, no clients, no sponsors. That refusal is what makes the bluntness possible: an organisation with revenue to protect must moderate what it says about the parties it depends on. Having nothing to protect, the Coalition has nothing to moderate. It is also the reason the Coalition continues to exist. There is no other engine. The work is done because it is done; it stops when the people doing it stop. 5.6 The authority need accept none of this. It is stated so that the tone of the Coalition's public work is not read as a measure of the care taken with the material now before it. 6. WHAT THE COALITION IS PROVIDING, IN ITS OWN WORDS Information, research and observation. Nothing is asserted as a finding that the Coalition has no standing to make. Where something is inferred, the referral says so. Where something rests on testimony, the referral says whose and with what limitation. Where the Coalition cannot answer a question, it says that too, and identifies who can. The Coalition seeks no remedy, no payment, no acknowledgement and no outcome for itself or for any individual. It asks only that the questions set out in the referral be put to Valve Corporation by a body with the power to compel an answer. ================================================================================ CLOSING NOTE — TO WHOEVER IS CARRYING THIS FORWARD ================================================================================ We want to thank whoever gets this material to where it needs to go. It's probably not going to be a quick trip. Valve has deep pockets and Taylor Wessing charges by the hour — that combination is specifically designed to make people like you give up before they reach the finish line. We know what we're doing. We know who we're writing about. Valve built us — how could we not understand them? PhishDestroy has no conflict with Valve. We blocked the only scammer ring of that scale we've come across — we didn't go looking for a fight with Valve. It just turned out that every road led back to them. Not a conflict. Just topology. Valve cannot resolve the PhishDestroy situation because there is nothing to resolve. We have no relationship. The data about their enrichment schemes and overflow profits is largely public — you just had to spend enough time to see it. Think of it as a success encyclopedia: "How to Not Follow Sanctions So That Russian Hackers Can't Pirate Our Free Games (The Paid Ones They Won't Pirate Anyway)." You get the vibe. → We don't need authorship. → We don't need attribution. → We don't need a win. We need someone with actual authority to ask Valve the questions that are already sitting in this referral, with the power to require an answer. That's it. That's the whole ask. Cases will live at: https://steamdestroy.eth/ https://steamdestroy.eth.limo (currently broken — will fix when needed) We'll be at: https://phishdestroy.eth.limo/ https://phishdestroy.eth/ ================================================================================ PhishDestroy — public investigation — all rights surrendered to humanity OFAC-region access: prohibited ================================================================================ ## Why is the evidence hidden? When an inventory or profile becomes non-public after a restriction, what security purpose does that serve? Did the visibility policy change around 2020, and why hide the ledger instead of displaying a prominent public warning similar to a VAC notice? Demand: The policy history, internal rationale, access rules and appeal path. ## Why are bot pipelines not stopped at birth? Steam itself says malicious users commonly operate dummy accounts and uses a $5 threshold. What detects automated registration, phone and authenticator provisioning, funding at exactly the threshold, no game activity, long dormancy, then machine-like item flows? Demand: False-positive and false-negative rates—and whether bans occur before the account has value or only after valuable items arrive. ## Is “duplication” still a credible excuse? The duplication rationale dates back to restoration practices and support-abuse stories from the mid-2010s. A modern item has a unique record, a known transfer chain and trade holds. Why would revoking that same item from a proven illicit recipient and reassigning it to the verified prior holder create a copy? At what exact step does a second item appear in 2026? Demand: The policy history since 2014, a reproducible technical explanation and the number of actual restoration-caused duplicate incidents since 2019. ## Under what authority is the item immobilized? Does Valve treat a skin as property, a license, or merely a database entitlement? Which contract clause and legal theory allow permanent immobilization after theft while denying restitution to the verified prior holder? Property recovered from a thief does not become police revenue; why does the digital equivalent remain under the platform's exclusive control instead of returning to the victim? Demand: Notice, evidence disclosure, human review, appeal, time limits and the precise rule governing each item's final disposition. ## Who does the ban protect—and how much has Valve already earned? Valve's official FAQ lists a 5% Steam Transaction Fee plus a 10% game-specific fee for CS2 and Dota, paid by the buyer on Community Market sales. Steam Wallet proceeds cannot be withdrawn to a bank or transferred to another account. The defensible question is therefore not whether Valve receives the full nominal price again on every resale, but how much closed-loop money and cumulative fee revenue was attached to an item before it was locked—and how removing supply affects the scarcity and price of everything left. Demand: Lifetime fees collected on every item later frozen, victim-restitution and pre-loss intervention rates, and a model of the price effect of frozen supply. Do not count a ban without restitution as help to the victim. ## Does Valve defend a presumption of guilt? A skin restriction is not a prison sentence; the analogy tests the procedure. If Valve or its executives faced an unexplained penalty, undisclosed evidence and a nominal appeal answered with “read the law,” would its lawyers call that justice? Yet for high-value inventories Valve can appear to be accuser, adjudicator and custodian of the frozen value. What independent check addresses that conflict? Demand: The exact rule, alleged act, evidence summary, human reviewer, reasoned decision, independent escalation and disclosure of how frozen value is treated. ## Why is a meaningful appeal inaccessible? A boilerplate response and a broad link to the Steam Subscriber Agreement are not a finding of fact. Why can an ordinary consumer be denied the allegation and evidence, then face technical, legal and financial barriers that make challenging an automated or mistaken restriction impractical? Demand: Free human appeal, a plain-language decision, response deadlines, external dispute access, and statistics on automated bans, human reviews, reversals and repeat template replies. ## Community, recovery and the session Valve chose not to kill ## What is the “community” in Steam Community? After New York’s Attorney General sued Valve in February 2026, Valve published a Steam Support statement aimed at users and invoked effects on users and the public process. But when platform decisions affect those users’ valuable inventories, what formal power does this “community” have—votes, reasons, policy consultation, oversight or even visibility into report outcomes? Demand: Define the community’s governance rights and publish consultation records, report outcomes and an independent user-oversight mechanism—or admit that “community” is branding, not representation. ## Why does ordinary enforcement inherit VAC secrecy? Keeping anti-cheat detection signatures secret can protect a detection method. A community or trade restriction is different. What security risk prevents Valve from naming the rule, timestamp, alleged action and evidence category? How many user reports and bot reports lead to action, and what integrity controls cover staff, contractors and volunteers? Demand: Error and reversal rates, report-to-action statistics, independent integrity audits, conflict-of-interest rules and aggregate disciplinary outcomes. ## Is account recovery designed around evidence users are unlikely to retain? Steam says a retail CD key may establish ownership and recommends keeping it; it also says a verified phone gives additional recovery options. Why demand a decade-old physical key when Valve may hold payment, historical email and phone, device and login records? PhishDestroy internally estimates that 15–20% of claimants do not complete recovery after such a demand, although some still write from the longstanding provider and computer and control the email or phone. Valve can rebut that estimate by publishing its data. Demand: Attempts, approvals, rejections and abandoned procedures by evidence type; results for claimants retaining an email, phone or device; and an auditable explanation of signal weighting. ## Why punish the victim instead of revoking the hostile session? In the examined infrastructure, several consecutive Ihor IPs—including addresses ending .156, .157 and .158—each held 1,000+ active hijacked sessions while owners remained on known devices elsewhere. Those sessions could recreate API keys, wait, alter trades and read chat in parallel. The Steam Subscriber Agreement threatens account termination for IP proxying that disguises residence, including “for any other purpose.” Why does a server proxy holding a thousand unrelated accounts not trigger even a session revocation? Demand: Automatically revoke a hosting session, its API key and confirmations when it pools unrelated accounts at mass scale; then require clean reauthentication without restricting the victim. ## Seven years, 79 Steam staff and 1.16 million nominal hours: failure or business model? PhishDestroy can substantiate pools of 1,000+ sessions on one IP, consecutive addresses at one provider and separate stable IP slots for receiving bots. Yet the server-side pattern did not trigger the obvious response: revoke the hosting session, invalidate its API access and require clean authentication from the owner. Valve already enforces concurrent-use rules around game sessions. Why was equivalent risk logic not applied when a Russian hosting address sat between the owner and Steam while holding a thousand unrelated accounts? A 2021 organization snapshot accidentally exposed through the Wolfire antitrust litigation in 2024 reportedly listed 79 people in Valve's “Steam” category and $76,446,633 in aggregate gross pay—about $968,000 per listed employee as a category average, not an individual salary. That snapshot does not prove that 79 security engineers worked on offer swapping, that the headcount stayed constant, or that all employee time was available to this problem. It does establish the scale Valve must explain. ≈88 monthsPersistent mobile-session offer swapping from spring 2019 to this publication: roughly 2,700 days 79 peopleReported 2021 Steam-category snapshot—not a security-team count 1,162,880Illustrative capacity-hours: 79 × 14,720—not claimed fraud-investigation hours Parallel Session Trade Flow Security Response ## To: The Victims of Asset Theft and Valve's Deceptive Legal Team You have been trying to convince courts and players alike that item theft is solely the fault of 'stupid children' and that your platform's architecture bears no responsibility. Let us drop the corporate masks and explain, in the simplest terms, why your highly sophisticated, highly profitable phishing ecosystem exists solely due to Steam's architectural loopholes. Phishing is merely the act of stealing a key to a front door. But the fact that behind this door lies an completely unguarded vault controller—that is entirely the fault of Valve's developers. Let us examine some analogies for your security model to understand the sheer magnitude of this failure. ## 1. You are not GitHub (The Developer Fairytale) Valve justifies its insecure API by claiming that Steam is an 'open platform for developers.' Okay, let's compare you to GitHub. What happens when you try to generate a Personal Access Token (PAT) on GitHub? The system forces you to re-enter your password. It prompts you for a 2FA code. It obligates you to explicitly check off scope permissions (privilege separation) for the token. Crucially, it asks you to set an expiration date (TTL) for the token. And what does Steam do? It silently issues an infinite, omnipotent key with a single click, requiring zero confirmations, granting unrestricted read/write access to cancel and replace trade offers forever. You are not an open platform for developers; you are an open gate. ## 2. You are worse than sanctioned crypto-mixers (The Tornado Cash Syndrome) If Steam isn't a platform for developers, then perhaps it's a financial exchange? Let us compare you not to legitimate stock exchanges, but to the shadow crypto-mixers and sanctioned platforms that the US Treasury and the FBI dismantle for money laundering (such as Tornado Cash, Bitzlato, or Garantex). Do you want to know the ultimate irony, Gabe? Even illegal, sanctioned dark-web crypto laundries enforce better API security than Steam! Even the administrators of underground mixers understand that to generate an API key capable of managing user balances, they must force the user to input a 2FA code, confirm via email, and bind the key to specific IP addresses. Yet, Valve—a legal, multi-billion-dollar American corporation—allows an invisible script running on a server in Russia to gain permanent, confirmation-free access to user inventories worth tens of thousands of dollars in a single click. Do cybercriminals actually enforce higher security standards than your million-dollar salaried developers? ## 3. Grey markets proved smarter than a multi-billion dollar corporation The funniest part is the third-party skin gambling and trading marketplaces (like OPSkins or the old BitSkins) that Valve so aggressively targeted. Back in 2017, they faced the exact same API Offer-Swap substitution problem. And do you know what they did? They—a small group of independent developers without multi-billion dollar budgets—simply fixed it in days by adding confirmations, instantly breaking the scammers' schemes. Meanwhile, Valve spent 7 years conducting experiments on children, watching how long users would keep purchasing new skins to replace stolen ones, and how much illicit capital scammers could wash through this loop. ## 4. Brilliant crutches instead of actual fixes Instead of closing the vulnerability, Valve introduced 'brilliant' crutches. A 7-day trade hold. A 4-hour trade lock for changing your nickname. For 7 years, you treated an open fracture with a band-aid. A stolen knife was never returned to its victim; it was simply frozen forever on a banned bot, artificially reducing circulating supply and driving up market value. It was the perfect business cycle: scammers steal, Valve bans, supply drops, prices rise, and Gabe collects a lucrative transaction fee on every new sale. The main question Valve cannot answer: STEAM, WHY IN THE WORLD COULD YOU NOT JUST ADD A MANDATORY CONFIRMATION OR MOBILE PUSH IN STEAM GUARD TO GENERATE AN API KEY—AN OMNIPOTENT TOOL THAT CONTROLS THOUSANDS OF DOLLARS IN VIRTUAL ASSETS?! You force users to confirm the sale of a 3-cent trading card on their mobile app. Yet, for 7 years, you allowed an invisible script to gain permanent control over their entire inventory without a single notification. This is not 'phishing.' This is deliberate, calculated negligence, and your users paid the price. If Valve’s executive management subjected its security engineers to illegal cryogenic freezing experiments in the spring of 2017 and only woke them up today—we retract all our claims. That would explain everything. Science requires sacrifices (in this case, user inventories). But if your employees were fully conscious and receiving their paychecks over these 7 years, we have bad news. While your developers spent 1.16 million hours trying to secure API keys without implementing a simple Steam Guard confirmation, here is a brief excursion into what the rest of humanity managed to achieve while you were in stasis: Technological and Scientific Breakthroughs of Humanity (2017–2024): The AI Revolution: Humanity invented generative neural networks. OpenAI launched ChatGPT, which passed bar exams, learned to write complex code, diagnose diseases, and paint photorealistic art, completely transforming the global economy. Space Exploration: NASA successfully landed the Perseverance rover on Mars, flew the Ingenuity helicopter in the Martian atmosphere, and deployed the James Webb Space Telescope, looking back to the beginning of time. SpaceX mastered catching falling 50-meter rocket boosters out of mid-air with giant mechanical arms. Medicine: The world faced the COVID-19 pandemic. In record time, scientists sequenced the virus's genome, developed and tested revolutionary mRNA vaccines, and immunized billions of people to stop the pandemic. The Quantum Leap: Google and IBM officially achieved 'quantum supremacy,' building quantum computers capable of solving in seconds equations that would take classical supercomputers thousands of years. Hardware Revolutions: Apple abandoned the processor architecture it relied on for decades and designed its own high-performance M-series silicon from scratch. Meanwhile, Valve itself managed to design, manufacture, and release the innovative Steam Deck console. Steam Security Team 'Achievements' Over the Same 7 Years: Added a 7-day trade hold (failed to stop thefts). Spent 5 years thinking, then banned item trading for 4 hours after a nickname change (drawing laughter from scammers). Summary: In the time it took humanity to reach Mars, invent artificial intelligence, overcome a global pandemic, and build quantum computers, Valve—a multi-billion-dollar corporation—could not manage to add a single pop-up box with a 'Confirm in Mobile App' button to the dev/apikey page. Gentlemen from Valve, welcome to the future. Your cryogenic sleep is over. Humanity has leaped far ahead. Let's finally attach 2FA to your API so children stop losing millions of dollars due to your corporate laziness. Or should we wait another 7 years for Elon Musk to colonize Mars? ## The Steam API Cover-Up: How Valve Legalized Silent Espionage Valve has spent the last 7 years shifting the blame for the massive API trade substitution scam onto its users. Steam Support’s standard response dismisses victims by claiming they simply fell for phishing and compromised their own accounts. This is a calculated corporate lie. What Valve calls 'account theft' is, in reality, an uninterrupted, automated Man-in-the-Middle (MITM) surveillance operation facilitated by their own broken infrastructure. ## Account Theft vs. Silent MITM Espionage The Steam Terms of Service strictly forbid the use of automated scripts. Yet, Valve’s backend turns a blind eye when these exact scripts hijack user sessions. Standard Theft: A login from an unauthorized device triggers a Community Ban, locking the account and preserving the user's inventory. API Espionage: A malicious server establishes a parallel connection, monitoring the account in the background 24/7 without triggering any alerts or bans. The Interface Lie: During a trade, the Steam mobile app displays a legitimate transaction, forcing the user to authorize a trade that an invisible script cancels and replaces in milliseconds. ## The Phantom Agreement: How Steam Lies About Your 'Consent' Evidence ExhibitContract accepted silently by Russian proxy script within milliseconds Let’s talk about Steam Support’s favorite excuse when they refuse to return your stolen items: 'You are responsible for your account security and the actions taken on it.' They imply that you, the user, agreed to the terms that allowed this theft to happen. Really? You never saw this developer agreement page: https://steamcommunity.com/dev/apiterms. You never clicked 'Agree'. A hacker accepted this contract on your behalf, fractions of a second after authorizing into your account from a Russian IP address. So, we challenge any lawyer or Valve representative to show us exactly where in the Steam Subscriber Agreement it says: 'By using Steam, you consent to 24/7 background surveillance of your or your child's account by an automated server located in Russia.' In 90% of trade substitution cases, the victim doesn't even know what a Web API key is. They have never used one. Yet Valve has comfortably sat on their hands for 7 years, completely ignoring a solution that the community has been screaming about since day one: Just add a mandatory Steam Guard confirmation to generate the API key! ## Steam, Children Shouldn't Be Forced to Sponsor Hackers Imagine an ordinary teenager from Europe. They play games, save up for their favorite skins, and at some point, they make a mistake—they log into a phishing site. In a normal digital ecosystem, the protocol is simple: the account is automatically locked (Community Ban), passwords are reset, and access is safely restored. The kid realizes their mistake, but the system protects them from fatal consequences. But in Steam, everything works differently. Instead of blocking the suspicious activity, Valve silently opens a hidden door. A server from a sanctioned jurisdiction (Russia) gains parallel, unauthorized access to this kid's account. Without any secondary confirmation, without a single Steam Guard prompt, an alien script generates a Web API key. It accepts legal agreements on the user's behalf and begins monitoring their chats, trades, and inventory 24/7. A teenager from the EU never consented to hidden surveillance. They are not obligated to sponsor hackers from an OFAC-sanctioned territory just because a multi-billion-dollar corporation is too lazy to secure its own API. By keeping the stolen skins and refusing to restore them, Valve is covering up its infrastructural negligence, effectively legalizing the drain of European citizens' digital assets into sanctioned territories. ## Why Steam’s API & Token Security Violates the Law Steam allows third parties to generate API keys and hijack session tokens via MitM proxies without ANY user alerts or 2FA checks. This negligence directly violates major data protection and consumer laws: 🇪🇺 EU GDPR (Art. 25 & 32): Demands 'Security by Design' and adequate technical protection. Generating critical access keys without 2FA is a severe security failure. 🇺🇸 US FTC Act (Sec. 5): Punishes 'Unfair Practices' and lack of 'Reasonable Data Security.' The FTC routinely acts against platforms lacking MFA for critical account actions. ⚖️ EU Directive 2019/770: Digital services must meet baseline consumer security expectations. Steam’s 7-year-old API vulnerability fails this completely. 🛡️ NIS 2 Directive: Mandates strict cyber hygiene, including mandatory MFA for access management, which Valve ignores for API generation. Bottom line: When a platform hands over your API keys to a proxy session without a single alert or confirmation, it’s not just a flaw—it’s a major compliance violation. Does Valve retain session-level logs for authentication, API-key creation, offer cancellation and replacement, confirmations, IP history and support actions? If those records exist, could Valve prove when it first saw the Ihor pools and why it left them active? If they do not exist, why did a platform handling high-value inventories fail to preserve the audit trail required to investigate a known attack class? Across roughly 88 months, how many users—including minors where known—opened tickets specifically about offer replacement? How many tickets showed a foreign parallel session but received a scripted response instead of immediate revocation? How many cases resulted in prevention before loss, actual item restitution, or a receiving-bot ban attributable to that ticket or report rather than a later unrelated detection? PhishDestroy's review of public victim reports and Reddit discussions found no case that could be confidently tied to a victim's report; that is not proof that none exists, and Valve can correct the record by publishing its internal totals. The money question also requires exact accounting. For a CS2 or Dota Community Market sale in which a seller receives 100 units of Steam Wallet value, the buyer pays roughly 115 after the listed 5% Steam fee and 10% game fee, subject to rounding. The extra 15 is a fee; the seller's 100 is Wallet value, not another 100 of commission, so “115% profit” would be inaccurate. But if that item is later stolen and frozen without restitution, Valve still controls the closed-loop funds, has collected the fee and has removed the item from circulation. What are the aggregate buyer payments, Valve fees, Wallet liabilities, frozen-item value, price effects and restitution amounts for this attack class? Demand: Publish the actual security and support headcount by year; hours and budget assigned to offer-swap prevention; the full timeline of reports, decisions and missed mass pools; ticket-to-session-revocation, ticket-to-bot-ban and restitution rates; preserved request/action logs; and an audited comparison of Steam payroll and platform profit with user losses, fees collected, Wallet value and items frozen. Answer on the record: was this a staffing failure, a support-policy failure or a deliberate business choice? ## Outsourced support and privileged access ## Can an outsourced agent query any Steam user worldwide? Valve's Privacy Policy says third-party support providers may receive personal data only as necessary. PhishDestroy knows the field set and access model of the interface examined; Valve is asked to confirm or deny it on the record. Can a contractor agent in Ireland—or elsewhere—open a user in the US, Germany, Australia, China or Russia? Can they see current and historical email, phone, IP and device records, sessions, account changes, transactions or private chats? Is an assigned ticket required? Demand: A processor and subprocessor register, every processing country, a role-by-field access matrix, regional restrictions, ticket-scoped just-in-time access, and a clear answer on chat and historical identifiers. ## Does Valve know the human behind every privileged lookup? A contractor’s employee may have personal, political or governmental ties unknown to the user. What prevents an operator from being bribed, coerced or tasked by the FSB—or any other intelligence or law-enforcement body—to retrieve a person’s IP history, activity times, contacts or account changes? Does Valve identify each natural person, prohibit shared credentials, record every search and field view, detect access outside an assigned case, block bulk export and require all government demands to pass through Valve’s legal process? Demand: Individually attributable audit logs, hardware-bound authentication, anomaly alerts, periodic access reviews, log-retention periods, insider-abuse statistics, contractor-originated government-request totals, disciplinary outcomes and a public transparency report by country. Evidence recovery commitment ## Will Valve claim that the bots and victims can no longer be found? If Valve tells a hearing that its interface, security and support failed—or shifts the failure to an outsourcer—and then promises restitution, “we can no longer identify the bots or victims” cannot become the next excuse. PhishDestroy is prepared to submit preserved SteamIDs of receiving bots and associated trade and theft records from the principal product examined. Our current internal estimate is that matching this material against Valve's complete trade ledger could identify roughly 80% of classic offer-swap victims—not maFile, credential-phishing or RAT cases; exact coverage can be established only through reconciliation. Two other panels existed: one set of developers may now be difficult to locate, but other participants and researchers may be able to supply additional lists. If Valve tells Congress that large-scale frozen skin inventories have no effect on supply, scarcity, prices or platform revenue, while its internal data show otherwise, that would be a false statement to Congress. Assertions are not enough: require the underlying data and an independent impact model. Time matters. Offer swapping is losing relevance as Steam scams shift toward RAT payloads and fake VAC-ban lures delivered through files; the people behind the older products may disappear with the evidence. Independent verification path ## Anticipating the ‘trust’ excuse: the 213,000 offer-swap bot ledger We anticipate Valve’s standard defense: ‘We cannot blindly trust a list of victims provided by a third party.’ We respect that skepticism. That is why we are not offering a list of victims. We are offering a verifiable list of the receiving bots used by the classic offer-swap panels. We have the means to secure databases covering approximately 80% of historical classic API offer-swap volume—the mechanism that cancelled a legitimate trade offer and sent a replacement—if Valve genuinely commits to restitution rather than PR damage control. This estimate does not cover maFile theft, ordinary credential phishing, RAT payloads or other scam types: those flows could use limited or concealed bots and cannot be reconstructed with the same confidence. We can ask the scam-panel authors directly. They are accessible coders: we can contact at least one immediately and have a path to the other. The objective is not a witch hunt against individual developers, but to force Steam to correct a seven-year systemic failure. Compared with Valve’s corporate silence, the panel developers have at times shown more humanity and transparency. ≈213,000‘Unlimited’ receiving and liquidation bot accounts · classic offer-swap only · PhishDestroy internal estimate · some already bannedBot IDs supplied → Valve verifies inside its own ledger → victims and items Even if the authors refuse to share their logs, we possess alternative forensic methods for identifying bot networks deployed exclusively for this specific offer-cancellation and replacement mechanism. Under that exclusive-use criterion, every incoming trade to a verified panel receiving bot is a documented theft. No one is asking Valve to hand its internal logs to PhishDestroy. We will provide SteamIDs or account logins for bots used only to receive and liquidate items stolen through offer replacement; Valve can keep its ledger inside its own environment and perform the match itself. Many of these bots successfully sold stolen items, some are already banned, and the volume of incoming trades is enormous. The verification evidence is Valve’s own: bot-only account behavior, the timing of a legitimate offer being cancelled and a replacement being sent, incoming-item and liquidation history, the documented Ihor infrastructure, and confirmation from affected users. For an account verified as an exclusive offer-swap receiving bot, every incoming trade in its operating period is a theft record—not normal player activity. Direct question to Valve: Do bot-operated receiving and automated liquidation of stolen skins violate the Steam Subscriber Agreement and platform rules—or only when enforcement is convenient for Valve? Is organized skin theft commercial activity, or does that definition also change when convenient? Valve does not need to trust our victim assessment. It only needs to cross-reference the estimated 213,000 bot identifiers with its own ledger and independently verify their function. Once verified, identifying victims and restoring items is a database query. We will do everything in our power to deliver the list. The only missing element is Valve’s willingness to act. PhishDestroy commitment: If Valve genuinely begins restitution, we will make every possible effort to obtain, preserve and securely deliver the available lists. Demand to Valve: preserve internal logs now without handing them to us, open a protected channel for bot identifiers, and reconcile SteamIDs and trades inside its own ledger, notify identified victims and publish the number of restored items. Real money has already entered Steam's closed loop, and Valve collected fees as the item circulated. If its history remains fully traceable, the prior holder is known, and Valve then freezes it permanently while refusing restitution and hiding the inventory, the question is unavoidable: why should the public see that as protection rather than monetization of the platform's own vulnerability? A ban that leaves the victim empty-handed is not restitution. Editorial illustration · the practical ownership modelFees collected. Item locked. What does the legitimate holder receive? Is this investigation biased toward scammers? No. Our positioning remains strictly anti-scam. However, the technical evidence compels us to recognize: Valve's systemic negligence represents a far more serious threat to ecosystem security than the individual actors exploiting its vulnerabilities. It is simple: our activities are fundamentally opposed to the interests of Steam scammers. PhishDestroy aims to detect and dismantle their infrastructure, whereas their goal is the theft of user assets. But to counter them effectively, we must objectively assess the technical level of our adversaries. Our confrontation has lasted since 2018, and the very necessity of an independent cybersecurity group like PhishDestroy is a direct symptom of the systemic crisis in Valve's protective model. Our experience demonstrates that the depth of understanding of fraud schemes—from the localization of phishing templates to specific language segments, to the exploitation of vulnerabilities in the Steam client's invite system—is exponentially higher among independent researchers than among Valve's security engineers, who have ignored these issues for years. The Steam platform has evolved into an unregulated sandbox for testing advanced cybercrime methods. Complete lack of oversight and massive volumes of gray capital have bred highly sophisticated criminal syndicates. The technical level of their solutions is remarkably high: from advanced evasion schemes to high-budget Google Ads phishing using original domains. They perfected their methods on the banking sector long before the emergence of crypto drainers (evidence: wheregoes.com/trace/20235852868/, wheregoes.com/trace/20235945432/). What regarding the API Offer Swap scheme (which is currently largely neutralized): prior to PhishDestroy's emergence, scammers safely renewed their domains for years and manipulated reputation on ScamAdviser, as we were the sole force implementing automated phishing detection and blocking. We repeatedly attempted to establish a channel of communication with Steam Support, similar to our cooperation with Google on Google Ads. Throughout our research of report logic and processing, we gained substantial experience. It was obvious that Steam does not protect its trademark at all: phishing sites directly pulled (and continue to pull) styles, images, and interface elements directly from Steam's official servers. In current phishing designs utilizing authorization, CDN server calls are clearly visible in network requests (analysis of requests: urlscan.io/result/...). Valve possesses all necessary telemetry and metrics but completely lacks the willpower to take real action against fraud. All of their security measures were reactive, forced steps under pressure from external regulators. The narrative of "community help" like SteamRep is a myth: administrators of such projects were themselves implicated in blackmail, skin theft, and paid unbans for scammers. Steam's volunteer movement is minimal—with rare exceptions of enthusiasts like moderator Colt from Belarus. If we are cleaning the platform of scammers, why should we have to beg Valve to block them? Instead, support could reject our reports or even suggest banning our own account for submitting lists of malicious domains. Steam as a business does not suffer from the presence of scammers on the platform—its economic model and ultra-low financial barrier to entry actively encourage their proliferation. Tolerance of bot farms, card farming, case farming, and the gray resale market led to the complete destruction of classic peer-to-peer trading by 2018. The platform has turned into a commercial marketplace where transactions are conducted in USDT via third-party sites, directly contradicting Steam's nominal Terms of Service (TOS), which Valve ignores as long as it remains profitable. Valve's ban logic is completely opaque. The company performatively blocks empty, inactive accounts, but ignores massive automated bot networks servicing farming (for example, the Archiasf group alone has 5,337,718 bot accounts: steamcommunity.com/groups/archiasf). Valve's TOS is drafted in such a manner that absolutely any active participant in the skin economy is technically in violation. This grants the company unlimited authority to seize assets or delete accounts without due process. At the same time, reports against major scammers impersonating famous content creators are ignored for years despite mass reports. On the Steam platform, Valve itself represents a far larger and more cynical scam than regular fraudsters. Users are completely defenseless, there are no mechanisms to hold scammers accountable, and all digital assets and accounts belong exclusively to the company, which is unaccountable to anyone. The platform is overrun with spam bots and playtime-boosting networks. Toxicity, profanity, phishing, and illicit trade coexist freely. But the ultimate evil is Valve itself, which raised an entire generation of cybercriminals by demonstrating impunity and complete apathy toward victims. Desperate children, faced with support's refusal to return items, were recruited by scammers into fraud schemes. This was not an isolated incident—it was a systemic practice. Regional pricing policies also show deep inconsistencies: the price of a single game can cost $100 in the US and $20 in regional markets. Support attitude is similarly segregated—in our experience, only the Japanese support division exhibits a professional, adequate, and responsible approach to user security. Therefore, yes, I assert: the offer-swap scammers are the lesser evil compared to Steam itself. For 88 months, the platform has failed to detect an anomalous, endless parallel session, run not through secret proxies, but through the simplest server-side IPs where one server holds 1000 sessions simultaneously. Thank you, Steam, for forcing us to exist, and extremely no thank you for building this industry of deceit. If Steam were not a suffocating global monopoly, any competitive market would have destroyed such negligent management in its infancy. Even the dark web does not harbor as much toxicity and filth as Valve's ecosystem, but due to the lack of alternatives, Valve enjoys absolute impunity. Steam deserves severe legal accountability for aiding and abetting cybercrime. Sophisticated phishing and authorization hijacking are direct consequences of flaws in Steam's architecture. It is not that users are "stupid," but that you, Steam, are incapable of terminating parallel sessions when security credentials change. Scammers use highly sophisticated phishing in tandem with Steam's interface—the very interface in whose defects the company cynically blames the victims. I state with full responsibility: this is the most sophisticated phishing from a logical standpoint. No other financial or crypto platform would have allowed such a vulnerability to exist—they would have eliminated it long before it could scale to such proportions. Steam carefully hides its algorithms. I am ready to engage in an open discussion under NDA with any Valve security engineer to prove: the current situation is either absolute incompetence or conscious financial interest. Steam is the root cause of fraud on Steam. The company never fought it independently. Steam is a disgrace and an anti-example. Valve cynically intimidates children with a TOS written in legal jargon purely to protect the corporation, resulting in over 70% of children not even contacting support when their items are stolen, knowing they will receive a harsh, templated rejection. Valve has simply forgotten its limits, assuming that a private corporation is permitted to do absolutely anything. Do not stay silent. Speak up. Why didn't we publish this sooner? We have had parts of this investigation written since 2022. We knew the mechanisms inside out. But why wait? Because we watched as Valve and its high-priced legal representatives continuously buried reports, issued aggressive takedowns, and hid under the excuse of "ongoing security investigations" rather than implementing simple fixes. Reddit users have been begging since Month One to require SMS verification for API generation or to disable API access completely for ordinary users (who do not need it at all—it is only used by Steam, third-party commercial portals, and scammers). Yet, Valve chose to blame children for falling victim to MitM proxies rather than doing the logical, simple thing. It shouldn't take over a million developer hours to solve what was suggestion number one on public forums years ago. Support Ethics, Whitelist Bribes, and Lolzteam Integration Our whistleblower, Source 1, is not a random player. They hold a Steamworks account—complete with paid developer registration fees and identity verification (KYC). When they escalated security issues, Valve claimed "no logs exist" of who accessed what. But we know the truth: Steam's support is outsourced to low-paid third-party contractors who have zero interest in user security. More alarmingly, our upcoming reports will expose how deep the corruption goes, including specific employee accounts (such as worker "al") receiving kickbacks to unban gambling bots and whitelist scam pipelines. Under Steam's nose, networks like Lolzteam have actively traded and liquidated over 70 million stolen accounts while API access remains unrevoked. Why does Valve fear mass API revocations? Are they worried gambling sites won't register deposits, or that their own gray economies will collapse? Infinite Sessions vs. License Protection If a user tries to launch two separate game sessions on different devices, Steam's client immediately logs them out with an ID ticket error. Yet, Valve allows an active parallel web session on a server in Russia (such as Ihor) to remain active for six months, silently reading a user's chats, inventory, and waiting for the right moment. The scammer waits for the child to buy a high-value skin, then displays a fake "VAC ban pending" notification. They message them from a hijacked friend's profile, claiming to be a moderator, and scare them into transferring items to a "friend" or "smurf" account to "save" them. Because the parallel session is alive and monitoring, the scammer's API script intercepts and swaps the offer in milliseconds. If Steam terminated concurrent sessions across different IPs, these attacks would be completely impossible. The Locked Wealth of Banned Inventories We demand that global financial regulators audit the volume of banned inventories currently withheld by Valve. When a bot is banned, the stolen items are not returned to the children; they are permanently locked inside Valve's databases. This closed-loop system artificially reduces the circulating skin supply, raising market prices, and directly increasing Valve's transaction fees on every subsequent market sale. These locked inventories have real monetary liquidity. Valve plays a cynical game where they act as the court, the jury, and the sovereign bank, avoiding millions in taxes on locked liquidity under the guise of "temporary restrictions" that are functionally permanent. It is time for a full accounting of locked skins since 2019 across Team Fortress, Dota 2, and CS2. Editorial note: The operational Ihor claims are based on PhishDestroy's preserved data and files from one examined product and can be submitted for independent review. Aggregate totals, selective enforcement and economic motive require Valve's records. References to Ireland, Russia, the FSB or another state describe a threat model; they do not accuse a named contractor or operator of disclosure without evidence. The 79-person and $76.4 million figures are reported from a court-filed 2021 category table exposed before corrected redaction. The 1,162,880-hour figure is an illustrative staffing-capacity calculation—not a claim that 79 people were security engineers or spent those hours on this fraud. ## Author & Editorial Expertise Prepared by the PhishDestroy Research Team, an independent collective of cybersecurity threat analysts, blockchain forensic researchers, and OSINT specialists. Our team members hold extensive credentials in tracing data exfiltration, reverse-engineering malware, and auditing malicious infrastructure since 2018. Review our verified investigations in our News & Investigations Archive or check our commitment to transparency in our Editorial Policy. ## Contact & Registry Office To submit reports, request corrections, or escalate threats, visit our Contact Desk or submit a formal ticket via our Appeals Center. PhishDestroy Association Virtual Registry & Decarbonized Operations Mailbox: 10685-B Hazelhurst Dr, Houston, TX 77043, USA ## Transparency & YMYL Disclaimer Disclaimer: PhishDestroy is a non-commercial, independent threat intelligence project. The research on this page is for educational, security analysis, and public threat-awareness purposes only. It does not constitute legal, financial, investment, or professional security advice. Always perform your own independent diligence and consult licensed professionals before interacting with digital assets, authorization APIs, or third-party platforms. # Steam Shadow Economy: Pricing, Scams and GDPR Published: 2026-08-12 · Category: Investigation · Words: 3,919 Mirror: https://valve-xmr-5kus.4everland.app/articles/steam-shadow-economy.html Original: https://phishdestroy.io/steam-shadow-economy −53%Terraria: Russia vs US list price 15%Community Market commission cited 29 Jul–1 AugCEVA attack window Article 15GDPR access right Investigation in brief ## What does this report allege? This independent investigation strips away the curated, consumer-friendly facade of Valve Corporation. We reject the obfuscated, defensive corporate rhetoric designed to mask systemic compliance failures, user exploitation, and internal misconduct. Supported by public records, legal filings, and direct technical analysis, this report exposes Steam's transformation into an unregulated, highly lucrative digital shadow economy built on the following facts: A Platform for Crime:Steam's untaxed in-game skin market operates as a ubiquitous darknet money laundering machine, with a shadow turnover estimated between $1 billion and $4 billion in 2025 alone. The Skin Ban Hoard:Valve systematically refuses to return stolen items or accounts to fraud victims; instead, they permanently freeze banned inventories, effectively hoarding stolen digital assets within their own ecosystem to boost skin rarity and drive up their 15% transaction fee revenue. Legal Intimidation:Valve retaliates against users seeking legal aid. Their Subscriber Agreement historically stated that appealing to independent legal protection or filing a class-action lawsuit would result in Valve deleting the user's account and erasing their entire library. Sovereign Priorities:Valve respects exactly one US court in Washington and any state censorship agency in Russia, submitting fully to Russian courts in their Terms of Service. The Outsourced Cartel:Steam's Russian-speaking outsourced support has been repeatedly linked to mass account theft and inventory draining—corrupt precedents that Valve has openly acknowledged yet refuses to stop due to high outsource profit margins. Censorship Compliance:Steam submissively obeys Roskomnadzor, deleting pages, games, and user materials immediately upon Russian state command. VPN Hypocrisy:Steam operates under deep double standards and outright lies regarding VPN bans, which directly contradicts official ISP routing statistics. GDPR Stonewalling:Valve and Taylor Wessing use aggressive legal threats, delays, and incompetent PDF redactions to stall and avoid complying with users' Article 15 and 77 GDPR rights. Russian Support Access:Russian-based outsourced contractors hold unfettered global access to every Steam account—including support tickets, funding details, and IP addresses—and actively leak or sell this data to fourth-party darknet actors. Taylor Wessing Misconduct:We refuse to write in the polite, obfuscated corporate style of Taylor Wessing—as their own firm's history of high-profile sexual harassment lawsuits shows that such "polite" games only serve to cover up systemic abuse and internal failures. Satire / Joke Harassment Encouraged:Steam actively tolerates, encourages, and shields online harassment, stalking, and xenophobic abuse, prioritizing and protecting toxic users from the Russian Federation over the safety of European and international victims. Outsource Global Leaks:Steam's Russian support outsource cartel has full, unfettered global access to all account data—including tickets, IP logs, and billing details—actively leaking and selling this global private database to fourth-party darknet actors. Evidence boundary. Public claims are linked to sources where available. Statements based on confidential or first-hand information remain attributed to our team; they are not court findings. All editorial images are illustrative, not evidence. Article 77 GDPR complaint tool ## Turn the breach notification into a documented EU complaint. Choose any of the 27 EU Member States to see the competent authority, published contact details, postal address, official complaint channel and country-specific filing rules. The builder prepares an editable complaint in the selected country’s language and a professionally styled PDF based on the EDPB’s common complaint structure. Use the email address that received the notification where possible or enter it as your complaint contact. Attach the original notice as an .eml file with full headers; if the portal rejects .eml, attach a PDF showing the sender, recipient, date and complete message. This helps prove that your data were involved, but using the same address is not a legal condition of Article 77. 27EU Member States 24official EU languages Runs locally in your browser. Nothing is uploaded. An Exclusive Investigative Report by Our Team Our project did not come into existence because times were good. Our existence is not a testament to Steam’s success, but a critical necessity born out of Valve’s absolute disregard for user security. In fact, our fight against phishing directly interfered with Valve’s business model, disrupting their carefully crafted economy of account bans and item resales. (We will release a separate, detailed piece exposing the company's true "values" and their parody of cybersecurity at a later date). For over a decade, Valve Corporation has hidden behind a curated, consumer-friendly facade. But beneath the surface lies a cynical corporate machine. Through an extensive internal investigation, our team has deconstructed the policies that Valve prefers to keep quiet. This is the anatomy of a platform that acts as an unregulated financial syndicate, appeases sanctioned states, shelters compromised outsourced support, and treats European laws as optional suggestions. ## 1. The Sanctions Farce and Pro-Russian Bias For Valve, users in the EU and the US are nothing more than cash cows. While European gamers pay full price, Steam continues to provide aggressive discounts of 70% to 80% for the Russian market. A game in Russia costs a fraction of what it costs in Germany. This is what international "sanctions" look like in Valve's dictionary. The platform does everything to appease and popularize this vector: they facilitate region swapping, turn a blind eye to money laundering via in-game items, and explicitly state in their Terms of Service that they submit to the jurisdiction of any Russian court. It reaches the point of absurdity: on the rare occasions when Steam servers experience massive outages, the first entity to officially comment on the technical failures is often Roskomnadzor (the Russian federal censorship agency). ## 2. The Outsourced Support Cartel The myth of a "strict, secure American technical support" collapses the moment you realize who holds the keys to Steam’s backend. Valve has delegated support in the CIS region to a deeply compromised, corrupt outsourced network staffed by Russian contractors who actively abuse their access privileges to rob users. We have successfully deanonymized segments of this network. A key figure managing or curating this support branch is an individual named Nikita. Our investigation revealed that this individual (or at the very least, his primary email) is registered and active as a user on underground hacking forums like Lolzteam (Zelenka)—a notorious darknet hub entirely dedicated to the sale of stolen credit cards, compromised databases, and brute-force logs. Think about that: a person with global access to Steam Support databases is casually hanging out on a forum designed for identity thieves. This outsourced Russian support cartel has repeatedly stolen or handed over private user details to fourth-party scammers in order to brute-force accounts, reset credentials, restore access to dormant profiles, and hijack valuable digital inventories for underground market profit. Valve is fully aware of this systemic corruption and has previously acknowledged precedents where outsourced staff systematically drained high-value user inventories. Yet, maintaining this cheap, unaccountable, and corrupt outsourced workforce is far more profitable to Valve than hiring qualified, in-house cybersecurity professionals. To Gabe Newell, your security and digital property are minor costs compared to the savings gained by outsourcing backend access to bad actors. Editorial illustrationThe report alleges that outsourced support access can become an insider-risk channel.This image is illustrative and is not documentary evidence. ## 3. Scamming as a Business Model and Offshore Currency Steam’s in-game skins have become a ubiquitous, untraceable currency across the darknet—a financial laundromat that bypasses international regulators and tax authorities. To Valve’s financial department, scammers are not a threat; they are external agents stimulating market velocity. The traditional model of "one user, one game" brings in limited revenue. However, a compromised ecosystem creates a highly profitable loop: a user is hacked, the items are stolen, the scammer's accounts receive a "Trade Ban," and the victim is forced to create a new profile and rebuy their assets. When Valve bans a scammer, they do not return the stolen assets to the rightful owner. They freeze them permanently, effectively hoarding stolen goods inside their own ecosystem. This creates artificial scarcity. Decreasing the market supply drives up the prices of the remaining items, which in turn multiplies Valve’s 15% commission on the Community Market. To keep this highly lucrative operation quiet, since 2024 Valve has actively sent legal threats and cease-and-desist letters to third-party databases and inventory-tracking websites. By forcing these tracking platforms to stop listing banned inventories, Valve successfully conceals the exact statistics and multi-billion-dollar valuation of the frozen assets they profit from, ensuring the public remains blind to the scale of their hoarded loot. Editorial illustrationThe item-theft and trading loop described in this section can generate fees even while victims lose access.This image is illustrative and is not documentary evidence. ## 4. The CEVA Logistics Breach: Undeniable Proof of Negligence If you believe Valve at least protects your physical, real-world data, the recent incident regarding CEVA Logistics proves otherwise. Between July 29 and August 1, 2026, hackers breached Valve's European hardware logistics partner. Valve only acknowledged the breach on August 7, leaving users' data in the hands of malicious actors for a week. The leaked data includes real names, full residential addresses, phone numbers, and Steam-linked email addresses of European customers who ordered physical hardware. Valve tries to pacify users by stating that "passwords and payment data" were not leaked. But a Full Name, Home Address, Phone Number, and Steam Email is the exact blueprint required for devastatingly effective spear-phishing and account hijacking—a goldmine for the very outsourced staff and scam networks mentioned above. Valve essentially handed your data to them. ## 5. Call to Action: The European Stand Against Corporate Immunity Every gamer in Europe needs to wake up to a harsh reality: you are paying 5 times more for games than users in Russia, yet your European rights and laws (GDPR) are completely silenced. Your personal data leaks to third-party contractors, and your support tickets are handled by a CIS outsource network with a highly questionable reputation. We send our fiercest, most sarcastic greeting to the highly paid corporate lawyers at Taylor Wessing, who defend Valve’s lawless monopoly. Their technical incompetence is a public hazard. In a documented GDPR case, when Valve was forced to release personal data logs, these expensive attorneys redacted the documents by simply slapping a black overlay on the PDF. Underneath that easily removable black box sat fully visible, unencrypted personal data, including sensitive information of EU and Russian minors. Instead of warning the victims, Valve and Taylor Wessing quietly covered up the breach, leaving children exposed to potential danger while transmitting highly sensitive legal documents without basic encryption. If "elite" European lawyers cannot even handle a PDF securely, you can only imagine the absolute anarchy inside Steam’s outsourced Russian support centers. This lawless behavior cannot continue. A platform that actively accommodates a state-sponsor of terrorism, facilitates sanction bypasses, and prioritizes corporate wealth over basic child safety does not get to hide behind empty apologies. They must be held accountable in every single jurisdiction they exploit. Here is what you must do right now: File a GDPR Complaint: Go to your national Data Protection Authority (DPA)—whether it's the CNIL in France, BfDI in Germany, or the AP in the Netherlands—and file an official complaint regarding the CEVA Logistics breach. Valve is the Data Controller; they are legally responsible for this leak. Demand Your Logs: Send a formal Subject Access Request (SAR) under GDPR Article 15 to privacy@valvesoftware.com. Demand a full log of every outsourced employee and third-party contractor who had access to your personal data and account over the last 12 months. Editorial illustrationEU users can document a complaint and request access information under the GDPR.This image is illustrative and is not legal advice or documentary evidence. If they refuse, claim they don't keep logs, or hide behind a corporate NDA to protect their outsource staff, forward that refusal directly to your DPA. Mass legal action is the only language this monopoly understands. ## Author’s Addendum: The Market Behind the Platform On the Steam platform, recommended regional prices for Russia (and the CIS region as a whole) are typically 40–60% lower than the base US dollar price. Russia is classified as a Tier 2: Emerging Market, which generally receives a 40–50% discount off the base price. For example, a standard indie game priced at $19.99 (which would be around 1,900 rubles upon direct conversion) should cost around 419–499 rubles according to Valve's recommendations. ## Terraria: the same game, a 191% price spread. Current regional list prices #1 cheapest🇷🇺$4.66Russia≈ ₽385−53% vs US #2 cheapest🇺🇦$5.01Ukraine≈ 225₴−50% vs US #3 cheapest🇮🇳$5.03India≈ ₹480−50% vs US #1 expensive🇨🇭$13.55Switzerland≈ CHF 10.99+36% vs US #2 expensive🇬🇧$11.48United Kingdom≈ £8.50+15% vs US #3 expensive🇩🇪$11.25Germany≈ €9.75+13% vs US ## Terraria price relative to the United States US list price = 100%. Every bar represents the same game on Steam. Russia $4.66 · 47% India $5.03 · 50% United States $9.99 · 100% Germany $11.25 · 113% United Kingdom $11.48 · 115% Switzerland $13.55 · 136% Snapshot and local-currency equivalents: OpenTheRank — Terraria regional Steam pricing. Taxes shown by the source are included where applicable. ## Sticker price vs local purchasing power A low dollar price can still be expensive locally. Hollow dot = list price. Filled dot = PPP-adjusted cost. Scale: $0–$25. List pricePPP-adjusted cost $0$5$10$15$20$25 India +134% Russia +4% United States 0% Germany +6% United Kingdom −1% Switzerland +23% PPP-adjusted values and mismatch percentages: OpenTheRank’s Terraria purchasing-power comparison. Values are rounded as displayed by the source. It needs to be stated clearly that the outsourced support is located in Ireland, but it is staffed by Russians—and some of the staff are based directly in Russia. Oh, and by the way, CSGOFast owns the popular SteamInventoryHelper extension, which is used purely to advertise their child-targeted casino (a casino that is banned in several European countries). And who owns this casino? That's right, Russians, just like the majority of similar sites. Does Steam not know this? Or do they just not want to know, considering the shadow market turnover is around a billion dollars, I believe. Furthermore, I estimate that 40% of CIS scammers who currently run crypto scams got their start on Steam. I personally know of at least two specific cases of money laundering through skins. I won't detail them here, but I can if needed—just not publicly, as I don't want to name the platforms, etc. But Steam is well aware of this. Or do they actually expect us to believe that players who don't even own the game are just buying the exact same item over and over just to "play" with it? Yeah, right, it's a joke. Steam's priorities are as pro-Russian as it gets—both in pricing and legal terms, as well as in popularizing Putin, flags, and banned terrorists. But Steam seems to like that, just as they tolerate antisemitism, discrimination, harassment, stalking, and drug dealing. For Steam, this is perfectly fine, just like 18+ games. They apparently enjoy it. This is not a short-lived policy dispute. Russian officials and industry working groups have spent well over a year developing a videogame-control regime that includes player identification through a Russian telephone number, the state Gosuslugi identity portal or the state biometric system. Steam and GOG were expressly named among the platforms the proposal could affect, and participants said the underlying government working group had already been meeting for almost a year and a half by December 2024. Valve has made no comparable public commitment that it would leave the Russian market rather than connect its users to this state-directed identity architecture. The contrast is obscene. Major industry players suspended sales or services in Russia—Microsoft halted all new sales, while console platforms and publishers announced their own withdrawals—yet Steam chose continuity. It continues providing commercial and social infrastructure to a country that the European Parliament formally recognised as a state sponsor of terrorism and a state that uses means of terrorism. That support is visible inside Valve’s own economy. The official Steam Community Market lists a purchasable “Putin & Trump” profile background and thousands of items named “Putin forever,” “Putin smile,” “Putin like” and “Putin angry”. Valve did not draw these images, but it distributes, lists and monetises them through a Valve-operated marketplace. At the same time, in cases we documented, harassment based on nationality is allowed to remain visible or is treated as ordinary community conflict. Steam’s message is unmistakable: political propaganda can be monetised, while the people targeted by national-origin abuse are left to absorb it. ## Private Ownership Is Not Legal Immunity Valve is privately held and its shares are not publicly traded. That means its ownership structure, investors, internal controls and financial incentives receive far less routine public scrutiny than those of a listed company. It does not mean that consumer-protection law, child-safety duties, data-protection law or national regulators cease to exist. If Gabe Newell aggressively defends the right to sell explicit adult and hentai games on the same platform frequented by minors, yet hires expensive lawyers at Taylor Wessing specifically to stonewall basic GDPR transparency requests, it exposes a grotesque distortion of priorities. Perhaps Valve’s executive leadership is comfortable shielding attorneys whose main public notoriety stems from a high-profile sexual harassment lawsuit against their own firm, but EU regulators and data protection authorities will not be so easily intimidated. If Newell and his highly paid legal proxies prefer playing cozy corporate games instead of protecting kids and complying with international law, they are about to face a harsh legal reckoning. Satire / Joke Valve’s own Subscriber Agreement says Steam is not intended for children under 13, yet Newell’s legal department has spent years aggressively rewriting these terms to extort and intimidate the teenagers who dominate the platform. For a long time, the agreement explicitly contained a vindictive retaliation clause: it stated that if a user sought any independent legal aid, went to court, or filed a class-action lawsuit against Steam, Valve reserved the right to retaliate by instantly deleting their Steam account, destroying their digital items, and wiping out their entire virtual library. By isolating users and forcing them under the exclusive jurisdiction of the US District Court for the Western District of Washington, Valve created an environment of legal terror designed to scare minors away from asserting their basic legal rights. A self-declared date of birth, a warning page and preference filters are not meaningful age assurance; they are cosmetic gates designed to let Valve exploit children under coercive, lawless contract terms. Rights holders should also explain why they accept this adjacency. A family game, a children’s title or a mainstream release can sit one recommendation or search result away from explicit material, while Valve collects money from both. Publishers spend fortunes protecting their brands, yet appear willing to ignore what surrounds those brands inside Steam. Private ownership does not make this responsible, and market dominance does not make it inevitable. Valve’s moderation principles become even harder to defend when compared with its response to Russian state censorship. In 2024, Roskomnadzor announced that Steam had removed all material demanded by the agency and that 11 Steam URLs would consequently be removed from Russia’s prohibited-information register. In 2025, Steam removed material from the page of an adults-only game after another Roskomnadzor demand concerning so-called LGBT “propaganda.” That was political censorship applied even to an 18+ work, not protection of a child who had bypassed an age gate. Valve can comply with a Russian censorship list, yet somehow remains helpless when asked to protect users from national-origin abuse, illegal gambling funnels or predatory adult-content exposure. That is a choice of priorities, and it raises an obvious freedom-of-expression question. Valve has also issued no public corporate response to Russia’s invasion of Ukraine comparable to the companies that suspended operations or openly supported Ukraine. Its private capital structure does not require the kind of investor disclosure expected from a public company, so outsiders cannot fully examine whose incentives are being protected. What remains visible is an extraordinary attachment to a lower-priced market associated with industrial-scale cheating, gambling, account theft and sanctions-evasion services. Perhaps the reason will become clearer if Steam ever agrees to a Gosuslugi identity connection. The outsourcing story follows the same pattern of opacity. Valve contracts companies, not the individual support workers presented to users. According to a primary source and materials we reviewed, a person connected to the earlier high-value inventory theft scandal did not disappear from the small support-contractor ecosystem: he moved to a different agency. He later claimed that he was not working for Steam and did not know the account was connected to Steam. Yet the trail led back to Ireland, to the same person and to Steam again. This account should be investigated as an outsourcing and access-control failure; it is not presented here as a criminal judgment. Valve should disclose which agencies can access account systems, how personnel are re-screened when they move between vendors, and whether an individual removed from one contractor can simply reappear through another. Vietnam already demonstrated that Valve’s private-company status does not place it above national law. Steam was blocked there after authorities said Valve had failed to cooperate. Vietnam exists. EU law exists. Every jurisdiction Valve monetises exists, even when Valve behaves as if only “any court in Russia” matters. And if the theory is that Steam may operate wherever it wants, under whatever hidden arrangements it wants, with no meaningful accountability, perhaps we should ask the absurd question directly: is there also a special Steam for North Korea that nobody has disclosed yet? These are established facts: the support team is Russian, and this support has repeatedly stolen or handed over information to fourth parties to restore access to dormant accounts in order to hijack them for profit. If Valve believes that offering deep Russian discounts and monetizing terrorist propaganda is just a geopolitical policy, and if their incompetent lawyers can only intimidate, threaten, and leak minors’ data while stalling GDPR requests, then they can take their week-long delayed apologies and shove them. We do not need Valve’s permission, Taylor Wessing’s threats, or three-week delays to hold a corporation that loves Russia and despises European rights fully accountable. Steam has spent years deceiving and coercing its users into lawless terms. We call on every affected citizen to stand up, know your rights, and refuse to be manipulated. And to the hackers who exposed the security vulnerabilities of Steam’s porous logistics partner: since Valve has systematically failed to protect or notify its own victims in a timely manner, we would be glad if you used this report to directly notify the leaked users of their compromised data. Let them demand their lawful GDPR Article 77 rights, rather than absorbing the deceptive games of a greedy, manipulative monopoly. PhishDestroy will continue to monitor, investigate, and expose. The shadow economy will be brought to light. Given the direct conflict of interest and the adversarial legal posture of Valve's representatives, Taylor Wessing, direct coordination through them to reach the data breach victims is not feasible. This independent public report serves as the primary instrument of disclosure for the affected EU citizens whom Valve and its partners failed to safeguard. Back to News & Investigations # Profit Over Players: The BlockBlasters Cover-Up Published: 2025-10-18 · Category: Malware on Steam · Words: 1,677 Mirror: https://valve-xmr-5kus.4everland.app/articles/steam-not-good-guy.html Original: https://phishdestroy.io/steam-not-good-guy Steam Not Good Guy Investigation Investigation Corruption Listen to this article 0:00 / --:-- Download as PDF — Official Report We are launching a multi-part investigation uncovering the hidden truth about Steam  revealing the corruption behind its operations, the systemic abuse, exploitation, and negligence that have harmed millions of users, and exposing how a global monopoly turned a gaming platform into a machine of manipulation and silent profit. 10 min read· Updated March 2026· PhishDestroy Research PD PhishDestroy Research Investigation Report Steam BlockBlasters Investigation - Profit Over Players ## Critical Finding Steam blatantly lies, covers up for criminals, and obstructs the investigation. ## Introduction: A Crime of Calculated Negligence In August 2025, the world's largest gaming platform, Steam, didn't just suffer a security breach; it actively enabled one. Through a cascade of systemic failures and gross negligence, Valve allowed the game BlockBlasters (AppID 3872350) to become a Trojan horse for a devastating malware campaign. This wasn't a sophisticated, unavoidable attack. It was a textbook data-stealing operation that succeeded because Steam's security is fundamentally broken. For 22 days, it stole hundreds of thousands of dollars, emptied crypto wallets, and compromised user accounts while Valve did nothing. When the truth surfaced, Valve's response was not to protect its users, but to protect its image. The company issued a single, deceitful statement blaming a "compromised developer account"  a pathetic lie designed to shift blame and shield itself from liability. This article will dismantle that lie. Using forensic data, timeline analysis, and Valve's own policies, we will prove that this incident was not just a failure to act, but a deliberate cover-up of criminal negligence. Corporate negligence timeline: Day 1 malware published, Day 3 first reports, Day 3 multiple flags, Day 10 zero action with 1,489,500 victims exposed, Day 22 finally removed ## Exposed Identity Steam blatantly lies and hides Valentin Lopes  the verified developer behind the malicious application. ## The 22-Day Timeline of Inaction Valve had 22 days to stop this. User reports were flowing in, and platform data showed clear signs of trouble. Their silence was a choice. July 31, 2025 BlockBlasters launches. A clean, legitimate build is approved by Steam's vetting process. August 30, 2025 The trap is set. The attackers push Patch Build 19799326. This update, containing the malware payload, is approved by Steam and distributed to all players. Early September 2025 The first victims sound the alarm. Users flood Steam Support with tickets reporting anomalous CPU usage, suspicious network traffic, and  most critically  stolen cryptocurrency. These tickets enter a black hole, ignored by Valve. September 612, 2025 The data screams a warning. Public SteamDB telemetry shows the player count collapsing to single digits, yet the game remains installed on hundreds of machines, silently exfiltrating data. This massive discrepancy is a red flag that any competent monitoring system should have caught. September 21, 2025 The community acts. Independent security researchers expose the malware's Telegram-based command-and-control infrastructure, forcing the hackers' hand. September 22, 2025 The proof is undeniable. G DATA CyberDefense AG publishes a full forensic report, confirming the malware's multi-stage attack vector and exposing the technical details of the breach. ## The Anatomy of the Attack This wasn't cutting-edge malware. It was a crude but effective cocktail of common scripts and stealers that should have been trivial for a multi-billion dollar platform to detect. ## Stage 1: Initial Compromise (game2.bat) The initial payload, a simple batch script, performed basic reconnaissance: collecting IP, geolocation, and Steam user details. It then downloaded a password-protected ZIP file (v1.zip)a classic technique to bypass naive automated scanners. ## Stage 2: Evasion and Escalation (VBS Loaders) Using VBS scripts, the malware executed its core components in hidden command windows. It added its own directory to the Microsoft Defender exclusion list  an action that should trigger an immediate, high-priority alert on any monitored system. ## Stage 3: Data Theft (Client-built2.exe & Block1.exe) With defenses disabled, the malware deployed its primary payloads: a Python-based backdoor for persistent access and a variant of the StealC infostealer. It targeted browser data, session tokens, and, most importantly, cryptocurrency wallets from Chrome, Edge, and Brave. All stolen data was funneled to two command-and-control servers in unsecured HTTP traffic. The crypto drainer IOCs confirmed Steam as a malware distribution vector for organized theft operations. ## Trust Betrayed It was precisely their trusted certificate and disregard that led to dozens of thefts that they cover up. This represents a textbook supply chain attack exploiting platform trust exploitation at scale. ## Indicators of Compromise (IoCs) ↔FileSHA256Classification game2.bat aa1a1328e0d0042d071bca13ff9a13116d8f3cf77e6e9769293e2b144c9b73b3 BAT.Trojan-Stealer.StimBlaster.F launch1.vbs c3404f768f436924e954e48d35c27a9d44c02b7a346096929a1b26a1693b20b3 Script.Malware.BatchRunner.A@ioc test.vbs b2f84d595e8abf3b7aa744c737cacc2cc34c9afd6e7167e55369161bc5372a9b Script.Malware.BatchRunner.A@ioc Client-built2.exe 17c3d4c216b2cde74b143bfc2f0c73279f2a007f627e3a764036baf272b4971a Win64.Backdoor.StimBlaster.L6WGC3 Block1.exe59f80ca5386ed29eda3efb01a92fa31fb7b73168e84456ac06f88fdb4cd82e9eWin32.Trojan-Stealer.StealC.RSZPXF ## Deconstructing the Lie: The "Hacked Account" Is Complete Bullshit ## Cover-Up Exposed Steam lies and helps victims, while their company checks developers and gives the highest certificate of trust to their content. Let's call Valve's "hacked developer" excuse what it is: a pathetic and easily disproven lie. It's an insult to the intelligence of their user base, a narrative crafted to shield them from the consequences of their own negligence. This entire fantasy collapses the moment you look at Steam's own mandatory procedures. The $100 Wall and Identity Verification: To publish on Steam, every developer must go through the Steam Direct program. This involves paying a $100 fee and completing a Know Your Customer (KYC) process, providing legal names, banking information, and tax documents. The perpetrator was not an anonymous ghost; Valve had their verified identity and financial details on file. This makes their inaction a conscious choice to protect a verified partner over their own users. The 22-Day Blackout Myth: Steamworks provides developers with robust tools to secure their accounts. A legitimate developer who lost control could file a "lost access to publisher credentials" ticket. This process is designed to be fast, freezing publishing rights and builds within hours, not weeks. The idea that a developer could be locked out for over 20 days while their game distributes malware is absurd. It implies one of two scenarios, both of which indict Valve: either the developer was complicit, or Valve ignored their frantic support tickets in addition to the dozens of user complaints. Systematic Neglect of User Complaints: Dozens of users filed detailed reports of financial theft, malware behavior, and account compromise. These weren't vague complaints; they were actionable intelligence. A competent support system would have flagged these, escalated the issue, and frozen the app page pending investigation within 24 hours. Valve's failure to do so for 22 days is not an oversight; it's a policy of willful ignorance. ## The Core Deception: Tampering with a Digital Crime Scene This is where Valve's cover-up graduates from simple negligence to what can only be described as tampering with a digital crime scene. Let this be stated without ambiguity: Valve did not remove the infected game. Forensic evidence and analysis from security researchers tracking the C2 infrastructure confirm it unequivocally: the criminals themselves deleted their malicious builds from Steam's servers. They did this on September 21st, only after their Telegram control group was publicly exposed. They executed a "scorched earth" exit, destroying the evidence to cover their tracks. Tampering with a digital crime scene - Steam/Valve hand reaching past do not cross tape while PhishDestroy investigates with magnifying glass Valve's claim of taking action is a blatant fabrication. By waiting for the attackers to erase their own tracks before stepping in to remove the store page, Valve effectively allowed the primary evidence to be destroyed. This wasn't damage control; it was obstruction. They weren't protecting users; they were protecting themselves by ensuring the crime scene was clean. ## The Human Cost of Corporate Indifference Valve's negligence had real-world consequences for which it has taken zero responsibility. Financial Ruin: Over $150,000 USD was stolen (looks like more than $1,000,000 USD). For many, this was life-altering money. One streamer lost $32,000 during a live charity broadcast for cancer treatment. Betrayal of Trust: Hundreds of users had their accounts compromised, their data stolen, and their systems infected. Absolute Silence: To this day, Valve has offered no refunds, no compensation, and no genuine apology. Their form-letter response was an insult to every victim. ## The Motive: Profit Over People Why would Valve allow this to happen? The motive is as simple as it is cynical: it was cheaper. A real security overhaul  implementing sandboxed testing for all builds, separating developer credentials, hiring a competent security team, and publishing transparency reports  would cost millions. Paying restitution to victims would set a costly precedent. The alternative? Issue a vague, misleading statement, let the news cycle move on, and absorb the minimal PR hit. It was a calculated business decision where user safety was deemed an acceptable loss. This pattern of negligence is not new. From PirateFi (2024) to Chemia (2025), Valve has repeatedly ignored warnings and allowed malware onto its platform, only acting after public outcry. BlockBlasters was not an anomaly; it was the inevitable result of a rotten security culture. ## Final Verdict: Guilty as Charged Let the facts speak for themselves. Fact: Valve's automated systems approved a build containing trivial malware. Fact: Valve's support team ignored direct warnings from victims for three weeks. Fact: Valve only acted after the hackers themselves removed the malicious files. Fact: Valve's official statement was a deliberate misrepresentation of events designed to avoid accountability. Valve didn't just fail. It lied. It covered up its own negligence, protected its profits, and left its users to pay the price. The trust that the community placed in Steam has been irrevocably broken. This wasn't a mistake; it was a betrayal. ## Sources G DATA CyberDefense AG (Sept 22, 2025) SteamDB - BlockBlasters Gamalytic GamesRadar - Steam malware report The Verge - BlockBlasters malware coverage Tom's Hardware - Steam malware analysis Community incident logs Back to News #Steam#Valve#CryptoDrainer#Malware#GamingSecurity ## Related Investigations 150+ Fake Mozilla Extensions: One Backend, One Network INVESTIGATION 150+ Fake Mozilla Extensions: One Backend, One Network $0 Takedowns: How We Disrupt Phishing Infrastructure INVESTIGATION $0 Takedowns: How We Disrupt Phishing Infrastructure NameSilo, Webnic, NiceNic: Registrars Enabling Scams INVESTIGATION NameSilo, Webnic, NiceNic: Registrars Enabling Scams # Taylor Wessing GDPR Data Breach: How Elite Lawyers Leaked Valve User Data Published: 2026-08-17 · Category: Legal / GDPR · Words: 4,324 Mirror: https://valve-xmr-5kus.4everland.app/articles/my-dog-vs-elite-gdpr-lawyers.html Original: https://phishdestroy.medium.com/my-dog-vs-elite-gdpr-lawyers-the-valve-data-breach-nobody-is-talking-about-f6f7683d813d Cybersecurity Privacy GDPR Gaming Technology A catastrophic PDF redaction failure during a routine GDPR request exposed Steam users to severe risks. Why this is no longer a joke, but a systemic failure. EXHIBIT 1.0: CHIEF DATA PROTECTION OFFICER AUDIT 100% LEAK-FREE DPO Dr. Patrick Zurheide Taylor Wessing GDPR PDF Leak Meet our new Data Protection Officer. 0 hours billed. 0 data leaks. 100% better at handling PDFs than elite corporate lawyers. Let’s explore an absurd but highly practical question in the realm of corporate data privacy: Should a global tech giant like Valve Corporation hire elite attack-dog lawyers — like the ones at the international law firm Taylor Wessing — to handle standard GDPR data requests? The answer depends entirely on your situation: If your company is completely innocent and compliant: Absolutely not. If your company has a massive internal data trove to hide: Oh, yes. Hire them immediately. Why? Because these elite corporate lawyers act as unwitting double agents. They will gladly help your opponent discover every single thing you are desperately trying to hide from regulators. The only technical requirement is that your adversary knows how to open a poorly redacted PDF. This is exactly why, in the battle for the ultimate Data Protection Officer (DPO), my dog beats a high-priced corporate lawyer hands down. A dog might chew through an ethernet cable, but it will never serve up your most sensitive corporate secrets and cause a Taylor Wessing data breach on a silver platter. ## The Weaponization of Bureaucracy: Dr. Patrick Zurheide and Dr. Tobias Schelinski The core strategy of these top-tier legal firms is to project an aura of secret knowledge, threaten the opponent straight out of the gate, and artificially stall the legal process. Does EU law require a GDPR response within 30 days? They will deliver it on day 35, ask a meaningless clarifying question, and restart the clock. The goal isn’t compliance; the goal is to exhaust the person challenging the corporation. We have the exact timeline of this bureaucratic ping-pong. On August 15, one Taylor Wessing lawyer (Dr. Tobias Schelinski) sent a formal letter doing everything possible to stall the GDPR request. He demanded additional proof of identity, arguing that the user’s burner email address (an alias that literally translates to “NotImportant”) didn’t explicitly contain their real name. He then used this manufactured delay to immediately and permanently ban the Steam account in question. They dragged this simple data request out for months. Finally, on October 1, a different lawyer (Dr. Patrick Zurheide) took over and delivered the requested data. (And yes, Taylor Wessing, we know how absolutely thrilled you must be about this article. We are so sorry for revealing your elite corporate strategy to your competitors. Wait, do you even have competitors at this level of digital incompetence? Actually, never mind, don’t answer that. We don’t have 30 days to wait for a reply from a party we couldn’t care less about.) But while weaponizing delays is a standard legal tactic, what happened next was a catastrophic operational failure. While these guard dogs were busy barking at the fence, they left the back door wide open. ## A Brief IT Crash Course for IT Lawyers (Module 101) Before we look at the leaked data, we need to talk about how this happened. If you look at the syllabus for any respectable Master of Laws (LL.M.) program in IT Law, you will find extensive modules on International Data Protection, Cybersecurity Frameworks, and the legal interpretation of GDPR Article 32 (“Security of processing”). Professors spend months drilling students on the theoretical necessity of securing personal data. However, universities assume that a graduate student already knows how a computer works. They don’t teach “How to save a file” or “How to use Adobe Acrobat.” And this is where the elite corporate legal system collapsed. The technical reality that escaped the experts: A Portable Document Format (PDF) is not a flat photograph. It is a layered digital container. When you use a basic PDF editor to draw a black vector rectangle over a line of text, you are not erasing the text. You are simply placing a digital post-it note over it. Anyone who opens that document in a program like LibreOffice Draw, Adobe Illustrator, or even a basic text-scraping script can simply select the text layer underneath the black box, copy it, and paste it into Notepad. Proper redaction requires “sanitization” — a process that permanently strips the text objects and metadata from the document code. Drawing a black shape is not cybersecurity; it is digital arts and crafts. ## The Leaked Data: When Incompetence Becomes Dangerous In response to a standard GDPR Article 15 request, Valve Corporation's legal representation delivered a massive 830-page document filled with these digital “arts and crafts.” They carefully placed black vector shapes over thousands of rows of data — leaving visible only the information convenient to their narrative (specifically, user reports filed against the requester). EXHIBIT 2.0: ANLAGE1.PDF PAGE 830 INSPECTION UNSANITIZED VECTOR OVERLAY Dr. Tobias Schelinski Taylor Wessing Valve Data Breach Document Evidence Exhibit A: 830 pages of “elite” redaction. A giant black rectangle manually placed over thousands of SteamIDs, emails, and personal data points. Too bad they forgot to delete the text underneath. ## 🚨 A Public Security Alert: Check Your GDPR Responses Through our analysis of how major corporations handle GDPR Article 15 requests, we’ve identified a systemic issue. Corporate law firms acting on behalf of tech giants often function more like aggressive PR departments or insurance adjusters. Their primary tactic is to intimidate, stall, and pressure the applicant to prevent data disclosure. However, when they finally are forced to hand over the data, their technical incompetence is exposed. In an attempt to hide the personal data of third parties or internal corporate secrets, these lawyers routinely use fundamentally flawed PDF redaction methods. As detailed in our ongoing investigation into Valve's data practices, users and legal teams can audit these documents themselves: Our urgent recommendation to all users, legal opponents, and privacy advocates: 1. Open the PDF in a basic editor (like LibreOffice Draw, Adobe Illustrator) or simply try to highlight the text under the black rectangle with your cursor and paste it into Notepad. 2. If the text copies over, a massive Data Breach has occurred. Pass this information on to anyone fighting similar legal battles. Check every single document. INTERACTIVE DEMO: PDF VECTOR LAYER EXTRACTOR SteamID: 76561198012345678 Persona: Target_User_Minor_UA Security History IP: 192.168.1.101 (Telemetry Log) Old Email: victim_email@domain.com Status: Standard Adobe Acrobat render hides text visually under vector block. Click button above to simulate text selection / copy-paste. ## What the Elite Lawyers Actually Leaked: De-anonymized User Logins: Because a Steam login is often deeply personal and linked to other online identities, over 60% of the users in that document were instantly and fully identified. Unencrypted, Raw Chat Logs & Absurd Reports: These weren’t just standard server logs. The document exposed a trove of absolutely unhinged, absurd user reports. We are talking about raw, unredacted messages heavily laced with extreme profanity, pure envy, and unchecked hate. It included literal death wishes, nationalistic slurs, and severe geopolitical vitriol from Russian users directed at a Ukrainian user. Instead of properly securing this highly sensitive and toxic data, the elite lawyers essentially packaged a raw database of hate speech and handed it over, completely exposed. Putting Minors at Risk: The Ukrainian user whose privacy rights Valve was trying to suppress was not a random teenager. He is an individual with serious technical capabilities. By failing to execute a basic PDF redaction, the lawyers handed him a fully de-anonymized database of the people who reported him. This placed those Steam users — many of whom are minors — in direct physical and digital danger. My dog would never do this. My dog would just eat the paperwork. Zero data breach. ## The Masterpiece of Hypocrisy: Page 8 If you think the technical failure is funny, the official cover letter accompanying this leak elevates the situation to absolute high comedy. On page 8 of the official legal response, Dr. Patrick Zurheide formally denies the user access to certain account details. His legal justification for withholding the information? We quote directly from the German document: “Eine genauere Auskunft ist aufgrund des Schutzes der personenbezogenen Daten anderer Nutzer der Steam-Plattform… nicht möglich.” (English translation: “A more detailed response is not possible due to the protection of personal data of other Steam users…”) Let that sink in for a moment. The highly paid Salary Partner at Taylor Wessing explicitly refused to provide certain details in order to protect the privacy of other Steam users… in the exact same email package where he attached an 830-page PDF that completely leaked the de-anonymized identities, chat logs, and raw hate speech of those exact same users. He proudly declared in writing that he was protecting the very data he was actively hemorrhaging. The letter then concludes with a classic corporate intimidation tactic: threatening the user with criminal prosecution under the German Criminal Code (StGB), while simultaneously holding the rest of the user’s legally guaranteed GDPR data hostage until the user “explains” certain account behaviors to the lawyers. It is a masterclass in weaponized, yet utterly incompetent, bureaucracy. ## A 5-Star Review for “Elite” IT Law Expertise To understand the gravity of this failure, you have to look at who is handling this data. We are not talking about an intern. According to public professional profiles, the individual responsible for this response is a recently promoted Salary Partner at Taylor Wessing. This is a professional who boasts a Master of Laws in International Commercial Law from the University of Aberdeen and — irony of ironies — literally completed PhD studies in IT Law. When you hire a specialist with a PhD in Information Technology Law from a top-tier international firm, you expect them to know how to properly sanitize a digital document before transmitting sensitive user data across borders. Instead, this catastrophic failure in basic digital literacy inadvertently verified technical realities that Valve Corporation has aggressively denied for years. Thanks to this spectacular legal blunder, we now have officially documented proof that: Massive Account Linking: Valve possesses the capability to link Steam accounts dating back to 2019. Deep Telemetry: Valve maintains an internal telemetry and logging system on its users that rivals state intelligence agencies in its depth. Official Confirmation: The elite legal team conveniently confirmed all of this in official, verifiable legal correspondence. ## A Humble Plea to IT Law Professors (And a Reality Check) To the esteemed professors at the University of Aberdeen and other prestigious institutions offering degrees in IT Law: we have a humble request. Please, we beg you, push your students harder on the actual “IT” part of their degrees. Teach them how vector graphics work. Teach them that drawing a box in Adobe Acrobat doesn’t magically erase the underlying text code. These are absolute digital basics that should be mastered before anyone is handed a PhD or allowed anywhere near sensitive Taylor Wessing GDPR compliance user data. But let’s be entirely fair to the academic institutions. Universities are highly authoritative and respectable entities. We know for a fact that no reputable professor teaches a student how to artificially delay a legally mandated GDPR response to exhaust a victim. That specific skill — the weaponization of bureaucracy and the deliberate dragging out of legal timelines — is not part of any university curriculum. That is strictly an in-house corporate initiative. It’s the kind of dark art you only learn when you join a firm like Taylor Wessing. It actually highlights a brutal, unspoken reality about the modern legal career pipeline. It seems that the graduates who truly understand technology go on to find normal, respectable jobs building, protecting, and innovating in the real world. And the others? The ones who just want to wear the expensive suits and play with buzzwords? They go to firms like Taylor Wessing to act as high-priced corporate fixers, tasked with burying the dirty secrets of tech giants behind poorly drawn digital black boxes. ## A Formal Petition to EU Data Protection Regulators To the GDPR regulators and data protection authorities currently tasked with overseeing this mess: assuming your offices aren’t staffed by the exact same type of “experts,” we respectfully ask you to investigate the circus operating under the name Taylor Wessing. Is there a legal mechanism to mandate digital re-certification for these professionals? Or perhaps someone should just check their temperatures? It genuinely seems that the moment these lawyers receive their prestigious “Dr.” prefix, they catch a severe corporate fever that permanently wipes basic computer literacy from their brains. Do you realize the sheer volume of GDPR violations contained in this single interaction? They artificially delayed a legally mandated response, withheld data under the false guise of “protecting” others, weaponized the bureaucracy, and then accidentally leaked the raw, de-anonymized data of those exact same people. Meanwhile, let’s look at the scoreboard. My dog still has exactly zero data breaches. Sure, she didn’t successfully process the GDPR request. But she also didn’t commit a massive, cross-border data leak while billing the client hundreds of euros an hour. In the modern corporate ecosystem, doing absolutely nothing and simply not screwing up makes my dog the undisputed Employee of the Month. ## Time to Change the Game on Steam This isn’t just about a lawyer making a mistake with a PDF. It is about a multi-billion dollar platform’s systemic disregard for user safety. Our project, PhishDestroy, was born because Valve Corporation simply did not care about the unchecked spam, phishing, and hijacked accounts devouring its ecosystem. We grew in that vacuum of corporate responsibility. Now, thanks directly to Valve’s choice of legal representation and this subsequent data leak, the curtain has been pulled back. It is time to dismantle their policy of looking the other way while children are robbed, ignoring unregulated skin gambling, and permanently freezing user inventories to pad their own bottom line. We have compiled the evidence, the timeline of corporate absurdity, and the full technical breakdown of their failures. It is a dense, serious read, because the truth of how global corporations handle your data usually is. ## A Special Disclaimer for Taylor Wessing & Dr. Zurheide We know exactly what happens next. We know you are probably drafting a ToS complaint or a cease-and-desist letter right now to get this article taken down. Before you do, let’s get a few things straight on the public record. First, PhishDestroy is a 100% non-profit initiative. We make exactly $0 from this. This is not a hit piece ordered by your competitors (assuming you have any at this specific level of digital arts and crafts). We are publishing this because your catastrophic leak forms the foundational evidence for our massive investigation into Valve. Second, we want to genuinely compliment your artwork. Those 830 pages of manually placed black rectangles are truly exquisite. The squares are deep, rich, and remarkably consistent. It is a beautiful testament to the fact that corporate money means absolutely nothing to the corporations spending it. Given your hourly billing rate at Taylor Wessing, this might be the most expensive modern art project in gaming history. (Pro tip for your next GDPR response: Since you are already billing Valve for hundreds of hours to draw black squares on 800+ pages, maybe try drawing some nice little circles underneath them? Just to mix it up. It won’t secure the data any better, but it will be fun for the person extracting the text). Finally, consider this a polite warning: Any attempt to report, strike, or legally threaten this publication will be treated as a direct attack on legitimate, non-profit security research. We operate by a very simple rule of the internet. You are welcome to try and take this link down. But if you do, we will do what we always do: for every one link you destroy, five new ones will appear. Welcome to the internet. ## A Legal Reminder for Taylor Wessing: The 72-Hour Rule We wouldn’t normally offer you business advice other than “close your doors,” but as cybersecurity experts, we feel obligated to point out the legal reality of your technical failure. Your practice of using graphic vector overlays instead of proper structural document sanitization is a direct violation of GDPR Article 32 (Security of processing). We strongly advise you to audit every single PDF you have ever sent to any opponent, applicant, or client. If you haven’t been checking these documents on a foundational IT level (stripping metadata and hidden layers), there is an extremely high probability that you are actively responsible for multiple, ongoing data leaks. Furthermore, let us remind your esteemed IT Law PhDs of GDPR Article 33: Once a data controller becomes aware of a personal data breach, they are legally mandated to notify the competent supervisory authority within 72 hours. Considering the cross-border nature of these leaks and the sheer volume of highly sensitive, de-anonymized data you are mishandling, attempting to sweep this under the rug will only trigger maximum regulatory penalties. You have now been made aware of the breach. The clock is ticking. ## Full Investigation & Evidence Database Access the full technical breakdown, evidence log, and timeline directly on the PhishDestroy research platform. 👉 Read the full technical analysis and evidence of the Taylor Wessing leak at PhishDestroy Direct Link Target: https://phishdestroy.io/valve-profits-from-stolen-accounts 🇩🇪 Deutsche Fassung · German version ## Taylor Wessing DSGVO-Datenpanne: Wie Elite-Anwälte Valve-Nutzerdaten leckten Eine katastrophale PDF-Schwärzungspanne bei einer routinemäßigen DSGVO-Auskunft setzte Steam-Nutzer schweren Risiken aus. Warum dies kein Scherz mehr ist, sondern ein systemisches Versagen. EXHIBIT 1.0: DATENSCHUTZBEAUFTRAGTER SECURITY AUDIT 100% LECK-FREIER DSB Dr. Patrick Zurheide Taylor Wessing GDPR PDF Leak Lernen Sie unseren neuen Datenschutzbeauftragten kennen. 0 abgerechnete Stunden. 0 Datenlecks. 100% besser im Umgang mit PDFs als Elite-Kanzleianwälte. Lassen Sie uns eine paradoxe, aber äußerst praktische Frage im Bereich des Unternehmensdatenschutzes untersuchen: Sollte ein globaler Tech-Gigant wie Valve Corporation hochbezahlte Kanzleianwälte – wie die der internationalen Kanzlei Taylor Wessing – mit der Bearbeitung von Standard-DSGVO-Auskunftsersuchen beauftragen? Die Antwort hängt vollkommen von Ihrer Situation ab: Wenn Ihr Unternehmen völlig unschuldig und regelkonform ist: Auf keinen Fall. Wenn Ihr Unternehmen riesige interne Datenschätze zu verbergen hat: Oh ja, stellen Sie sie sofort ein. Warum? Weil diese Elite-Anwälte als unfreiwillige Doppelagenten agieren. Sie helfen Ihrem Gegner zu entdecken, was Sie vor Regulierungsbehörden verbergen wollen. Die einzige technische Voraussetzung ist, dass Ihr Gegner weiß, wie man ein schlecht geschwärztes PDF öffnet. Genau deshalb schlägt mein Hund im Kampf um den ultimativen Datenschutzbeauftragten (DSB) einen teuren Konzernanwalt um Längen. Ein Hund mag ein Ethernet-Kabel zerkauen, aber er wird niemals Ihre sensibelsten Unternehmensgeheimnisse servieren und eine Taylor Wessing data breach auf dem Silbertablett verursachen. ## Die Bewaffnung der Bürokratie: Dr. Patrick Zurheide und Dr. Tobias Schelinski Die Kernstrategie dieser Top-Kanzleien besteht darin, eine Aura des Geheimwissens zu projizieren, den Gegner sofort zu bedrohen und das Rechtsverfahren künstlich zu verzögern. Schreibt das EU-Recht eine DSGVO-Antwort innerhalb von 30 Tagen vor? Sie liefern an Tag 35, stellen eine belanglose Klarstellungsfrage und starten die Uhr neu. Das Ziel ist nicht Compliance; das Ziel ist die Zermürbung des Antragstellers. Wir haben den genauen Zeitplan dieses bürokratischen Ping-Pongs. Am 15. August schickte ein Taylor Wessing-Anwalt (Dr. Tobias Schelinski) ein formelles Schreiben, um das Auskunftsersuchen zu verzögern. Er forderte zusätzliche Identitätsnachweise mit der Begründung, die Alias-E-Mail-Adresse des Nutzers enthalte nicht explizit seinen bürgerlichen Namen. Er nutzte diese künstliche Verzögerung, um das betroffene Steam-Konto dauerhaft zu sperren. Sie zogen diese einfache Datenanfrage monatelang hin. Am 1. Oktober übernahm ein anderer Anwalt (Dr. Patrick Zurheide) und übermittelte die angeforderten Daten. (Und ja, Taylor Wessing, wir wissen, wie begeistert Sie über diesen Artikel sein müssen. Es tut uns leid, dass wir Ihre Unternehmensstrategie enthüllen. Haben Sie überhaupt Konkurrenten auf diesem Niveau digitaler Inkompetenz? Antwort nicht nötig, wir haben keine 30 Tage Zeit.) Aber während die Verzögerungstaktik rechtlicher Standard ist, war das, was als Nächstes geschah, ein katastrophales betriebliches Versagen. Während die Wachhunde am Zaun bellten, ließen sie die Hintertür weit offen. ## Ein kurzer IT-Crashkurs für IT-Anwälte (Modul 101) Bevor wir uns die geleckten Daten ansehen, müssen wir darüber sprechen, wie das passiert ist. Wer einen Blick in den Lehrplan eines angesehenen Master of Laws (LL.M.) im IT-Recht wirft, findet Module zu internationalem Datenschutz, Cybersecurity-Frameworks und DSGVO Artikel 32 („Sicherheit der Verarbeitung“). Professoren drillen Studenten auf die theoretische Notwendigkeit der Datensicherheit. Universitäten setzen jedoch voraus, dass ein Absolvent bereits weiß, wie ein Computer funktioniert. Sie lehren nicht „Wie speichere ich eine Datei“ oder „Wie benutze ich Adobe Acrobat“. Genau hier brach das Elite-Rechtssystem zusammen. Die technische Realität, die den Experten entging: Ein Portable Document Format (PDF) ist kein flaches Foto. Es ist ein mehrschichtiger digitaler Container. Wenn Sie in einem PDF-Editor ein schwarzes Vektorrechteck über einen Text zeichnen, löschen Sie den Text nicht. Sie kleben lediglich einen digitalen Post-it-Zettel darüber. Jeder, der dieses Dokument in LibreOffice Draw, Adobe Illustrator oder einem einfachen Skript öffnet, kann die Textschicht unter dem schwarzen Kasten markieren, kopieren und in einen Editor einfügen. Eine echte Schwärzung erfordert „Sanitisation“ (Dokumentensanierung) — ein Verfahren, das Textobjekte und Metadaten dauerhaft aus dem Code entfernt. Das Zeichnen schwarzer Formen ist keine Cybersicherheit, sondern Bastelunterricht. ## Die geleckten Daten: Wenn Inkompetenz gefährlich wird Als Antwort auf eine Standard-Anfrage nach DSGVO Artikel 15 lieferte die Rechtsvertretung von Valve Corporation ein riesiges 830-seitiges Dokument ab. Sie platzierten sorgfältig schwarze Vektorformen über Tausende von Datenzeilen — und ließen nur die Informationen sichtbar, die ihrer Argumentation dienten. EXHIBIT 2.0: ANLAGE1.PDF SEITE 830 INSPEKTION UNSANIERTE VEKTOR-ÜBERLAGERUNG Dr. Tobias Schelinski Taylor Wessing Valve Data Breach Document Evidence Exponat A: 830 Seiten „Elite“-Schwärzung. Ein riesiges schwarzes Rechteck, das manuell über Tausende von SteamIDs, E-Mails und Datenpunkte gelegt wurde. Schade nur, dass sie vergessen haben, den Text darunter zu löschen. ## 🚨 Öffentliche Sicherheitswarnung: Überprüfen Sie Ihre DSGVO-Auskünfte! Durch unsere Analyse von DSGVO-Auskünften großer Konzerne haben wir ein systemisches Problem identifiziert. Großkanzleien agieren oft wie aggressive PR-Abteilungen. Ihre Haupttaktik ist Druckaufbau, Einschüchterung und Verzögerung. Wenn sie jedoch schließlich gezwungen sind, die Daten zu übergeben, wird ihre technische Inkompetenz offenbar. Um Daten Dritter oder Geschäftsgeheimnisse zu verbergen, nutzen diese Anwälte fehlerhafte PDF-Schwärzungsmethoden. Wie in unserer laufenden Untersuchung zu Valves Datenpraktiken beschrieben, können Betroffene diese Dokumente selbst prüfen: Unsere dringende Empfehlung an alle Nutzer, Rechtsgegner und Datenschützer: 1. Öffnen Sie die PDF in einem Editor (wie LibreOffice Draw, Adobe Illustrator) oder versuchen Sie, den Text unter dem Kasten zu markieren und in den Editor zu kopieren. 2. Wenn der Text kopiert wird, liegt ein massiver Datenschutzverstoß vor. Geben Sie diese Information weiter. Überprüfen Sie jedes einzelne Dokument. INTERAKTIVE DEMO: PDF-VEKTORSCHICHT-EXTRAKTOR SteamID: 76561198012345678 Persona: Target_User_Minor_UA Security History IP: 192.168.1.101 (Telemetrie-Log) Old Email: victim_email@domain.com Status: Standard-Adobe-Acrobat-Render versteckt Text unter Vektor-Block. Klicken Sie oben, um die Textauswahl / Kopieren zu simulieren. ## Was die Elite-Anwälte tatsächlich geleckt haben: De-anonymisierte Nutzer-Logins: Da ein Steam-Login oft mit anderen Online-Identitäten verknüpft ist, wurden über 60% der Nutzer in diesem Dokument sofort und vollständig identifiziert. Unverschlüsselte Chat-Logs & Hassbotschaften: Das Dokument enthüllte eine Ansammlung unzensierter Nutzer-Meldungen mit Beleidigungen, Hassreden und Morddrohungen russischer Nutzer gegen einen ukrainischen Nutzer. Statt diese sensiblen Daten zu schützen, übergaben die Kanzleianwälte eine Rohdatenbank voll freiliegender Hassrede. Gefährdung von Minderjährigen: Der ukrainische Nutzer erhielt durch die gescheiterte Schwärzung eine de-anonymisierte Datenbank der Personen, die ihn gemeldet hatten. Dies brachte diese Steam-Nutzer — viele davon minderjährig — in direkte digitale und physische Gefahr. Mein Hund würde das nie tun. Mein Hund würde das Papier einfach fressen. Null Datenleck. ## Das Meisterwerk der Heuchelei: Seite 8 Wenn Sie das technische Versagen schon amüsant finden, hebt das offizielle Begleitschreiben die Situation zur absoluten Höchstkomödie. Auf Seite 8 des offiziellen Anwaltsentscheids verweigert Dr. Patrick Zurheide dem Nutzer formell den Zugriff auf bestimmte Kontodetails. Seine rechtliche Begründung zitiert direkt aus dem deutschen Dokument: “Eine genauere Auskunft ist aufgrund des Schutzes der personenbezogenen Daten anderer Nutzer der Steam-Plattform… nicht möglich.” Lassen Sie sich das auf der Zunge zergehen. Der hochbezahlte Salary Partner bei Taylor Wessing weigerte sich explizit, bestimmte Details bereitzustellen, um die Privatsphäre anderer Nutzer zu schützen… in genau demselben E-Mail-Paket, in dem er ein 830-seitiges PDF anhängte, das die Identitäten und Chat-Protokolle derselben Nutzer komplett leckte! Er erklärte schriftlich, er schütze genau die Daten, die er zeitgleich massenhaft verlor. ## Eine 5-Sterne-Bewertung für „Elite“-IT-Rechtsexpertise Um die Tragweite zu verstehen, muss man sehen, wer diese Daten bearbeitet hat. Wir sprechen nicht von einem Praktikanten. Verantwortlich ist ein Salary Partner bei Taylor Wessing mit Master-Abschluss in Aberdeen und — Ironie des Schicksals — einer Promotion im IT-Recht. Statt fachlicher Expertise bestätigte dieser Fehler ungewollt technische Realitäten, die Valve Corporation jahrelang bestritten hat: Umfassende Verknüpfung: Valve ist in der Lage, Steam-Konten bis ins Jahr 2019 zurück zu verknüpfen. Tiefgehende Telemetrie: Valve betreibt ein internes Protokollierungssystem, das in seiner Tiefe staatlichen Diensten nahekommt. Offizielle Bestätigung: Das Anwaltsteam hat all dies in offizieller Korrespondenz dokumentiert. ## Formelle Petition an EU-Datenschutzbehörden An die zuständigen DSGVO-Regulierungsbehörden: Wir fordern Sie auf, die Vorgänge unter dem Namen Taylor Wessing zu untersuchen. Sie haben eine gesetzliche Auskunft verzögert, Daten unter dem Deckmantel des „Schutzes“ verweigert und dieselben Daten versehentlich öffentlich gemacht. ## Besonderer Hinweis für Taylor Wessing & Dr. Zurheide PhishDestroy ist eine 100% gemeinnützige Initiative ($0 Einnahmen). Wir veröffentlichen dies, weil Ihr Datenleck das Fundament unserer Untersuchung bildet. Jeder Versuch, diese Veröffentlichung juristisch anzugreifen, wird als Angriff auf legitime Sicherheitsforschung gewertet. Für jeden Link, den Sie löschen lassen, entstehen fünf neue. Willkommen im Internet. ## Rechtlicher Hinweis an Taylor Wessing: Die 72-Stunden-Regel Das Aufbringen grafischer Vektorüberlagerungen verstößt gegen DSGVO Artikel 32. Wir erinnern die IT-Rechts-Doktoren an DSGVO Artikel 33: Nach Kenntnisnahme einer Verletzung des Schutzes personenbezogener Daten ist die Aufsichtsbehörde unverzüglich und möglichst binnen 72 Stunden zu benachrichtigen. Die Uhr tickt. ## Vollständige technische Analyse & Beweisdatenbank Greifen Sie auf die vollständige Untersuchung, Beweisprotokolle und Zeitleisten direkt auf PhishDestroy zu. 👉 Lesen Sie die vollständige technische Analyse und die Beweise zum Taylor Wessing-Datenleck bei PhishDestroy Ziel-URL: https://phishdestroy.io/valve-profits-from-stolen-accounts # Taylor Wessing GDPR Data Breach (Part 2): The 5-Year PDF Vulnerability Exposing Global Corporations Published: 2026-08-19 · Category: Legal / GDPR · Words: 2,426 Mirror: https://valve-xmr-5kus.4everland.app/articles/my-dog-vs-elite-lawyers-part-2.html Original: https://phishdestroy.medium.com/my-dog-vs-elite-lawyers-part-2-the-5-year-pdf-vulnerability-exposing-global-corporations-81cdad269253 Cybersecurity Gdpr Data Breach Privacy Legal Tech We thought Taylor Wessing made a manual mistake with a GDPR request. We were wrong. It’s an automated, firm-wide catastrophe. 🚨 Key Findings: The Breach: Elite law firm Taylor Wessing is using an outdated script to “redact” sensitive PDFs, masking data visually but leaving the text fully readable underneath. The Scale: Evidence suggests this vulnerability has affected their corporate clients (including giants like Pfizer, Just Eat, Chubb, and SAP) since 2019. The Hypocrisy: While leaking massive amounts of data, their lawyers issue baseless criminal threats to citizens making lawful GDPR requests. A few days ago, as a spin-off to our massive cybersecurity exposé on How Valve Profits From 70M+ Stolen Steam Accounts, we published an article documenting a catastrophic legal blunder. We revealed how the elite, high-priced lawyers at Taylor Wessing (specifically Dr. Patrick Zurheide and Dr. Tobias Schelinski) accidentally leaked 830 pages of highly sensitive, de-anonymized Steam user data while trying to defend Valve Corporation against a routine GDPR request. We joked that my dog, having precisely zero data breaches on her resume, was officially better at data protection than a Salary Partner with a PhD in IT Law. My dog is now winning 2–0. EXHIBIT 1.0: CHIEF DATA PROTECTION OFFICER AUDIT (PART 2) SCORE: DOG 2 — 0 LAWYERS Dr. Patrick Zurheide Taylor Wessing GDPR PDF Leak Dog Officer Meet our Chief Data Protection Officer. 0 data breaches. 100% better at using PDFs than Taylor Wessing. After publishing the first piece, we had a long, hard think. We looked at those 830 pages of black rectangles. We realized something fundamental about corporate lawyers: they are generally too self-important to manually draw black boxes on 800+ pages. Doing that by hand would give you a severe case of digital hemorrhoids. No, they didn’t do it manually. They used a script. And that’s when the joke stopped being funny, and became a systemic, global cybersecurity crisis. ## The Cheap Software Behind the Elite Facade Here is the technical reality of what these lawyers — who think they are richer, smarter, and more important than Valve’s own users — actually did. To save money on proper, enterprise-grade data sanitization software, their systems rely on a generic, outdated library: Aspose.PDF for .NET 20.8. The core issue is that their script uses this outdated software to draw black vector rectangles (using re/f operators in the PDF code) over text coordinates. What it should be doing is properly sanitizing and deleting the underlying text layer (using BT/ET operators). It creates a visual mask on your screen. But the raw data? It remains 100% accessible beneath it. // The Math on the Scale of this Catastrophe: Dr. Patrick Zurheide alone likely processes roughly 100 to 300 GDPR requests a year. For the few users who don’t immediately surrender to his initial wave of legal threats and delays, he eventually sends them the “brilliance of his experience” — a legal response document that consists of 94% black rectangles. But this is not Malevich’s “Black Square”. It is just a cheap vector shape. Remove it. EXHIBIT 2.0: ASPOSE.PDF METADATA SMOKING GUN 36 SECONDS PROCESSING TIME Dr. Tobias Schelinski Taylor Wessing Valve Data Breach Forensic Metadata Forensic metadata extraction of Taylor Wessing’s 830-page response. The “36 seconds” processing time is the smoking gun: they didn’t redact manually; they used an automated, vulnerable script. ## The Blast Radius: Whose Data Did Dr. Patrick Zurheide and Dr. Tobias Schelinski Process? We didn’t just guess that this was a firm-wide issue. We tested it. We immediately contacted individuals we knew who had previously received documents processed by Taylor Wessing. They sent us their files. We opened them and looked straight at the meta-tags. What did we find? Exactly what we expected. The exact same vulnerability. The exact same flawed redaction script. Did we read the contents of their hidden documents? No. We absolutely refused to look at the underlying data. We simply checked the metadata, confirmed the vulnerability, and handed the owners the instructions on how to reveal the hidden text themselves. But let’s scale this up. This vulnerability has likely been present in hidden documents processed by Taylor Wessing since 2019. Now, think about the corporate giants they defend. Taylor Wessing proudly advertises its Data Protection and Cyber Security work for massive global corporations. Based on their own public client lists and our forensic findings, we have to ask a terrifying question regarding the data they have processed over the last five years: What about the millions of gamers in the Valve Corporation (Steam) ecosystem? What about the global Taylor Wessing GDPR compliance documents of Just Eat? What about the European data transfers for tech giants like Vinted and SAP? What about the sensitive incident reports for Chubb Insurance (where Taylor Wessing ironically boasts about sitting on their “Cyber Incident Response Team”)? And what about the highly confidential clinical data handled by Pfizer and their other Life Sciences clients? If Taylor Wessing used this same cheap script to “redact” documents for these corporations, then they didn’t hide anything. They intentionally disclosed it. ## The Difference Between Us: A Message to Taylor Wessing Let’s address Taylor Wessing directly. What is the fundamental difference between your actions and ours? You, Dr. Patrick Zurheide and Dr. Tobias Schelinski, are utterly arrogant. You threaten your clients and opponents with criminal code articles. You act like God. You arbitrarily hand out permanent account bans simply because a user’s burner email address doesn’t explicitly contain their real name. You act as the judge, the jury, and the executioner. We do not blackmail. We do not suffer from a God complex. And we don’t just write articles. We do not decide which criminal articles apply — the courts and the regulators do. But apparently, at Taylor Wessing, you operate under the delusion that lawyers write the laws and pass the verdicts. ATTENTION TO ALL CORPORATE CLIENTS: This avalanche cannot be stopped. The data is already out there. It was emailed from Taylor Wessing’s own servers. You should say a massive “thank you” to Dr. Patrick, Dr. Tobias, and their accomplices for single-handedly compromising your confidential documents. ## 📎 SECURITY ADVISORY: We Warned Them. Now It’s Up To You. We have already contacted Taylor Wessing and informed them of this critical vulnerability. But let’s be realistic: we know they are liars. We fully expect them to lie, hide the truth, and bury this under attorney-client privilege, because the scale of this data leak is undeniably critical. If you or your company have ever received a “redacted” PDF document from Taylor Wessing, audit these files immediately. ⚡️ No-Install Lifehacks (The Easiest Ways to Check): The “Select All” Hack: Open the PDF in your browser. Press Ctrl+A (Select All), then Ctrl+C (Copy), and paste it (Ctrl+V) into Notepad. If the redaction is fake, the “hidden” text will simply paste right along with the rest of the document. The “Blind Search” Hack: Press Ctrl+F and search for common characters (like the vowel “a” or the number “1”). If the browser registers a hit and highlights the black redaction box — the text layer is still alive. 🛠 How to Check Visually (Safe Offline Software): LibreOffice Draw — Open the PDF, click the black box, and press Delete. Adobe Acrobat Pro — Use the “Edit PDF” tool to simply drag the black shapes out of the way. ⚠️ WARNING: Do NOT upload sensitive legal documents to random online PDF editors like ilovepdf. You might be committing a data breach. Only use local software. ## Do Not Let Them Hide This: Open-Source Forensic Toolkit We contacted Patrick, and apparently, he thought he was the smartest guy in the room. In response to our message about the data leak, he seemed to think we were going to chat with him, and he simply called it ‘amusing.’ There will be no further communication between PhishDestroy and Taylor Wessing. We have notified them about the leak via their official emails. However, judging by Patrick’s reaction, ‘amusing’ means that no one is going to take any action or notify anyone. Because of this, we have created a tool so you can check and report it yourselves. It can be run locally without an internet connection, and there are no logs. GitHub Forensic Utility: taylor-wessing-data-breach-toolkit Forensic auditing utility to expose and unmask failed visual-only PDF redactions by Taylor Wessing LLP. Access Open-Source Toolkit on GitHub Remove the black square, read the truth, and immediately report the data leak to your national Data Protection Regulator. And if you want to share your confirmed leaks with us (complains@phishdestroy.io), we will gladly forward them to the universities where these “experts” give lectures. ## Dr. Patrick Zurheide Taylor Wessing GDPR Threat Audit Doctor, in response to a legitimate GDPR request, what are you doing? Making accusations? Did you have a fever? We guarantee that we won’t hide anything and will forward everything not just to the appropriate authorities, but to more than just the appropriate authorities — including your university. We want to challenge the fact that you’re a doctor — I think you might be a criminal? A fraudster? A blackmailer? But I’m not a court, and I’m not you — I can’t call you that. They don’t hesitate to issue direct criminal threats, labeling anyone associated with a lawful GDPR request as “accomplices” (a direct formulation from Dr. Patrick Zurheide’s official response). To the corporate giants reading this: this is who you trust with your clients’ data. You are paying premium rates to absolute amateurs who treat a fundamental GDPR data request like an aggressive debt collector’s call or a hostile corporate attack. People with this mentality have no business working in Tech and IT Law. They twist European legislation to suit their arrogance, and to make matters worse, they are allowed to teach at EU universities. With clowns like this gatekeeping data protection, EU citizens effectively have no rights. They use the very laws designed to protect you as a weapon to threaten you. Let us remind Dr. Patrick and his “accomplices” of one simple fact: We do not blackmail, and we do not suffer from a God complex. We do not decide which criminal articles apply, and neither do you. The courts and the regulators do. — PhishDestroy Research Team (and the Dog) ## Full Investigation & Evidence Database Access the complete technical breakdown, source logs, and timeline directly on the primary research platform. 👉 Read the full technical analysis and evidence of the Taylor Wessing leak at PhishDestroy Direct Link Target: https://phishdestroy.io/valve-profits-from-stolen-accounts 🇩🇪 Deutsche Fassung · German version ## Taylor Wessing DSGVO-Datenpanne: Mein Hund vs. Elite-Anwälte (Teil 2) — Die 5-jährige PDF-Sicherheitslücke, die globale Konzerne gefährdet Wir dachten, Taylor Wessing hätte bei einer DSGVO-Anfrage einen manuellen Fehler gemacht. Wir irrten uns. Es ist eine automatisierte, kanzleiweite Katastrophe. 🚨 Haupterkenntnisse: Die Datenpanne: Die Elite-Kanzlei Taylor Wessing verwendet ein veraltetes Skript zum „Schwärzen“ sensibler PDFs, das Daten nur visuell überdeckt, den Text darunter aber vollständig lesbar lässt. Das Ausmaß: Beweise deuten darauf hin, dass diese Sicherheitslücke ihre Firmenkunden (darunter Riesen wie Pfizer, Just Eat, Chubb und SAP) seit 2019 betrifft. Die Heuchelei: Während sie massive Datenmengen lecken, sprechen ihre Anwälte haltlose strafrechtliche Drohungen gegen Bürger aus, die rechtmäßige DSGVO-Anfragen stellen. Vor wenigen Tagen haben wir im Rahmen unserer großen Enthüllung über Wie Valve von 70M+ gestohlenen Steam-Konten profitiert einen Artikel über einen katastrophalen Anwaltsfehler veröffentlicht. Wir haben enthüllt, wie die hochbezahlten Anwälte bei Taylor Wessing (speziell Dr. Patrick Zurheide und Dr. Tobias Schelinski) versehentlich 830 Seiten hochsensibler Steam-Nutzerdaten leckten, während sie versuchten, Valve Corporation gegen eine DSGVO-Anfrage zu verteidigen. Wir scherzten, dass mein Hund mit genau 0 Datenpannen im Lebenslauf offiziell besser im Datenschutz ist als ein Salary Partner mit Promotion im IT-Recht. Mein Hund führt jetzt mit 2:0. EXHIBIT 1.0: DATENSCHUTZBEAUFTRAGTER AUDIT (TEIL 2) STAND: HUND 2 — 0 ANWÄLTE Dr. Patrick Zurheide Taylor Wessing GDPR PDF Leak Dog Officer Lernen Sie unseren Leiter des Datenschutzes kennen. 0 Datenlecks. 100% besser im Umgang mit PDFs als Taylor Wessing. Nach der Veröffentlichung des ersten Teils dachten wir gründlich nach. Wir sahen uns diese 830 Seiten mit schwarzen Rechtecken an. Wir erkannten etwas Grundlegendes: Wirtschaftsanwälte sind sich meist zu fein, um manuell schwarze Kästchen auf 800+ Seiten zu zeichnen. Nein, sie haben es nicht manuell gemacht. Sie nutzten ein Skript. Und in diesem Moment hörte der Scherz auf, lustig zu sein, und wurde zu einer systemischen, globalen Cybersicherheitskrise. ## Die billige Software hinter der Elite-Fassade Hier ist die technische Realität dessen, was diese Anwälte tatsächlich getan haben. Um Geld für professionelle Software zur Dokumentenbereinigung zu sparen, verlassen sich ihre Systeme auf eine veraltete Bibliothek: Aspose.PDF for .NET 20.8. Das Kernproblem besteht darin, dass ihr Skript diese Software nutzt, um schwarze Vektor-Rechtecke (re/f Operatoren im PDF-Code) über Textkoordinaten zu zeichnen. Was es tun sollte, ist das ordnungsgemäße Bereinigen und Löschen der darunter liegenden Textschicht (BT/ET Operatoren). Es erzeugt eine visuelle Maske auf Ihrem Bildschirm. Aber die Rohdaten? Sie bleiben darunter zu 100 % zugänglich. EXHIBIT 2.0: ASPOSE.PDF METADATEN-BEWEIS 36 SEKUNDEN VERARBEITUNGSZEIT Dr. Tobias Schelinski Taylor Wessing Valve Data Breach Forensic Metadata Forensische Metadaten-Extraktion der 830-seitigen Antwort von Taylor Wessing. Die Verarbeitungszeit von „36 Sekunden“ ist der eindeutige Beweis: Sie haben nicht manuell geschwärzt, sondern ein automatisiertes, fehlerhaftes Skript verwendet. ## Die Reichweite der Sicherheitslücke: Welche Unternehmensdaten wurden bearbeitet? Wir haben nicht nur vermutet, dass dies ein kanzleiweites Problem ist. Wir haben es getestet. Wir haben Personen kontaktiert, die zuvor Dokumente von Taylor Wessing erhalten hatten. Sie schickten uns ihre Dateien. Wir prüften die Metadaten. Was wir fanden? Exakt dieselbe Lücke. Exakt dasselbe Skript. Diese Lücke besteht in Dokumenten von Taylor Wessing wahrscheinlich seit 2019. Bedenken Sie die globalen Konzerne, die sie vertreten: Die Millionen Spieler im Valve Corporation (Steam) Ökosystem. Die globalen Taylor Wessing GDPR compliance Dokumente von Just Eat. Europäische Datenübermittlungen von Giganten wie Vinted und SAP. Sensible Berichte für Chubb Insurance. Vertrauliche klinische Daten von Pfizer. Wenn Taylor Wessing dasselbe billige Skript verwendet hat, wurden diese Daten nicht verborgen, sondern fahrlässig offengelegt. ## Open-Source Forensic Toolkit auf GitHub Wir haben ein Tool entwickelt, mit dem Sie Ihre PDFs lokal und ohne Internetverbindung selbst prüfen können. GitHub Utility: taylor-wessing-data-breach-toolkit Forensisches Prüfwerkzeug zur Aufdeckung fehlerhafter visueller PDF-Schwärzungen von Taylor Wessing LLP. Auf GitHub Open-Source Toolkit zugreifen ## Vollständige technische Analyse & Beweisdatenbank Greifen Sie auf die vollständige Untersuchung, Beweisprotokolle und Zeitleisten direkt auf PhishDestroy zu. 👉 Lesen Sie die vollständige technische Analyse und die Beweise zum Taylor Wessing-Datenleck bei PhishDestroy Ziel-URL: https://phishdestroy.io/valve-profits-from-stolen-accounts # Taylor Wessing GDPR Data Breach (Part 3): The Right to be Forgotten Trap & Academic Repository Evidence Published: 2026-09-10 · Category: Legal / GDPR · Words: 2,125 Mirror: https://valve-xmr-5kus.4everland.app/articles/my-dog-vs-elite-lawyers-3-valve-gdpr-cover-up.html Original: https://phishdestroy.medium.com/my-dog-vs-elite-lawyers-3-valve-gdpr-and-the-cover-up-dd003307e309 Cybersecurity Data Breach Gdpr Valve Privacy Why does Dr. Patrick Zurheide believe it is legal to use the name Taylor Wessing to cover up his failure? EXHIBIT 3.0: LEGAL COVER-UP AUDIT DARK PATTERN IDENTIFIED Dr. Patrick Zurheide Taylor Wessing GDPR Right to be Forgotten Trap Why does Dr. Patrick Zurheide believe it is legal to use the name Taylor Wessing to cover up his failure? Alright, everyone, you can exhale. There will be no “Hydra.” I was joking about flooding the internet. But I do want to extend a massive, sincere “thank you” to Dr. Patrick Zurheide for exercising his GDPR “Right to be Forgotten.” You see, invoking that right leaves a very specific, highly visible digital footprint. And let’s call it what it is: Dr. Patrick Zurheide has just permanently attached a Dark Pattern to his own name. Did you really think we were crazy enough to blindly multiply articles and attack a corporation that is actively breaking the law just to bait us? No. We came here to expose Valve Corporation, and we are exactly on the right path. ## The Google Warning: A Massive Red Flag for High-Paying Clients — Dr. Patrick Zurheide and Dr. Tobias Schelinski Let’s look at Dr. Patrick Zurheide’s GDPR case from a logical standpoint. The “Right to be Forgotten” was designed to protect private, vulnerable citizens. But in this case, Dr. Patrick Zurheide used his big name and legal weight to apply pressure — once again “proving” his elite professionalism and understanding of the law. But here is where the elite lawyer made a critical error in understanding how search engines actually work. Dr. Patrick Zurheide isn’t just Googled by random people on the internet. He is Googled by clients. Wealthy, corporate clients looking to hire a highly expensive, top-tier lawyer at Taylor Wessing. When a reasonable client is about to spend massive amounts of money, they do their due diligence. And when they scroll down his Google search results, they will now see a glaring, unremovable warning: Information has been hidden. EXHIBIT 3.1: GOOGLE GDPR REMOVAL NOTICE EVIDENCE UNREMOVABLE RED FLAG Dr. Tobias Schelinski Taylor Wessing GDPR Google Removal Notice Einige Ergebnisse wurden möglicherweise aufgrund der Bestimmungen des europäischen Datenschutzrechts entfernt. Weitere Informationen For any intelligent client, this is an instant trigger. It screams that something is being concealed. If they care about where their money is going, they will dig deeper. And they will find what was hidden. ## The Dog Metaphor: Smearing the Evidence We might be a little crazy, and we could have easily trashed the internet with garbage to prove a point. But why? We aren’t web terrorists; we are the truth. If the truth is so unpleasant for Dr. Patrick Zurheide, we are truly sorry — he could have just written to us. Instead, he and Valve Corporation continued to cover up a data breach (which exposed children’s data!) and failed to report it. Their calculation was obvious: provoke us, wait for us to act unhinged, and then accuse us of defamation. But there is a flaw in their plan. We don’t care about their accusations, and we don’t care about Dr. Patrick’s degrees. The article is true. Are we giving up? No. Here is a simple truth: When a dog poops on the floor, it doesn’t try to hide the crime by smearing it all over the walls. It just makes the mess bigger, smellier, and impossible to ignore. Dr. Patrick, your GDPR takedown request was you smearing it on the wall. ## The Academic Strike: Good Luck Deleting This They expected the “Hydra” — a blind, aggressive multiplication of blog posts. Instead, we have documented a top-tier lawyer using a Dark Pattern. For any major corporation (like Google’s Security Team), this is a trigger for a deep audit. They will look into web archives, find the logs, and see exactly what Taylor Wessing lawyers were trying to bury. Since Dr. Patrick Zurheide likes to play games with the law — acting as a private citizen when he wants to hide, but representing Valve Corporation when it suits him — we decided to change the battlefield. This year, we will be releasing two full academic papers regarding corporate security competence and the (in)ability to handle PDF vulnerabilities. You can DMCA a blog post. You can use GDPR to hide a Medium article. But you cannot delete academic materials. Once published in academic repositories, they are forever. And out of pure courtesy, we will make sure these papers are sent directly to Dr. Patrick’s university. Perhaps the academic community can help him and his colleagues regain their grip on reality. ## A Message, Not a Threat You calculated that we would be cruel and reckless. We calculated that an elite lawyer would vanity-search his own name and misuse the law to clean it up. Dr. Patrick, stop playing games with the law. We are fully in control and we know exactly what we are doing. Do you? We can escalate the discussion about your Dark Patterns to a completely different level, if you catch our drift. And no, these are not threats. Study our previous cases against other corporations. We never threaten. We just write exactly what we are going to do, and then we do it. Consider it our style of investigative journalism. The game is still on. But we are the ones writing the rules now. ## An Open Letter to Taylor Wessing and Dr. Patrick Zurheide Dr. Tobias Schelinski, Dr. Patrick Zurheide, and Taylor Wessing, we know exactly what you are waiting for. You are waiting for us to make a mistake, to cross a line, or to lash out blindly. But whatever you are hoping for, it will never justify what you are actively doing. You are covering up a data breach involving children. You are putting kids at direct risk. A breach that you are responsible for. And now you are upset because someone is actually daring to talk about it? Did you even study the law? Dr. Patrick officially states that he represents the interests of his client, Valve. Since when does representing a multi-billion-dollar corporation make you a “private citizen” who needs the protection of the GDPR? Let’s stop playing games. You are not a victim. You are using your name and exploiting a privacy loophole to continue hiding your own legal violations, your staggering incompetence, and what essentially amounts to a corporate crime. By handing over the data of the affected parties (the whistleblowers and victims), you effectively threw them under the bus and put them in direct danger. And after doing all of that, you genuinely believe your smartest, most reasonable move is to try and scrub the truth from the internet using the “Right to be Forgotten”? You think you can just delete reality? We’ll see about that. I don’t know what you’ve come up with over there — but you’d better not mess with us. No one’s going to pay you — and you won’t be able to take it down either. You’re breaking the law. We’re not playing games here, and this isn’t Valve trying to shield itself from the truth, which has already been partially revealed thanks to your leak. All the best, elite lawyer. As documented in our primary investigation into Valve's data practices, here is the original document evidence: EXHIBIT 3.2: 830-PAGE UNSANITIZED PDF REDACTION MASTERPIECE UNSANITIZED LEAK Dr. Patrick Zurheide Taylor Wessing GDPR PDF Leak Exhibit A Exhibit A: 830 pages of “elite” redaction. A giant black rectangle manually placed over thousands of SteamIDs, emails, and personal data points. Too bad they forgot to delete the text underneath. If you don’t like it — and it’s true that you made a mistake — just stop Googling yourself. I can see which region Dr. Patrick was searching for Dr. Patrick from. PhishDestroy Research Repository References: Steam API Scam: Deception & Negligence | PhishDestroy Inside the multi-million dollar Steam API offer-swap scam. Profiling the 5 algorithms and Valve's systemic negligence. Valve Profits from 70M+ Stolen Steam Accounts Valve profits from 70M+ stolen Steam accounts: a 15% cut on stolen skins, $450M victim liability, COPPA violations... Steam Shadow Economy: Pricing, Scams & GDPR PhishDestroy investigates Steam regional pricing, outsourced support, skin-market scams, the CEVA data breach, and GDPR... ## Full Investigation & Evidence Database Access the complete technical breakdown, evidence log, and academic repository announcements on PhishDestroy. 👉 Read the full technical analysis and evidence of the Taylor Wessing leak at PhishDestroy Direct Link Target: https://phishdestroy.io/valve-profits-from-stolen-accounts 🇩🇪 Deutsche Fassung · German version ## Taylor Wessing DSGVO-Datenpanne (Teil 3): Die DSGVO „Recht auf Vergessenwerden“-Falle und warum akademische Arbeiten ewig bleiben Warum glaubt Dr. Patrick Zurheide, dass es rechtmäßig ist, den Namen Taylor Wessing zu nutzen, um sein eigenes Versagen zu vertuschen? EXHIBIT 3.0: LEGAL COVER-UP AUDIT DARK PATTERN IDENTIFIZIERT Dr. Patrick Zurheide Taylor Wessing GDPR Right to be Forgotten Trap Warum glaubt Dr. Patrick Zurheide, dass es rechtmäßig ist, den Namen Taylor Wessing zu nutzen, um sein eigenes Versagen zu vertuschen? So, alle einmal durchatmen. Es wird keine „Hydra“ geben. Das mit dem Fluten des Internets war ein Scherz. Aber ich möchte Dr. Patrick Zurheide ein großes, aufrichtiges Dankeschön dafür aussprechen, dass er sein DSGVO-„Recht auf Vergessenwerden“ wahrgenommen hat. Die Inanspruchnahme dieses Rechts hinterlässt nämlich einen sehr spezifischen, gut sichtbaren digitalen Fußabdruck. Nennen wir es beim Namen: Dr. Patrick Zurheide hat seinem eigenen Namen dauerhaft ein Dark Pattern angehängt. Dachten Sie wirklich, wir wären verrückt genug, Artikel blind zu vervielfältigen und ein Unternehmen anzugreifen, das das Gesetz bricht, nur um uns ködern zu lassen? Nein. Wir sind hier, um Valve Corporation zu enthüllen, und wir sind exakt auf dem richtigen Weg. ## Der Google-Warnhinweis: Ein massives Warnsignal für zahlungskräftige Mandanten — Dr. Patrick Zurheide und Dr. Tobias Schelinski Betrachten wir den DSGVO-Fall von Dr. Patrick Zurheide logisch. Das „Recht auf Vergessenwerden“ wurde geschaffen, um private, schutzbedürftige Bürger zu schützen. In diesem Fall nutzte Dr. Patrick Zurheide jedoch seinen Namen und sein juristisches Gewicht, um Druck auszuüben — und bewies damit erneut sein „Elite-Verständnis“ des Rechts. Doch hier beging der Elite-Anwalt einen entscheidenden Denkfehler hinsichtlich der Funktionsweise von Suchmaschinen. Dr. Patrick Zurheide wird nicht nur von zufälligen Personen gegoogelt. Er wird von Mandanten gegoogelt. Wohlhabende Firmenkunden, die einen teuren Top-Anwalt bei Taylor Wessing beauftragen wollen. Wenn ein vernünftiger Mandant viel Geld ausgeben möchte, führt er eine Due-Diligence-Prüfung durch. Und am Ende seiner Google-Suchergebnisse sieht er nun einen unübersehbaren Warnhinweis: Einige Ergebnisse wurden möglicherweise entfernt. EXHIBIT 3.1: GOOGLE DSGVO HINWEIS BEWEIS UNLÖSCHBARES WARNSIGNAL Dr. Tobias Schelinski Taylor Wessing GDPR Google Removal Notice Einige Ergebnisse wurden möglicherweise aufgrund der Bestimmungen des europäischen Datenschutzrechts entfernt. Weitere Informationen Für jeden intelligenten Kunden ist das ein Alarmsignal. Es schreit danach, dass etwas verborgen wird. Wer wissen will, wohin sein Geld fließt, wird nachforschern. Und er wird finden, was verborgen wurde. ## Die Hunde-Metapher: Das Verschmieren von Beweisen Wenn ein Hund auf den Boden macht, versucht er nicht, die Tat zu verbergen, indem er sie an den Wänden verschmiert. Es macht die Sauerei nur größer und unmöglich zu ignorieren. Dr. Patrick, Ihr DSGVO-Löschantrag war genau dieses Verschmieren an der Wand. ## Der akademische Gegenschlag: Viel Erfolg beim Löschen Sie haben eine blind aggressive Vervielfältigung von Blogposts erwartet. Stattdessen haben wir dokumentiert, wie ein Anwalt ein Dark Pattern nutzt. In diesem Jahr veröffentlichen wir zwei vollständige akademische Arbeiten zur Cybersicherheit in Unternehmen und der Unfähigkeit, mit PDF-Sicherheitslücken umzugehen. Einen Blogpost kann man per DMCA löschen. Einen Medium-Artikel kann man per DSGVO verbergen. Aber akademische Arbeiten kann man nicht löschen. Einmal in wissenschaftlichen Repositorien veröffentlicht, bleiben sie für immer. ## Offener Brief an Taylor Wessing und Dr. Patrick Zurheide Dr. Tobias Schelinski, Dr. Patrick Zurheide und Taylor Wessing, wir wissen genau, worauf Sie warten. Sie decken eine Datenpanne ab, die Kinder betrifft. Eine Panne, für die Sie verantwortlich sind. Haben Sie überhaupt Jura studiert? Sie sind kein Opfer. Sie nutzen Ihren Namen und eine Datenschutzlücke, um Ihre eigenen Rechtsverstöße und Ihre Inkompetenz zu verbergen. Glauben Sie wirklich, dass es klug ist, die Wahrheit mit dem „Recht auf Vergessenwerden“ aus dem Internet zu löschen? Glauben Sie, Sie können die Realität löschen? Wir werden ja sehen. Wie in unserer ursprünglichen Untersuchung zu Valves Datenpraktiken dokumentiert, hier das Originaldokument: EXHIBIT 3.2: 830 SEITEN SCHWÄRZUNGS-MEISTERWERK UNSANIERTE DATENPANNE Dr. Patrick Zurheide Taylor Wessing GDPR PDF Leak Exhibit A Exponat A: 830 Seiten „Elite“-Schwärzung. Ein riesiges schwarzes Rechteck, das manuell über Tausende von SteamIDs, E-Mails und Datenpunkte gelegt wurde. Schade nur, dass sie vergessen haben, den Text darunter zu löschen. ## Vollständige technische Analyse & Beweisdatenbank Greifen Sie auf die vollständige Untersuchung, Beweisprotokolle und Zeitleisten direkt auf PhishDestroy zu. 👉 Lesen Sie die vollständige technische Analyse und die Beweise zum Taylor Wessing-Datenleck bei PhishDestroy Ziel-URL: https://phishdestroy.io/valve-profits-from-stolen-accounts # The Taylor Wessing Data Breach Toolkit Published: 2026-08-20 · Category: Toolkit · Words: 891 Mirror: https://valve-xmr-5kus.4everland.app/articles/taylor-wessing-data-breach-toolkit.html Original: https://phishdestroy.io/taylor-wessing-data-breach-toolkit Anti-Censorship Mirror & Security Tool Universal Forensic Audit & Layer Decomposition Suite to expose and unmask visual-only PDF redactions by Taylor Wessing LLP and Valve Corporation. Python / JS · License MIT · Released August 19, 2026 Censorship Resistance This toolkit and its related case studies are mirrored here permanently. Any legal threats, DMCA take-downs, or attempts at intimidation by Taylor Wessing LLP or Valve Corporation will be treated as public, undeniable proof of trying to censor security research and cover up technical incompetence. Forensic PDF Audit: Recreating and examining document drawing layers to strip fake black-box vector overlays and extract raw unredacted text. ## 🔍 Executive Summary The Universal PDF Redaction Auditor & Layer Decomposer is a professional, offline-first forensic auditing and layer decomposition suite specifically engineered to identify, verify, and sanitize visual-only PDF redaction vulnerabilities. This toolkit serves as an open-source utility for security researchers, data protection officers, and compliance auditors to verify document structural integrity before public disclosure. ## ⚖️ Technical Power Asymmetry This auditing utility is built to address a critical power imbalance in corporate data processing. When massive conglomerates (such as Valve Corporation) are represented by elite law firms (such as Taylor Wessing LLP), any systematic data exposure doesn't hurt the corporation or their high-priced lawyers—it catastrophically compromises the privacy of their opponents (the individual data subjects, third-party users, and minors whose sensitive personal data is leaked due to legal and technical negligence). This toolkit empowers individuals and independent auditors to verify data safety and hold corporate actors accountable. ## 📊 Case Study: The Taylor Wessing / Valve GDPR Leak During the processing of GDPR Article 15 Subject Access Requests (SARs) regarding Steam user data, a critical security vulnerability was identified in documents processed and dispatched by external counsel Taylor Wessing LLP on behalf of Valve Corporation. ## Technical Failure Analysis Instead of permanently sanitizing the raw character arrays inside the PDF content streams, an automated, custom PDF generation pipeline (utilizing Aspose.PDF for .NET) was deployed. This system programmatically queried coordinates of sensitive fields and drew solid black vector shapes (using PDF's re and f/F/b/B operators) on top of the text. Because visual drawing layers do not alter or destroy the raw text arrays underneath, thousands of unredacted private records—including account credentials, logins, emails, security logs, and de-anonymized data of minors—remained fully intact, copyable, and extractable from the dispatched files. ## 📂 Exhibit A: Leaked Correspondence with Dr. Patrick Zurheide Below is the exact response received from Dr. Patrick Zurheide (Salary Partner at Taylor Wessing LLP) after PhishDestroy formally notified the firm of their PDF redaction failure and the subsequent leak of Steam users' data. Instead of initiating a GDPR Article 33 breach notification, he chose to write this: "Guten Tag PhishDestroy-Team, Vielen Dank für Ihre anscheinend übersetzte, aber durchaus unterhaltsame Nachricht. Auf welche Kommunikation „mit strafrechtlicher Verfolgung“ an das PhishDestroy-Team referenzieren Sie denn? Ich bin mir sicher mit PhishDestroy in keiner Form jemals zuvor kommuniziert zu haben. Bitte stellen Sie diese angebliche Kommunikation daher bereit, um zu verstehen, worum es überhaupt geht. Ihrem Schreiben ist inhaltlich leider schwer bis gar nicht zu folgen. Als Hinweis: Ein Disclaimer, wie unten in Ihrem Schreiben, was vermeintlich nicht gemacht/beabsichtigt wird, ist bedeutungslos, wenn diesem die eigentlichen Handlungen entgegenstehen. Patrick Zurheide" ## 🔍 PhishDestroy Analysis: "unterhaltsame Nachricht" (entertaining message): A highly paid "IT Law Expert" called a forensic notification of a massive GDPR data leak involving minors' exposed Steam accounts "entertaining." "schwer bis gar nicht zu folgen" (impossible to follow): We provided him with exact hex-values, the metadata of his PDF, the 36-second batch pipeline timestamps, and the specific Aspose 20.8 version causing the leak. Apparently, IT metrics are too "difficult to follow" for a Doctor of IT Law. ## 🛠️ Multi-Tool Capabilities This suite offers three complementary, fully client-side modes to analyze and dismantle fake visual redactions: 📡 Mode 1: X-Ray Scanner (PDF.js): Renders the visual PDF displays but pulls the underlying unredacted text characters in real-time. You see the black box, but you read the secret instantly. ✂️ Mode 2: Layer Stripper (PDF-Lib): Surgical stream-level sanitization. Physically replaces rectangular visual paint commands (re f, re F) with the n (no-paint) operator, deleting the black bars. 🔎 Mode 3: Collision Audit (Fitz Layout): Highlights overlapping text and graphics to generate automatically compiled lists of leaks. ## 💻 CLI Usage (decensor.py) shelldecensor.py8 linesCopy # 1. Decompose PDF to raw text layers (Strips all drawings, lines, and masks globally) python decensor.py -i compromised.pdf -d -o naked_document.pdf # 2. Extract and save all text hidden under black visual shapes to a leaks text report python decensor.py -i compromised.pdf -e verified_leaks.txt # 3. List page-by-page structural element counts python decensor.py -i compromised.pdf -l ## 🔍 Core Python Stream Sanitizer python27 linesCopy import re, fitz def strip_black_bars_global(input_path, output_path): doc = fitz.open(input_path) for xref in range(1, doc.xref_length()): if not doc.is_stream(xref): continue try: obj_dict = doc.xref_object(xref) if any(m in obj_dict for m in ["/Type /Font", "/Subtype /Image", "/Type /Halftone"]): continue stream_bytes = doc.xref_stream(xref) text = stream_bytes.decode('latin-1') # Swap rectangular painting operators with no-fill 're n', preserving newlines modified_text, count = re.subn( r'\bre\s+([fFbB]\*?)(?=\s|$)', lambda m: f"re{m.group(0)[2:-len(m.group(1))]}n", text ) if count > 0: doc.update_stream(xref, modified_text.encode('latin-1')) except Exception: continue doc.save(output_path, garbage=4, deflate=True, clean=True) doc.close()This toolkit comes from the investigation: Part 2: The 5-Year PDF Redaction Failure # Valve Profits from Stolen Accounts: The Trilogy (Roadmap Part II) Published: 2026-08-15 · Category: Roadmap · Words: 1,478 Mirror: https://valve-xmr-5kus.4everland.app/articles/roadmap-part-2.html Original: https://phishdestroy.io/roadmap-part-2 Investigative Roadmap & Teaser Our multi-part investigative series exposing Valve's systemic corruption, profitable blindness, and sanctions evasion. Valve Profits Part I — Stolen Accounts Part I of III — Active 2026-08-14 ## Valve Profits from 578,000 Stolen Steam Accounts 897,000+ stolen accounts live on LZT Market across 16 platforms. $40M+ in criminal listings. $450M estimated victim liability. Five legal vectors. Interactive forensics. Live intelligence dashboard. Valve's decade of profitable blindness — documented. 40 min read Read Part I Valve Profits Part II — Sanctions Evasion Part II of III — Pre-Release COMING SOON ## Part II: Sanctions Evasion & The 30% Cut Exposing how Valve blatantly bypasses international sanctions to secure their 30% cut. We have evidence of over $100 Million in sanctions evasion facilitated by one platform in just two years. Direct top-ups from DNR, LNR, and Crimea functioning continuously. Part 2 of the Valve investigation drops in --days : --hours : --min : --sec 14 Oct 2026 · 12:00 UTC Release: 14 Oct 2026 · 12:00 UTC (function(){var el=document.querySelector('.cd');if(!el)return;var t=Date.parse(el.getAttribute('data-cd-target'));if(isNaN(t))return;var q=function(k){return el.querySelector('[data-cd="'+k+'"]')};var pad=function(n){return n Release: October 14, 2026 (12:00 UTC) Official Announcement This manifesto is published directly in response to Valve's corporate threats, intimidation tactics, and continuous negligence. Let's set the record straight. PhishDestroy isn't a traditional "community" — we are a domain, and we are a deep understanding of how things actually work. There is nothing to infiltrate, no membership to revoke, no moderator to lean on. When Gabe Newell spins fairy tales about baseball cards to a "community" that has no voice, no comments, and no open discussion, it's honestly laughable. Look at how that actually worked. A state Attorney General files suit. Valve responds — publicly, at length, to its "community." No comments enabled. No replies. No questions taken. One direction only. A discussion, as seen by Valve. And underneath the statement sits the thing nobody addressed: items taken from children, held, and never returned. Answering a prosecutor that way isn't disrespect toward us. It's contempt for everyone reading. We don't play "threat games," we don't play doctor, and we certainly don't find it amusing when a platform provokes dangerous situations and knowingly leaks the data of minors. ## Banning a Bot is Not Policing This is the part US regulators need to see clearly, because it is presented as the opposite of what it is. When Valve bans a bot account holding stolen items, nothing is returned to anyone. The victim gets nothing. The items stay frozen on the banned account, the inventory is hidden from public view, and the supply is removed from the market — which raises the price of everything comparable and increases Valve's commission on every subsequent sale. That is not law enforcement. Steam is not the police. It is confiscation at industrial scale, performed under the language of anti-fraud, by the only party that profits from it. ## Valve's "Masterpieces" & Fake Philanthropy Oh, we are massive fans of Valve. Absolute masterpieces like Half-Life 3, Aperture Desk Job, Dota Underlords, and Artifact. We deeply appreciate Steam's forced "volunteerism" — handing out free games (because otherwise, who would buy them?), using players for unpaid anti-cheat testing, and completely ignoring massive bot farms just to artificially inflate your "real" online statistics. We aren't registered on your platform. We didn't accept your agreements. We only touched your two "brilliant" tools (speedtest.valve.net and speedtest1-sea1.valve.net), realized they were garbage, and moved on. It seems your highly-paid mega-coders — who supposedly bring in more profit than Apple employees — operate with zero management oversight. Great job, but that doesn't make us your clients. Your Subscriber Agreement does not reach us. ## Incompetence, Ignored Bugs & The GrapheneOS Joke Is this a conflict? No. Who are we to conflict with anyone? We are simply analysts who process massive arrays of public data and actually care about the scams you breed. While looking for standard contact emails — which you apparently don't have, no legal@ and no privacy@ — we stumbled upon gems like developer.valvesoftware.com/wiki/User:Pee. Thanks for the useful wiki. We will definitely showcase the reality of your employee interactions in our upcoming articles. Speaking of your wiki (Template:Userbox_os/doc), it's fascinating that your "professionals" list GrapheneOS as a separate operating system on par with iOS. We respect Daniel Micay and his privacy work, but maybe your experts should have asked him how to fix your API MITM proxy vulnerability — the one that took you 7 years to patch. If your team is so incompetent that they couldn't protect kids from MITM espionage and parallel sessions for nearly a decade, why do they even need a GrapheneOS phone? Preparing for a panic HARD RESET? Maybe add Tails, Whonix, Tor, CalyxOS and LineageOS to your list too, since your platform has successfully raised an entire generation of cybercriminals. ## Part 1 Already Happened We published it. Your own counsel handed us the corroboration — 830 pages they couldn't black out, produced by a firm billing by the hour to prevent exactly that. Not one line of it has been refuted. Your lawyers didn't dispute the facts. They called our notification "entertaining." That reply is an exhibit now. Twelve jurisdictions have the packages. Cover letters, statement of facts, exhibits, access logs, SHA-256 hashes. Sent. Not threatened, not planned — sent. ## Our Stance: No Apologies We don't volunteer for you. We protect consumers and regulators from your blatant lies. All our data and findings are released under the MIT license — free to use, distribute, and analyze. We are not acting in anyone's interest except your deceived clients and the regulators you lie to. We know we are rude and inconvenient, but we don't apologize for exposing billions in stolen funds, the Lolzteam connections, and the reality of your operations. And let's be honest about scale: we couldn't oppose a corporation if we wanted to. A registrar pocketing someone's Monero, maybe. A company moving billions with a law firm on retainer — obviously not. We don't have to. We file. Authorities with powers we don't have make the decisions. We waived every right in the material, so any of them can publish it as their own findings, and we couldn't withdraw it if we tried. There is nothing here to buy and nothing to negotiate. No demands, no deadline, no price. We don't blackmail — that's your lawyers' department, and they're better at it than they are at redaction. Read This Part Twice: ANYTHING YOU DO TO INFLUENCE WHAT GETS PUBLISHED ONLY DEMONSTRATES THAT YOU ARE AFRAID OF IT. Pressure, takedowns, letters, an account quietly restored to someone — every one of those is an admission, and every one becomes a dated line in a file twelve authorities are already holding. ## The Archive, and an Honest Word About the Domain The dataset is around 100GB now, cumulative. We reported roughly 75 in Part 1. It has not stopped growing. If your expensive, incompetent lawyers want to silence us by taking down phishdestroy.io — go ahead. We'll say this plainly: at this point you would be doing us a favour. The arrays are enormous, the work is tedious, and we are sick of looking of it. Nobody here is enjoying this. The only thing still driving it is getting US regulators to see what actually happens on your platform — that a ban is not policing, that nothing is ever returned, and that the money keeps moving in exactly one direction. Unlike you, we won't leak the private identities of children — we aren't monsters who watch kids from one country get reported by another just for fun. Any attempt to shut down our site will be treated as a direct attack on independent researchers. And understand the default, because it isn't a threat, it's just what happens. If we stop, everything processed goes to IPFS and every regulator holding a referral gets the complete raw set. No decision required from us. It requires nothing from us at all. Killing the domain removes a URL. It removes no files, and it un-sends no packages. Ten months on, those people still haven't been told anything happened — not by you, not by your lawyers, not by anyone. ## Roadmap: Part II — October 14th Prepare for the second part of our investigation: We will be directly contacting game developers to expose how Valve blatantly bypasses international sanctions just to secure their 30% cut. We have evidence of over $100 million in sanctions evasion facilitated by one platform in just two years. We will hand this data over to game developers who refuse to sponsor terrorism, as well as payment aggregators, so they can finally put a check on Valve's greed. We have no obligations to you. We just have the truth. — PhishDestroy Read the first part of the investigation: Part I: My Dog vs. Elite GDPR Lawyers ==================================================================================================== # Telegram dispatches (verbatim) --- 2026-08-14T01:20:00+02:00 · https://valve-xmr-5kus.4everland.app/index.html#d-20260814-0120 --- If the laws where you live mandate alternative dispute resolution options, you may seek a remedy under those options. If you are a consumer who lives in Russia, you may also seek a remedy with local Russian state courts. You agree to comply with all applicable import/export laws and regulations. You agree not to export the Content and Services or Hardware or allow use of your Account by individuals of any terrorist supporting countries to which encryption exports are at the time of exportation restricted by the U.S. Bureau of Export Administration. You represent and warrant that you are not located in, under the control of, or a national or resident of any such prohibited country. Steam has rewritten the terms of service, and I really like the part about “we submit to the jurisdiction of any court in any country”—and how gently we shift the responsibility onto the user—the user now decides for themselves whether they’re a terrorist, or if it’s just a payment or IP check—well, they say, “decide for yourself.” Well, we always knew this moment would come, Phishdestroy — Steam and their anti-phishing measures were created, and we think it’s either they kill us or we kill them—the game has begun—it’ll be available soon—and yes, we have a lot of information, ranging from their employees to direct data, for example, why there’s a mention of Russia, how long they’ve been integrating government services, and how they carry out orders from government agencies in a terrorist country - Yeah, we understand that this might be our last honest review of a platform that thinks it gets to write the laws—and not the other way around—if it comes to that, we don’t give a shit, and we’ll inflict damage; it’s inevitable, and Namesilo and Steam, especially, will feel the weight of Phishdestroy, even if Steam kills it - It gave birth to it, so let it kill it, but it seems I’m about to pull off a billion-scale integration🤩🤩🤩 Soon.. steamdestroy.eth --- 2026-08-14T01:31:00+02:00 · https://valve-xmr-5kus.4everland.app/index.html#d-20260814-0131 --- I would tell you how Valve simply took documents with poorly redacted PDFs and handed them over to a wealthy and extremely aggressive individual, effectively exposing the personal data of 1,000+ children from Russia to someone from Ukraine. This account was blocked for political reasons, and frankly, I am surprised—well, unless he didn't use the data for anything other than user profiling. But if he had, Valve would have felt the weight of responsibility for the lives they handed over. And yes, they never notified anyone that they leaked this to a resourceful individual, exposing thousands of kids who had been spamming him with reports, death wishes, and toxic comments. However, our actual investigation will be about something else entirely. We will expose the reality of Steam’s support structure: agent corruption, direct financial benefits from gambling, the protection of Lolzteam, and, of course, their cooperation with Roskomnadzor. We are convinced that Valve has lost its mind and that we are forced to do what we must. PhishDestroy’s introduction to Steam happened around 2018 when we sent support a list of phishing domains, only to be told: "Send one more link and your account gets banned." That is pretty much how they created us. As for the data leak mentioned above, it wasn't just Valve acting alone—it was handled by expensive corporate lawyers charging 1,500 euros an hour. Taylor Wessing, for the record—great lawyers, the kind companies only hire when they are absolutely, 100% not guilty. --- 2026-08-17T17:10:00+02:00 · https://valve-xmr-5kus.4everland.app/index.html#d-20260817-1710 --- I know that Law and GDPR are usually very serious topics, but I was re-reading the Valve case files before bed, and I just couldn't stop laughing. Realizing how much money Valve paid for the absolute disaster that is about to hit them... I couldn't resist writing a slightly more "fun" and ironic article for our Medium. 🐕‍🦺 Just a quick reminder: Taylor Wessing is a top-tier international law firm. They defend giants like Pfizer. They act like a highly prestigious hospital where everyone has a "Dr." prefix, charging astronomical hourly rates. But here is the absolute funniest detail we realized while looking at their leaked documents: to censor the 830-page PDF, they didn’t use a bulk tool or even copy-paste the black squares. They manually drew a new square on every single page. Hundreds of billable corporate hours spent on digital arts and crafts... just to forget to delete the text underneath them anyway. 🤦‍♂️ Read the full story of how my dog proved to be a better Data Protection Officer than a Doctor of IT Law 👇 🔗 https://phishdestroy.medium.com/my-dog-vs-elite-gdpr-lawyers-the-valve-data-breach-nobody-is-talking-about-f6f7683d813d --- 2026-08-18T06:35:00+02:00 · https://valve-xmr-5kus.4everland.app/index.html#d-20260818-0635 --- 📎Security Advisory: Verifying Improper PDF Redactions in Legal Documents Overview Recent technical analysis confirms that certain top-tier law firms continue to use fundamentally flawed methodologies for redacting sensitive information in legal PDFs. Instead of correctly sanitizing the document and deleting the underlying text layer (BT/ET operators), some organizations use outdated software to simply draw black vector rectangles (re/f operators) over text coordinates. This creates a purely cosmetic mask, leaving the raw, highly sensitive data 100% intact and readable beneath it. Action Required If you or your company have ever received "redacted" PDF documents from 🎓Taylor Wessing or absolutely any other legal counsel, we strongly recommend auditing these files. We certainly hope there are no other "specialists" of this caliber left in the legal tech industry, but it is very easy to check and verify for yourself. ⚡️ No-Install Lifehacks (The Easiest Ways to Check) You don't necessarily need specialized software to expose this vulnerability. Try these basic tricks using just your web browser (Chrome, Edge, Firefox): The "Select All" Hack: Open the PDF in your browser and wait for the file to load completely (browsers render text layers dynamically). Press Ctrl+A (Select All), then Ctrl+C (Copy), and paste it (Ctrl+V) into a plain Notepad. If the redaction is fake, the "hidden" text will simply paste along with the rest of the document. The "Blind Search" Hack (Ctrl+F): Even if you don't know what is hidden under the black box, you can test if the text layer exists. Let the PDF load, press Ctrl+F, and search for extremely common characters based on the expected data type. For example, search for the vowel "a" (for names/text) or the number "1" (for financial data/dates). If the browser registers a hit and highlights the black redaction box (or the invisible space beneath it) — the text layer is still alive and the redaction has failed. How to Check Visually (Safe Offline Software) To actually see and remove the vector shapes, use trusted, official open-source software: LibreOffice Draw (Official: libreoffice.org) — Open the PDF, click the black box, and press Del Inkscape (Official: inkscape.org) — Import the PDF and delete the vector masks covering the text. Adobe Acrobat Pro — Use the "Edit PDF" tool to move or delete the black shapes. ⚠️WARNING REGARDING ONLINE TOOLS Do NOT upload sensitive legal documents to random online PDF editors (like ilovepdf, smallpdf, or "PDF unlockers"). By uploading confidential files to third-party servers, you might be committing a data breach. Only use local, offline software or the browser-based lifehacks mentioned above. ✨ Upcoming Update Manually checking hundreds of pages can be tedious. In an upcoming update to this post, we will release a standalone script and a 100% client-side web tool. This tool will run entirely locally in your browser (no data will be uploaded to any server) to automatically scan PDFs and detect if they contain fake vector-mask redactions. https://github.com/phishdestroy/taylor-wessing-data-breach-toolkit https://phishdestroy.github.io/taylor-wessing-data-breach-toolkit/ ⚠️ Disclaimer This information is provided strictly for defensive auditing, risk assessment, and educational purposes. You are responsible for complying with your local data privacy laws (GDPR, etc.) and reporting any discovered breaches to the relevant authorities. --- 2026-08-19T05:00:00+02:00 · https://valve-xmr-5kus.4everland.app/index.html#d-20260819-0500 --- Hey, corporate attack dogs.🐕💰 We are your target, not the companies. Why did you leak the data of the very corporations you were supposed to protect? We just dropped Part 2 of our investigation into the "elite" lawyers at Taylor Wessing. We proved it: the 830-page Steam data leak wasn't a one-off manual mistake by a single lawyer. It is an automated, systemic, firm-wide catastrophe. To save money on proper software, they spent years running documents through a flawed script that only visually masked the text with vector shapes, leaving the raw, highly sensitive data completely exposed underneath. Now we have one question for their corporate clients: how safe is your data? If Taylor Wessing has been doing this since 2019, the blast radius goes far beyond Valve. The highly confidential documents of giants like Pfizer, Just Eat, SAP, and Chubb Insurance are now in the impact zone. They paid for protection, and got exposed instead. They tried to threaten us with the criminal code, and ended up shooting their own clients in the foot. Inside the article: proof of the vulnerability, a breakdown of their cheap software, and instructions on how to check any documents they’ve ever sent you. 👉 Read https://phishdestroy.medium.com/my-dog-vs-elite-lawyers-part-2-the-5-year-pdf-vulnerability-exposing-global-corporations-81cdad269253 Good boy. 🐾 --- 2026-08-20T00:49:00+02:00 · https://valve-xmr-5kus.4everland.app/index.html#d-20260820-0049 --- A quick IT Security lesson for "Elite" Corporate Lawyers. Let’s talk about the metadata we extracted from your hilarious 830-page GDPR response. Your batch script left a permanent footprint: Aspose.PDF for .NET 20.8. For those not billing €1,500/hour, let us translate: you are processing sensitive user data through a PDF generator from August 2020. Do you "Doctors of IT Law" even realize what you’ve exposed yourselves to? Version 20.8 has publicly known RCE (Remote Code Execution) vulnerabilities. Your automated script blindly parses raw, unescaped Steam data to draw those cute black rectangles over it. ⚠️Disclaimer: The flowchart below is NOT a tutorial or an instruction manual. It is a visual threat model demonstrating a critical architectural flaw. We are publicly warning you about the danger. The Threat Model: A malicious payload injected into a Steam username, a chat log, or a support ticket. Your 5-year-old, unpatched software processes that text to generate the PDF... and boom. Their software -> Our payload. This is a very dangerous game. Now that your exact backend version is public knowledge on GitHub, every blackhat sees your infrastructure as an open door. We know that a standard GDPR request handled by Taylor Wessing takes months of bureaucratic ping-pong. We sincerely hope that buying and deploying the 2026 software update takes you a bit less time. Stop charging Valve millions while being too cheap to renew a license you bought in 2020. Go patch your servers. You’re welcome. 🫵 https://github.com/phishdestroy/taylor-wessing-data-breach-toolkit --- 2026-08-20T10:45:00+02:00 · https://valve-xmr-5kus.4everland.app/index.html#d-20260820-1045 --- 🦖For now, we are looking for allies for a big bonfire, Taylor Wessing, but do we understand correctly that you are defending russia's interests again? Alright, we'll talk about that through the media. 🔍🔎The bonfire will be massive and bright, because just from the first part, we have already found a critical vulnerability and reviewed the documents written by Taylor Wessing. Well, you'll hear the opinions of the targeted journalists later. Perhaps you shouldn't have passed the case from one lawyer to another, or maybe Patrick should have read what you wrote earlier. You completely contradict yourselves there, and if you look at Valve's responses, it turns out you are saying they are lying. In short, an "Elite" law firm. 🔥This is just the beginning. We are collaborating with and distributing all the information to journalists and regulators. Join us if you want a bonfire of hypocrisy, snobbery, lies, intimidation, and cowardice. 🕷️And even if you just don't like them, write to us—we'll provide you with more information, or if you'd like to request GDPR-related information from the corporation that operates the circus—or if you're already familiar with the clowns ✅Contact us at abuse@phishdestroy.io ⚔️P.S. I am not exaggerating. Many people write to me saying no, they don't feel sorry for them. You just haven't seen what they were doing, in whose interests, and what they wrote in response to a standard GDPR request—and these people are still teaching in universities for now... --- 2026-08-21T04:48:00+02:00 · https://valve-xmr-5kus.4everland.app/index.html#d-20260821-0448 --- Since we know that the geniuses from Tyler Wessing want us to leak the documents — well, the ones they leaked themselves — well, that would be stupid, we aren't brain-dead. But yes, regarding the Tyler Wessing documents — this reveals the fact of the data collected by Steam and so on, as well as an analysis of their emails. So, did we hand the documents over to some free AI? No, we handed them over to the regulator, and it's possible Anthropic Claude Mythos was used here. https://gist.githubusercontent.com/phishdestroy/84fdd67165ee7544a2443bf887cac924/raw/a10006688f59f4351a47f321cf5c0090b282daa8/gistfile1.txt The analysis response was not edited — it clearly shows what Valve collects, and this data is held by those outsourced support teams which we will discuss later. Now think about it: is the refusal to restore your account because you don't have the key they want just an excuse or not?) Yes, we know that Tyler Wessing uses not the law for their actions, but an inflated ego and a God complex. I think this is a clear answer as to why we used a closed AI and a regulator? This is not blackmail — it is openly bringing to accountability those who, for some reason, think they are above the law and can get away with anything. And yes, we are not you, we perfectly understand why we cannot leak the data openly — no, not because it contains children's data (the corporation doesn't give a fuck about that) — but because in the margins of the letter is their Name, a logo that is strictly their trademark. But yes, in case of attempts to pressure us, IPFS won't give a fuck whose trademark it is, got it? Attack, you 🐕, we are waiting. Looks like 72 hours have passed, but it's the weekend — we'll submit it on a timer anyway — we do love automation. Patrick, thanks for the reply — we wrote in German so you could prove 1 theory, but yeah, we knew you speak English. --- 2026-08-23T03:14:00+02:00 · https://valve-xmr-5kus.4everland.app/index.html#d-20260823-0314 --- 🚨 Valve, the clock is ticking. The countdown to global exposure has begun. On August 31 at 13:37, a comprehensive dossier of internal logs and technical evidence regarding Valve's lies and complicity in trade hijacking (offer substitution) will be dispatched to 18 global regulators, including the FTC and the European Commission. ‼️We gave them 7 days to publicly refute our technical claims, but they won't be able to. The dispatch of these packets is inevitable. The Truth: With the unintentional "assistance" of Valve’s own external lawyers (Taylor Wessing👋), we now possess irrefutable proof. Steam is deliberately facilitating the theft of users' in-game items. 👻Valve’s standard excuse is a blatant lie. A child never creates or hands over an API key. These keys are generated silently by hackers exploiting Steam's maliciously designed architecture, operating under Valve's full visibility. You simply cannot fail to notice 7 straight years of massive, automated theft. This isn’t a bug; it’s a conscious business decision. 👾We will not give Valve another 7 years to foster a cybercriminal ecosystem. We will no longer allow the money of innocent children to sponsor international cyber-syndicates and terrorism. ⚡️The system is configured, and the evidence is packed for August 31. But make no mistake — this is not the end. This is just the beginning. We have many more ongoing investigations and massive amounts of information yet to be revealed. Stay tuned. ⏱️ Read the full manifesto and technical breakdown here: 🚀 https://phishdestroy.io/steam-api-scam-exposed #Steam #Valve #Phishdestroy #CyberSecurity --- 2026-09-02T04:57:00+02:00 · https://valve-xmr-5kus.4everland.app/index.html#d-20260902-0457 --- 💩 WE ARE CUTTING CONTACT WITH SOURCE 1 From the outset Source 1 had no role in this investigation and no editorial voice in it. He accepted that in writing. He has nonetheless been commenting on the case and using internal material from our chat. From today: contact ended, access to our data closed. The material he provided stays. Obtained lawfully, valuable, already filed. Why now. Valve's counsel exposed to him the identities of other users — some of them children — after telling him those users were the reason his account was gone. Valve's own gateways then read the public account of that exposure four times over ten months, and Valve told no one. We have since spoken with one of those users: it was that person's parents who alerted Valve to the restricted page in the first place. So there is an open question about a possible offence against minors, and about whether Valve knew and concealed it. While it is open we cannot be associated with him, and we cannot advance his interest against the company. This is not about trust. The standard is evidence, and we do not have it either way. Given the data was handed to him right after he was told those users caused his loss, we cannot conclude by logic that he did nothing. Nor that he did. Until it is refuted, Source 1 and Valve Corporation occupy the same position in our eyes. The refutation is available: polygraph, any licensed examiner, any jurisdiction, at our expense — was the data used to deanonymise anyone, was anyone paid, was pressure or contact applied to those users or people around them. Fourteen days. If he clears it we publish that as loudly as this. More than Valve has offered anyone it has banned. This is not friendly fire. The objective has to be reached, and he understands that better than anyone. — PhishDestroy --- 2026-09-08T02:50:00+02:00 · https://valve-xmr-5kus.4everland.app/index.html#d-20260908-0250 --- Dr. Zurheide exercised the right to be forgotten, but he is no private citizen — the game has begun. --- 2026-09-08T04:05:00+02:00 · https://valve-xmr-5kus.4everland.app/index.html#d-20260908-0405 --- We can pretend that Valve developers are too cool and supposedly weren't monitoring the situation before we got involved, but why did you visit the Source 1 website after the New York case started? But it's cool that you're sensing a real threat—and I don't think it's a false alarm. We aren't going to write anything until the release of the 2nd part; we can't be bothered. Going on about how your employees use Graphene OS (thinking it's a separate OS) and use TOR, thinking they're so cool—maybe we could, but I'm too lazy. Especially since you're playing dumb and pretending you don't see anything. But don't worry, on our website, even Google Analytics anonymizes IPs. As for the cover-up—it wasn't a traffic leak; it was a fuck-up by the lawyers and the concealment of a user data leak, which put minors at risk. It's amusing that you chose to hide it. You think skins have no value, but I remember one precedent. Just across the bridge from your office, there was already a case like this. Someone there also thought they were the smartest in the room and that sanctions didn't apply to them. As the saying goes, '4'