HackingData ExfiltratedDelayed DiscoveryPIICREDENTIALSFINANCIAL_ACCOUNTLowActive
US VALVE CORPORATION
bd_5d1139df452962f0 · schema v1 · pii pii-v1
Full breach record for US VALVE CORPORATION →Valve Corporation disclosed a network intrusion into Steam forums discovered on November 6, 2011. The breach involved unauthorized access to a database containing user names, email addresses, and encrypted billing/credit card information from 2004-2008. Valve engaged outside security experts and the FBI. No evidence of encryption compromise or credit card misuse was found.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-22302
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 8, 2012
- Raw hash
- 08b8de14b3bcfdb034c50568b7b210ecfacc2f2ddac6cf5543f9199ca0d99b91
Reporting entity
- Name
- US VALVE CORPORATIONnorm: us valve
- Domain
- steampowered.com
Victim entity
- Name
- US VALVE CORPORATIONnorm: us valve
- Domain
- steampowered.com
Incident
- Discovered
- Nov 6, 2011
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIICREDENTIALSFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Working with the Seattle FBI office
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 13 weeks(94 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.