Valve Apologizes For Steam's Christmas Malfunction, Says It Affected 34,000 Users
Valve has finally apologized for last week's Steam Christmas disaster, explaining in a lengthy statement today that the issues stemmed from a Denial of Service attack and wound up exposing the information of around 34,000 users.
Context & Ripple Effects
Valve's apology closes out a week of rolling statements on the Christmas Day incident: the company had already confirmed the caching bug that let Steam users view other accounts' pages was fixed and that no unauthorized actions were taken on accounts. Today's statement reframes the episode as the downstream effect of a Denial of Service attack rather than an isolated code failure.
It also lands on top of a rough security year for Steam — July's password-reset exploit compromised accounts over several days, and December's trading-security tightening came amid 77,000 monthly account hijackings. The apology is less about one bug than about Valve's accumulating record of access-control failures.
First-order effects
- Roughly 34,000 users had personal information exposed during the Christmas outage, and Valve's statement now defines the blast radius and assigns cause to the DDoS attack.
Second-order effects
- Each successive disclosure forces Valve to spend engineering capacity on hardening Steam against attacks that target availability precisely because so much value — libraries, inventories, tradeable items — sits behind a single login.
Third-order effects
- If the 2015 pattern holds — exploit, hijacking wave, caching breach, apology — pressure builds on Valve to move from patch-by-patch responses to systemic account-security architecture, with user trust in hosted game libraries as the stake.
The trend: Steam's 2015 security incidents trace a widening gap between the platform's role as custodian of players' digital property and the access controls protecting it.