Report: 13TB of Steam Data Leaked After Users Access Publicly Accessible Endpoint
A massive data leak involving 13 terabytes of historical Steam data, including beta builds and pre-release assets, has surfaced online following access to a publicly accessible endpoint.
A massive data leak has exposed approximately 13 terabytes of historical Steam data, containing files and beta builds uploaded between 2003 and 2013. According to reports, the leak—dubbed "the Steam2 leak" by users on the social media platform X—references the older name of Steam's server infrastructure before it transitioned to the modern SteamPipes system in 2013.
The exposed data allegedly features early versions, builds, and screenshots of various Valve titles, including Left 4 Dead 2, Portal 2, and unreleased projects like Half-Life 2: Episode 3. Beyond Valve's own catalog, the data dump reportedly contains beta builds and files from other major publishers and developers, such as BioWare and Electronic Arts' Dragon Age: Origins, alongside Rocksteady and Warner Bros. Games' Batman: Arkham Asylum.
X user "Gabe Follower" shared screenshots from the data set and claimed that there was "no hacking" involved in acquiring the information. Instead, the data was reportedly visible through a publicly accessible endpoint, though the exact nature of that endpoint remains unclear. Sources speaking to Ars Technica suggested that the breach might not have originated directly from Valve, but could instead involve third-party servers that previously gathered data from earlier leaks.
While the contents provide a unique historical look at the early development phases of several celebrated titles, the incident raises security concerns regarding third-party data exposure. The full extent of sensitive information belonging to external publishers and the potential long-term ramifications remain uncertain. Game Developer has reached out to Valve for comment regarding the incident.
Sources
- Game DeveloperEstablished publication · recorded Aug 31, 2026Report: 13TB of Steam data leaked after users access 'publicly accessible endpoint'
