Someone left the door to a decade of Valve’s history wide open, and about 12 terabytes of it just walked out.
On August 29, 2026, a file dump nicknamed the “Steam2 Teraleak” started circulating online. It’s one of the biggest single leaks in PC gaming history, at least by size. Every gaming outlet has a version of this story right now, and a lot of them are blending it together with two other Steam-related security stories from this month that have nothing to do with it. So here’s the version that actually separates what happened from what didn’t, and tells you whether you need to do anything about it.
A 12TB archive of old Valve game files, nicknamed the Steam2 Teraleak, surfaced online after a legacy content server was found sitting open with no password. It contains early builds of Portal 2, Left 4 Dead, and Counter-Strike: Global Offensive from 2003 to 2013. It does not contain your Steam password, email, or any personal account data.
What Actually Happened
The leak traces back to Steam2, the file-delivery system Valve used to distribute games from roughly 2003 until 2013, before switching over to SteamPipe, the infrastructure that still runs Steam today. Steam2 packaged content using older formats called GCF (Grid Cache File) and NCF (No-Cache File). When Valve migrated to SteamPipe in March 2013, the old Steam2 servers apparently just kept running somewhere in the background, quietly holding a decade of build history that nobody was watching anymore.
Valve-focused researcher Gabe Follower was the first to flag it publicly on X. His explanation cuts straight to the point: nobody hacked anything. Someone simply found an old Valve server sitting open on the internet, no password, no login wall, and downloaded everything on it. He was blunt about where the blame sits, too, calling it a Valve problem rather than a hacker’s achievement.
In plainer terms: no breach, no exploit, no stolen credentials. If finding an unlocked door counts as hacking, so does reading a newspaper someone left on a park bench.
What’s Actually Inside the 12TB
The archive covers thousands of Steam depots from 2003 to 2013, spanning Valve’s own catalog and the third-party publishers who distributed through Steam during that window. Data miners are still working through it, because 12TB of mostly uncompressed game data takes real time to sort. So far, the standout finds include:
- An early Portal 2 build from around July 2009 โ playable, years before release.
- A June 2008 build of Left 4 Dead, with a different HUD and voice lines that never made the final cut.
- An early Counter-Strike: Global Offensive build, from back when it was essentially a reskinned Counter-Strike: Source.
- Assets from F-Stop, a scrapped Portal prequel built around a camera that could manipulate objects, instead of a portal gun.
- A weapon model tied to Half-Life 2: Episode Three, nicknamed the “Weaponizer,” which turns objects into ammo. It was reportedly a placeholder before Valve landed on the gel-drop mechanic that later became a core part of Portal.
- Third-party surprises, including an unfinished build of Sonic the Hedgehog 4: Episode II and files connected to Fallout: New Vegas.
What isn’t in there, despite days of digging: a complete, playable Half-Life 2: Episode Three, and nothing that confirms Half-Life 3 exists. If a headline implied otherwise, it’s doing more work than the leak actually did.
Former Valve writer Elan Ruskin summed up the mood pretty well, joking online that whatever got cut from these games probably deserved to stay cut.
Why the Leak Stops Dead at 2013
This isn’t a coincidence, and it’s the detail that actually explains what this leak is. Steam2 was Valve’s original content-delivery backbone. In March 2013, Valve rolled out SteamPipe, built on a standard HTTP file system instead of the old GCF/NCF format. Once that switch happened, Steam2 became legacy infrastructure, and legacy infrastructure is exactly the kind of thing that gets forgotten while everyone’s attention moves to the new system.
So the Teraleak is basically a frozen snapshot. Everything that existed in Steam2 before the 2013 migration was apparently sitting there, unprotected, for well over a decade before someone noticed.
Does This Affect Your Steam Account? No.
The Steam2 Teraleak does not contain your account data. No usernames. No passwords. No emails. No payment details. No Steam Guard codes.
This leak is old game development history, not user data. It’s builds, assets, and source material from games, not information about the people who bought them. If your worry after seeing “12TB Steam leak” in a headline was whether to change your Steam password, the answer here is no.
That said, downloading the archive yourself isn’t something we’d recommend. It’s spreading through torrent sites, it’s enormous, plenty of the individual files are unlicensed copies of commercial games, and running unknown executables pulled from a random dump carries its own risk regardless of how interesting the contents are.
The Real Steam Data Breach You Should Actually Know About
There was a genuine Steam-related data breach this month, and it’s a completely separate story that keeps getting tangled up with the Teraleak in social media threads.
Between July 29 and August 1, 2026, attackers breached CEVA Logistics, the shipping company Valve uses to deliver Steam hardware, think Steam Deck and Steam Machine orders, to customers in Europe. Valve found out on August 7 and started emailing affected customers shortly after.
What actually got taken, according to Valve’s own notice: names, home addresses, phone numbers, the email address linked to the Steam account, and details of what hardware was ordered and at what price. Valve was clear that passwords, payment card numbers, and Steam Guard codes stayed safe, because CEVA never had access to that information in the first place.
CEVA wasn’t only a Valve problem, either. The same breach also touched customers of Bol, De Bijenkorf, Ajax, and ING, since CEVA ships for a long list of European companies, not just Valve.
If you bought Steam hardware and had it shipped to a European address recently, this is the incident that actually involves your personal information, not the Teraleak. Valve’s own guidance is the right takeaway here: expect phishing emails, texts, or even phone calls that reference your real order and address to sound convincing. A message knowing your address doesn’t make it legitimate. It just means whoever sent it has your address.
There’s a Third Steam Story Floating Around Too
Just to make an already confusing month more confusing, a known dark web seller going by EnergyWeaponUser has separately advertised a database allegedly containing 89 million Steam-linked phone numbers and one-time passcodes, priced at $5,000. This one is unverified. Some researchers believe the data may actually trace back to Twilio’s infrastructure rather than Steam directly, and Twilio has denied being breached. Valve hasn’t confirmed anything either.
We’re not treating this as confirmed, and neither should you, but it’s worth knowing it exists so a headline about it doesn’t blindside you on top of everything else this month.
What You Should Actually Do
If you bought Steam hardware and shipped it to Europe this year, treat any message about that order with suspicion, even if it quotes your real address back to you. Go directly to Steam’s official site to check your order status instead of clicking a link in an email or text.
For everyone else, there’s genuinely nothing to act on here. This leak doesn’t touch your account, and it isn’t the kind of exposure that dark web monitoring tools are built to catch, since there’s no personal data in it to monitor for in the first place.
If you want to be cautious in general, turning on Steam Guard and staying alert to phishing that leans on real personal details is good practice regardless of this specific story.
The Bigger Picture
Old, forgotten infrastructure has been a recurring theme in security stories all year, and it rarely takes a sophisticated attacker to expose it. It just takes someone remembering to check whether a URL from over a decade ago still responds. Valve isn’t the first major company to have a legacy system quietly hand out more than it should, and it won’t be the last.
For now, the safest way to think about August 2026’s Steam news is as three separate stories wearing the same name: an open server that leaked old game files, a real breach at a shipping partner that leaked real customer data, and an unverified claim still working its way through checking. Only one of those three actually needs your attention.
Frequently Asked Questions
Is the 12TB Steam leak a hack?
No. It came from a publicly reachable server with no authentication behind it. Nobody broke in.
Was my Steam password or personal data exposed in the Teraleak?
No. The Teraleak is old game development files, not user account data.
Is there a real Steam data breach I should be worried about?
Yes, a separate one. The CEVA Logistics breach disclosed in August 2026, which exposed shipping details for European Steam hardware buyers.
Does the leak confirm Half-Life 3?
No. It contains an old weapon model tied to the canceled Half-Life 2: Episode Three, not a build of Half-Life 3.