Steam Store Credentials Leaked: 14,068 Gamer Logins Now Exposed
In May 2025, HEROIC analysts found a combolist uploaded by a Telegram user containing 14,068 records tied to store.steampowered.com, the Steam gaming platform. Each record pairs an email address with a plaintext password and the URL it was harvested from.
Why This Is Dangerous
Steam accounts often hold years of purchased games, saved payment methods, and linked wallets. A working email and password lets an attacker log in directly, change account details, and potentially drain stored funds or resell the account's game library.
What Was Exposed in the Steam Combolist
- Email addresses
- Plaintext passwords
- Source URLs
Why This Matters
Gaming accounts are valuable targets because they can be resold, stripped of in-game items, or used as a foothold to attack linked payment methods and email accounts. With over 14,000 records in this single file, the risk of credential stuffing and account takeover reaches a large group of Steam users at once.
How a Combolist Attack Works
A combolist compiles email and password pairs from previous breaches, phishing pages, or infected computers into one large file. Criminals then run automated scripts that test every pair against Steam and other popular platforms, instantly flagging which accounts still use the same password.
Check If You Are Affected
Check your email against HEROIC's free breach scanner, which searches more than 400 billion leaked records including this Steam combolist. If your credentials appear, change your Steam password immediately and enable Steam Guard for extra protection.
Breach Breakdown
14,068 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds