Valve has begun requiring Australian Steam users to verify they are at least 18 before purchasing online games and applications, complying with an Australian requirement that took effect on September 9. Steam relies on bank-card verification rather than government identification or biometrics; Mastercard's age-assurance service can return an adult-status result without providing the merchant with the customer's date of birth.
In practice, credit cards are the most consistently accepted method, while debit-card eligibility varies by card network and whether an issuer labels the product as adults-only. Users report failed debit-card checks, and Steam does not accept PayPal, account age, or purchase history as alternatives. The approach may prevent many legitimate adults—particularly younger customers with low credit-card adoption—from accessing R18+ titles, unlike PlayStation and Xbox, which offer multiple verification options.

See the reporting duties and controls this puts on the clock.
5 events from the most recent confirmed update back to the earliest known activity.
Valve implemented age verification for Australian Steam users seeking to purchase or access age-restricted games, using bank-card verification rather than government identification or biometric data. Credit cards generally pass the check, while debit-card eligibility depends on the card network and whether the issuer designates the product as adults-only.
Australian law began requiring an over-18 age-verification step for online application and game purchases.
Mastercard introduced a global age-assurance capability that can tell a merchant whether a cardholder is an adult without disclosing the cardholder's date of birth.
Australian requirements for online gaming services to verify that users are at least 18 before allowing access to R18+ games came into force.
Users reported that some Mastercard debit cards from Commonwealth, Westpac, and Macquarie worked for Steam age verification, while cards from Bendigo, St. George, Revolut, ANZ, and most Visa cards appeared to fail. Users requested alternative verification methods, and Valve had not confirmed plans to add them.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
tomshardware.com
Open sourceghacks.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.