For about two years the Open Source SSL software many websites use had a flaw that conceivably someone could get access to data that was encrypted including account info and passwords. You should change your password on effected sites but only after they have patched their SSL software.
Here is a link to the status of several popular sites. I know many Steam users are on here and that isn’t listed. Steam was effected but I am 99% sure has been patched.
Here is a link to more info about the flaw.