Valve confirms Steam hardware buyers’ data exposed in CEVA Logistics cyberattack

by John Garrett
0 comments

Valve is currently informing European customers who purchased Steam hardware that their personal details may have been exposed due to a cyberattack on CEVA Logistics, the company responsible for handling Steam hardware shipments in the region.

The breach was initially reported on ResetEra and Reddit, where affected customers shared screenshots of Valve’s email notification earlier today.

According to the email obtained by GamesIndustry.biz, Valve disclosed that the cyberattack on CEVA took place between July 29 and August 1, with Valve becoming aware of the breach on August 7.

As CEVA stores delivery-related data for up to 90 days after an order, Valve is reaching out to all potentially affected individuals within that timeframe.

The compromised information includes customers’ names, addresses, postal codes, cities, countries, phone numbers, email addresses associated with their Steam accounts, and details regarding the hardware ordered. The impact is believed to be primarily on purchasers of the Steam Deck, Steam Machine, and Steam Controller. However, Valve assures that no payment information, passwords, Steam Guard codes, or other account data were affected. Customers are not required to change their passwords or account settings.

Valve cautioned customers to be vigilant against phishing attempts via email, SMS, or phone, specifically related to their orders. Some of these attempts may include customers’ actual addresses to appear legitimate. The company emphasized that Steam Support solely operates through help.steampowered.com and will never request passwords or Steam Guard codes.

CEVA acknowledged the breach in a statement to TechCrunch, confirming that the incident impacted part of its European contract logistics operations.

The logistics company based in France stated that the breach disrupted operations in at least eight of its European warehouses. The breach has also affected several banks and retailers that rely on CEVA for shipping, including Valve.

Valve is seeking additional information from CEVA regarding the extent and cause of the breach and is informing data protection authorities in the affected regions. The specific number of impacted customers has not been disclosed.

You may also like