top of page

Valve Warns European Customers of Potential Data Breach

Valve has reached out to customers in Europe who purchased its hardware to inform them of a possible breach of their personal data due to a cyber attack. Users on Reddit have shared that they received emails today from the company, detailing that the distribution partner responsible for delivering Steam hardware to European customers experienced a security incident two weeks ago.



The email specifies that CEVA Logistics, the company tasked with shipping Steam Decks and Steam Machines, was affected by this cyber attack between July 29 and August 1. Valve reported that they were notified on August 7 that certain information regarding Steam customers was likely compromised.


Valve explained that it shares delivery-related information with CEVA to facilitate hardware delivery to European customers, which is the type of information that may have been accessed by the attacker. CEVA retains this data for up to 90 days after an order is placed, meaning that individuals who ordered a Steam Deck, Steam Controller, or Steam Machine within the past three months could be at risk.


According to Valve, the compromised data may include the following details: names, street addresses, postal codes, cities, countries, phone numbers, email addresses associated with Steam accounts and product types ordered.


In light of the breach, Valve has cautioned users to be vigilant for potential scams. "Expect fake messages from scammers," Valve warned, advising players in Europe who have recently ordered hardware to be on guard.

These fraudulent communications may come via email, SMS, or phone, and could reference their hardware orders to appear credible. Scammers might quote addresses to prove legitimacy and may request confirmation of delivery, payment of a minor customs or redelivery fee, or prompt users to log in to verify their orders. Valve emphasizes treating all such messages as suspicious.


Importantly, Valve reassured users that CEVA does not have access to sensitive information such as Steam passwords, payment details, or Steam Guard codes, meaning that this data was not compromised. Affected users do not need to change their Steam passwords or alter their account settings.


Valve continues to seek clarity on the full extent of the breach from CEVA, which has reportedly isolated the affected systems, taken them offline, and engaged outside investigators to look into the incident.

Comments


bottom of page