Valve confirms CEVA breach exposed European Steam hardware customer data

← Back to the feed

Valve confirms CEVA breach exposed European Steam hardware customer data

Developing story first seen 3 hours ago

Engadget · 3 hours ago

Valve has confirmed that personal data belonging to European customers who ordered Steam hardware was "likely compromised" after a cyberattack on CEVA Logistics, the firm that handles shipping for those orders. The breach matters because it leaves affected customers exposed to follow-up scams, with Valve warning that criminals may exploit the leaked details to send convincing fake messages impersonating Steam, Valve or delivery companies.

The cyberattack on CEVA Logistics took place between 29 July and 1 August, and Valve said it learned of the incident on 7 August. Stolen data includes names, addresses, phone numbers, emails and order details, but Valve confirmed that payment information, passwords and Steam Guard codes were not accessible, meaning affected users don't need to change their account credentials. Valve cautioned customers to watch for scam emails, texts or calls referencing their hardware order that request a small customs or redelivery fee, or ask them to "verify" the order by signing in somewhere, and said it is pressing CEVA for the full scope of the breach while notifying data protection authorities in the affected countries.

  • Valve warns European Steam hardware customers' data was likely stolen
  • CEVA Logistics breach (29 Jul–1 Aug) exposed names, addresses, contacts, orders
  • Passwords and payment data safe, but expect follow-up phishing scams

New here? Start with this

Valve, the company behind the digital games platform Steam, sells its own gaming hardware, such as controllers and handheld devices, to customers in Europe. Deliveries of that hardware are handled by CEVA Logistics, a shipping and logistics firm rather than a part of Valve itself, which means customer order details pass through CEVA's systems as part of the delivery process.

CEVA Logistics suffered a cyberattack, and Valve has since confirmed that personal details of its European hardware customers were caught up in the breach. This matters because the stolen information, including names, addresses and contact details, could be used by criminals to craft convincing scam messages that appear to come from Steam, Valve or a delivery company, putting affected customers at risk of follow-up fraud even though their Steam accounts and payment details were not compromised.

More coverage

Europe World

Read the full article at the source →

Originally published by Engadget as “Data of European Steam hardware customers ‘likely compromised’, Valve says”.