Valve issues warning to Steam Machine and Steam Controller customers to “expect fake messages” after its European hardware partner is hacked
Developed over time first seen 2 months ago
Valve has warned European customers who ordered a Steam Machine or Steam Controller that they may be targeted by scammers following a data breach at CEVA Logistics, one of its European hardware distribution partners. CEVA was hacked on 7th August and subsequently informed Valve, which then alerted affected customers directly, telling them to expect fake shipment-related emails, texts or calls attempting to exploit the stolen data. The breach matters because criminals could use the leaked details to send convincing fake delivery messages, potentially quoting victims' own addresses back to them, in an effort to extract bogus fees or further personal information.
No passwords or payment card details were exposed, but the compromised data may include names, addresses, phone numbers, countries of residence, Steam account email addresses and hardware order details, which CEVA retains for up to 90 days after an order. Valve said it was pressing CEVA for the full scope of what was taken and how, and confirmed it was notifying data protection authorities in the affected countries; no further updates have since emerged. The warning came as Valve continues shipping Steam Machines to winners of its pre-order lottery, while new Steam Controller orders are not expected to be fulfilled until sometime in 2027.
- Valve's European logistics partner CEVA was hacked on 7th August
- Stolen data may include names, addresses and order details
- Valve warns customers to treat delivery-related messages as fake
New here? Start with this
Valve makes Steam, the dominant platform for buying and playing PC games, and has recently been selling its own hardware, including a games console called the Steam Machine and a Steam Controller. Getting these devices to customers across Europe involves outside logistics firms, one of which is CEVA Logistics, a distribution partner that handles orders on Valve's behalf.
CEVA suffered a cyberattack, and the data it held on Valve's European customers who had ordered the hardware may have been accessed. This matters because logistics data of this kind typically includes real names, home addresses and contact details, which scammers can use to impersonate delivery companies and trick people into paying fake fees or giving up further personal information.
Valve is not the company that was hacked, but it is the company customers bought from, so it has taken on the job of warning them and coordinating with regulators. The episode is part of a wider, familiar pattern in which breaches at third-party suppliers expose a company's customers, even when the company's own systems were never compromised.
More coverage
Art Business Companies Culture Cybersecurity Europe Technology