Valve issues warning to Steam Machine and Steam Controller customers to “expect fake messages” after its European hardware partner is hacked
Developing story first seen 2 hours ago
Valve has warned European customers who ordered a Steam Machine or Steam Controller that they may be targeted by scammers following a data breach at CEVA Logistics, one of its European hardware distribution partners. CEVA was hacked on 7th August and subsequently informed Valve, which is now alerting affected customers directly. The breach matters because criminals could use the stolen details to send convincing fake delivery messages designed to trick recipients into paying bogus fees or handing over further personal information.
No passwords or payment card details were exposed, but the compromised data may include names, addresses, phone numbers, countries of residence, Steam account email addresses and hardware order details. Valve says CEVA retains such information for up to 90 days after an order, and it is urging customers to treat any email, SMS or phone message referencing their order — even ones that quote back their correct address — as fake if it asks for payment or account verification. Valve says it is pressing CEVA for the full scope of the breach and has notified data protection authorities in the affected countries.
- Valve's European shipping partner CEVA Logistics suffered a data breach.
- Stolen data could let scammers send fake, convincing delivery messages.
- No passwords or payment details leaked; customers urged to stay vigilant.
New here? Start with this
Valve makes Steam, the dominant platform for buying and playing PC games, and has recently been selling its own hardware, including a games console called the Steam Machine and a Steam Controller. Getting these devices to customers across Europe involves outside logistics firms, one of which is CEVA Logistics, a distribution partner that handles orders on Valve's behalf.
CEVA suffered a cyberattack, and the data it held on Valve's European customers who had ordered the hardware may have been accessed. This matters because logistics data of this kind typically includes real names, home addresses and contact details, which scammers can use to impersonate delivery companies and trick people into paying fake fees or giving up further personal information.
Valve is not the company that was hacked, but it is the company customers bought from, so it has taken on the job of warning them and coordinating with regulators. The episode is part of a wider, familiar pattern in which breaches at third-party suppliers expose a company's customers, even when the company's own systems were never compromised.
More coverage
Art Business Companies Culture Cybersecurity Europe Technology