Steam Hardware Customer Data Exposed in CEVA Logistics Cyber Attack

Valve has started informing European customers who purchased Steam hardware that their personal details may have been compromised following a cyber attack on CEVA Logistics, the company responsible for handling Steam hardware deliveries in the region. The news of the breach initially emerged on online forums, where affected customers shared screenshots of the notification email sent by Valve. According to the email, the attack on CEVA Logistics occurred between July 29 and August 1, with Valve being notified of the breach on August 7. As CEVA Logistics retains delivery-related data for a period of up to 90 days after an order is placed, Valve is notifying all customers who may have been affected within this timeframe. The exposed information includes names, addresses, postal codes, cities, countries, phone numbers, email addresses associated with Steam accounts, and details of the hardware ordered. Although the breach is believed to have primarily affected buyers of the Steam Deck, Steam Machine, and Steam Controller, Valve has assured that no payment information, passwords, or account data were compromised, and customers do not need to update their passwords or account settings. Valve has warned customers to be cautious of potential phishing attempts via email, SMS, or phone that reference their order, and has reminded them that Steam Support only operates through the official help website and will never request sensitive information. CEVA Logistics has confirmed the breach, stating that it affected part of its European contract logistics operations and disrupted at least eight of its warehouses in Europe. The breach has also reportedly affected several banks and retailers that rely on CEVA for shipping. Valve is seeking further information from CEVA on the scope and cause of the breach and is notifying relevant data protection authorities in the affected countries.