Valve confirms Steam hardware buyers' data exposed in CEVA Logistics cyberattack
Key Points:
- Valve has informed European customers who ordered Steam hardware that their personal information may have been exposed due to a cyberattack on CEVA Logistics, the company handling Steam hardware deliveries in the region.
- The breach occurred between July 29 and August 1, with Valve learning of it on August 7, affecting delivery-related data retained by CEVA for up to 90 days after an order.
- Compromised data includes names, addresses, phone numbers, email addresses linked to Steam accounts, and hardware order details, but no payment information, passwords, or Steam Guard codes were affected.
- Valve warned customers to be vigilant against phishing attempts that may use real order details and emphasized that Steam Support will never request passwords or Steam Guard codes.
- CEVA confirmed the breach impacted parts of its European logistics operations, disrupting multiple warehouses and affecting other clients, while Valve is investigating further and notifying relevant data protection authorities.