Valve tells Steam hardware customers in Europe their personal data ‘was likely compromised’ in a cyber attack

Valve tells Steam hardware customers in Europe their personal data ‘was likely compromised’ in a cyber attack

Valve has been contacting customers who bought its hardware in Europe to tell them their personal data may have been compromised in a cyber attack.

Numerous users on Reddit have been reporting that they received the email today, informing them that the distribution company that sends Steam hardware to European customers was affected by a cyber attack two weeks ago.

The email informs users that CEVA Logistics – which handles the shipping of Steam Deck, Steam Machine and Steam Controller across Europe – was affected by a cyber attack between July 29 and August 1.

Valve says that CEVA is still investigating the attack, but that it was told on August 7 that certain information about Steam customers “was likely compromised”.

According to Valve it sends delivery-related information to CEVA so it can deliver hardware to European customers, and “these are the details the attacker likely took”.

CEVA reportedly retains this information for up to 90 days after the order is made, meaning anyone who bought a Steam Deck, Steam Controller or Steam Machine in the past three months may be affected.

The following information may have been compromised, according to Valve:

  • Name
  • Street address, postal code, city and country
  • Phone number
  • Email address used by the person’s Steam account
  • Type of product ordered and total price

“Expect fake messages” from scammers, Valve warns

Valve tells Steam hardware customers in Europe their personal data ‘was likely compromised’ in a cyber attack
Players in Europe who recently ordered a Steam Controller or Steam Machine may have been affected by the leak.

Because CEVA doesn’t get access to a user’s Steam password, payment information or Steam Guard codes, this information was not compromised, Valve says.

The company now says those affected should prepare for the possibility of criminals attempting to scam them using the information that was leaked.

“Expect fake messages – email, SMS or phone – that mention your hardware order and appear to come from Steam, Valve or a delivery company,” Valve warned.

“They may quote your address back to you to prove they’re genuine. They may ask you to confirm a delivery, pay a small customs or redelivery fee, or sign in somewhere to ‘verify’ your order. Treat all of them as fake. You do not need to change your Steam password, and you don’t need to do anything to your account settings.”

Valve says it’s still “pressing CEVA for the full scope of what was taken and how”, and says CEVA has “isolated the affected systems, taken all offline and brought in outside investigators”.