Valve warns of Steam hardware data breach in Europe

Valve has begun emailing European customers about a Steam hardware data breach. The company is warning that a cyber attack on its shipping partner may have exposed their personal information. Valve confirmed the incident in messages sent to buyers of the Steam Deck, Steam Controller and Steam Machine. The emails went out on August 10, after users on Reddit posted screenshots of the notification.

Valve said CEVA Logistics, the company that ships Steam hardware to customers across Europe, was hit by a cyber attack between July 29 and August 1. Valve was told on August 7 that certain customer information “was likely compromised.” CEVA’s investigation into the incident is still ongoing, and Valve says it does not yet have the full picture.

What data was exposed in the Steam hardware data breach

Valve sends CEVA the details needed to deliver a package. That is likely what the attacker accessed. The exposed information reportedly includes names, street addresses, postal codes, cities and countries. It also covers phone numbers, the email address linked to each buyer’s Steam account, and the type of product ordered along with its price.

CEVA retains delivery records for up to 90 days after a customer places an order. Anyone who bought a Steam Deck, Steam Controller or Steam Machine in Europe within that window could be affected. Valve said CEVA has no access to Steam passwords, payment information or Steam Guard codes. That data was not exposed in the attack, according to the company.

Valve’s warning about scam attempts

Valve is urging affected customers to treat unexpected messages about their hardware order with suspicion. In its notice, the company wrote that scammers may pose as Steam, Valve or a delivery company. They could quote a customer’s real address back to them to appear legitimate, Valve said, since that information is part of what was likely taken.

Requests to confirm a delivery, pay a customs fee, or sign in to “verify” an order should be treated as fake. Valve said customers do not need to change their Steam password or update any account settings. The company noted that Steam Guard, payment details and login credentials were never handled by CEVA in the first place.

What happens next in the CEVA investigation

Valve said it continues to press CEVA for the full scope of the breach and how it happened. According to Valve, CEVA has isolated the affected systems and taken them offline. Outside investigators have also been brought in to examine the attack.

Valve has not said how many customers the Steam hardware data breach affected. The company has not confirmed whether CEVA has identified a specific cause. For now, Valve’s guidance to Steam hardware buyers in Europe is simple. Watch for phishing attempts that reference the order, and ignore any request for payment or login details tied to the incident.