Valve has issued a security warning to customers who purchased Steam hardware in Europe, confirming that personal details were exposed following a cyberattack on their distribution partner, CEVA Logistics.

Quick Facts

  • Impacted Region: Customers residing in Europe.
  • Affected Data: Names, email addresses, shipping addresses, and phone numbers.
  • Secure Data: Steam account passwords, payment information, and Steam Guard codes were not accessed.
  • Timeline: Valve was notified of the incident on August 7, following an attack on CEVA systems between July 29 and August 1.

In an email sent to affected buyers, Valve explained that CEVA Logistics held specific delivery-related information required to ship hardware like the Steam Machine and Steam Controller. The company confirmed that this data is what the attackers likely obtained.

While Valve stated that the breach does not impact the security of individual Steam accounts, they cautioned users to remain vigilant. Because the attackers possess email addresses and phone numbers linked to these orders, there is an increased risk of targeted phishing attempts via email or text message posing as official order updates.

The incident comes as Valve continues to manage the rollout of its latest hardware, which has faced previous delays and high demand in international markets.